48 ms·
US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing
- daniaal 5y agoTwitter link to a case of the vulnerability being exploited: https://twitter.com/th3_protoCOL/status/1433414685299142660 https://twitter.com/th3_protoCOL/status/1433414685299142660 NIST Link to issue: https://nvd.nist.gov/vuln/detail/CVE-2021-26084 https://nvd.nist.gov/vuln/detail/CVE-2021-26084 Tweet from USCYBERCOM urging users to patch: https://twitter.com/CNMF_CyberAlert/status/1433787671785185283 https://twitter.com/CNMF_CyberAlert/status/14337876717851852... Tweet from BadPackets showing where the bad actors are originating from: https://twitter.com/bad_packets/status/1433157632370511873 https://twitter.com/bad_packets/status/1433157632370511873
- macksd 5y agoNit: I wouldn't say "originating". That's where this specific exploit is coming from "most recently". But it would seem to not be script kiddies and they're listing like 8 countries. I would assume the bad actors could be anywhere, proxying traffic through any number of other places.
- SV_BubbleTime 5y agoHelpful links, looks like failure to sanitize input. Classic. But on the “attacks coming from”, I’ve never understood putting stock in these. Aren’t these all going to be proxies and botnets?
- hn_throwaway_99 5y agoFailure to sanitize input is one thing, but the bigger issue to me is that, with so many of these Java server installations, that a simple injection can immediately lead to "game over" from a server takeover perspective. For the bug in question, I bet the vast majority of webservers never need the ability to call unrestricted Runtime.exec(), yet access to that is just one unsanitized input away from complete control over your server. OS vendors have made leaps and bounds in the past decade making it much harder for code vulnerabilities to lead to system takeover. I'd argue it's time for server code and language runtimes to make it easier to write secure code.
- SV_BubbleTime 5y agoThat’s fair. But there needs to be a point somewhere that you just get work done. I absolutely agree that runtimes, frameworks, and server code should do a better job at trust and sanitization, but you will always get to a point where if you want to get something done, you need to do the work. I guess I’m skeptical that eval() or runtime.exe could or even should take in lists and configs of what the code is allowed to do and monitor for it during execution. It seems like doing that would add countless issues and complexity, but more so just kick the can down the code to another layer with the same eventual issue.
- LilBytes 5y agoA colleague who runs security at an ASX 200 company found crypto mining running within a day of the vulnerability being announced. They've since patched and cleaned up the hosts they run Data Centre on. Patch quickly, and check for the IoCs listed in Daniaal's tweet below.
- echelon 5y agoI am not in the least bit shocked. Atlassian products are some of the worst glued-together garbage in the industry. The entire product surface area is probably rife with exploits. Using Confluence or Jira will show you just how much Atlassian cares about its own products. I'd love for this to be the straw that breaks the camel's back and makes IT/infosec orgs move away from this bilge.
- m_eiman 5y agoAny suggestions on what to use instead of Confluence? Need to run on-prem, it's mostly the wiki-like features I'm interested in.
- winkelwagen 5y agoWhat target group? Devs? Po? General org?
- mrweasel 5y agoI'll just go with "Yes" because we use the same Confluence installation our entire organisation. Spaces might be configured differently, but we can have all our documentation in one system and link across space. There really isn't that many alternatives, SharePoint maybe, but then you're just suggestion something worse.
- nix23 5y agoI migrated every confluence instance over to XWiki, since the Australian backdoor law[1]. http://www.xwiki.org/xwiki/bin/view/Main/WebHome http://www.xwiki.org/xwiki/bin/view/Main/WebHome https://xwiki.com/en/try-xwiki/ https://xwiki.com/en/try-xwiki/ [1] https://www.wired.com/story/australia-encryption-law-global-impact/ https://www.wired.com/story/australia-encryption-law-global-...
- skinkestek 5y ago> Need to run on-prem, it's mostly the wiki-like features I'm interested in. Since you are looking mostly for the wiki part there is Dokuwiki which is magnitudes better at being a wiki. Remember, wiki is derived from the Hawaiian word for quick or something to that effect and whatever Confluence is it isn't quick. Don't know how well it will hold up under scrutiny if black hats gets a reason to swarm over it, but unlike Confluence you can hire someone to patch the guts of it if necessary. Edit: I have no reason to believe it is worse than anything else, I'm just pointing out it probably hasn't had so much exposure to help it harden.
- spullara 5y agoWhy are internally hosted instances even available on the public internet?
- Closi 5y agoSo that users can be at home or on a mobile device without requiring them to have VPN. But so that you still can ensure data-locality or run a customised instance e.t.c. if you have requirements around that. Plus licensing is approx. 40% of the full SaaS cost at scale so may be cheaper to deploy that way.
- CodeGlitch 5y agoBut why are they not using VPN?
- hanselot 5y agoFor the same reason docker exists. Convenience and lack of understanding.
- ianai 5y agoProbably because they’re on a mobile device or essentially monitoring 24/7 would be my guess.
- raesene9 5y agocommon reasons could be :- - Cost, VPNs and the hardware to run them can be expensive - Single point of failure. If you run all your remote access through a VPN gateway then you run the risk of disruption if it goes down. Of course you can implement redundnt/multiple gateways but that increases cost. - Complexity for B2B setups. If you're exposing an API and you want third party services to access it, it can be more complex if there's a VPN involved. All that said, I still wouldn't run something like this (or indeed most services) directly on the Internet as it's a single vuln. away from problems, however I've seen plenty of services directly visible on the Internet for these reasons. You can spelunk around one of the search engines like Shodan or Censys to get an idea of how many people run application services directly on the Internet.
- m_eiman 5y agoIs there a simple way to test if I've applied the mitigations properly?
- marc_h 5y agoThere are several exploits on github, e.g. https://github.com/march0s1as/CVE-2021-26084 https://github.com/march0s1as/CVE-2021-26084 This one opens a shell but I haven't tried it myself.
- wcchandler 5y agoMy employer was bit by this on Wednesday. Thankfully we had Crowdstrike on it which blocked any real damage. But it definitely moved our cloud migration from “later this year” to “later this month”. Also, not having confluence for a day exposed just how reliant we were on it for day-to-day activities.
- vasco 5y ago> Thankfully we had Crowdstrike on it which blocked any real damage For someone not familiar with their products, what did they do for you specifically?
- wcchandler 5y agoFor us specifically they blocked the server from downloading more assumedly dangerous tools. Blocked more privilege escalation and blocked crypto mining software from running. Our teams were also able to do a “network isolation” and essentially bring the server offline quickly, without touching more pieces and possibly exposing our credentials or tokens. We also had the paid Overwatch protection which is Crowdstrikes 24/7 security monitoring solution which resulted in an actual person emailing half our team at 1am letting us know this was happening and their recommended remediation steps.
- deleted 5y ago[deleted]
- SV_BubbleTime 5y agoI would explain it as next gen antivirus. Looks closer at hashes and heuristics of all data in and out to a server. It seems crazy that everything that is read or written is hashed and compared to a db, but it works. FWIW, we dumped crowdstrike for Cisco AMP and have been happy.
- darkwater 5y agoSecurity is planning to implement here CrowdStrike in the near future... does it run on every single server?
- spuz 5y agoThe linked proof-of-concept [1] demonstrates bypassing the OGNL blacklist by using this to do reflection: > ""["class"].forName(...) as opposed to: > "".getClass().forName(...) Does anyone know why this works in OGNL? It does not appear to be valid Java syntax. [1] https://github.com/httpvoid/writeups/blob/main/Confluence-RCE.md https://github.com/httpvoid/writeups/blob/main/Confluence-RC... Edit: Oh apparently, it's just a feature of OGNL: https://commons.apache.org/proper/commons-ognl/language-guide.html https://commons.apache.org/proper/commons-ognl/language-guid...
- ashtonkem 5y agoNever used it, but a quick perusal of its Wikipedia article mentions that it was a rewrite of something else using ANTLR, which implies a separate syntax.
- miken123 5y agoAtlassian was so kind to update their mailing lists somewhere over the last year or so. Previously, they would email the 'technical contact' of the license about any vulnerabilities. They quietly switched to some other notification system and never informed us about it. Hence we missed the update and got a free Bitcoin miner. Thanks Atlassian, I'll make sure to get your products out of the door as soon as possible. [edit] Oh it's even better. Their site says 'Note: if you are a tech administrator, you will always receive these notifications.' but they never mailed us. Great job, Atlassian, great job.
- angry_octet 5y agoWell, I got it. Maybe you specifically didn't get it, or maybe there is something filtering it.
- miken123 5y agoI only got the 'update' from last Saturday, by then it was too late already. Their original advisory was from the 25th, they should have mailed me back then.
- Mandatum 5y agoHow big is your organisation? I know it shouldn’t matter but your CS person would likely have reached out if they’re anything like Amazon, Microsoft, Salesforce, etc. I’ve always found government, sensitive customers (banks, payment processors, healthcare) and big spenders get prioritised with phone call notifications. However with a deprecated product, the financial impact is so minuscule - leadership won’t prioritise this one unless you’re big fish.
- miken123 5y agoIt's tiny, I just want them to send me an email if there is a critical vulnerability. Not too much to ask, I think.
- polote 5y agoThat's one of the selling point of Saas compared to hosted instance honestly. Some company think that having Confluence hosted internally is going to increase the security. But this is wrong. When you rely on a Saas provider. The provider has people who monitor the infrastructure constantly whereas when you hosted on your own server, the confluence instance is just one of the many services that they manage. And even if some company will be very reactive to events like this. The majority of companies will be much slower. And in addition to that. When you use Saas. Security is a top priority, a Saas provider can't allow to have data of its customers leaked on the web. Whereas once again when it is internal data people will be less cautious
- macksd 5y agoThis isn't always true. Using a SaaS is outsourcing these concerns, and sometimes you're outsourcing them to someone who will do better than you would and sometimes worse. I've worked on a couple of SaaS where security was absolutely not top priority. Especially in Silicon Valley, organizations often value growth over sound processes, fully staffed security teams, and managing tech debt. Many a SaaS has leaked customer data and survived, so many think they CAN allow that risk.
- polote 5y agoI didn't say that it is always the case. The same argument you use can be used to talk about companies who are going to self host Confluence. I agree that a lot of Saas startup are going to neglect security. But here we are talking about Knowledge base tools Saas companies. This is not some standard Saas company. They know they are in charge of company internal secrets. Or at lest I hope
- macksd 5y agoAny time a SaaS gets compromised there's a similar comment here about how obviously this is going to happen when you give someone else your data, and it should have just all been within your own firewall, unexposed directly to the Internet. I mean right this minute there's a privacy-focused SaaS on the front page for not being as private as everyone thinks. There's also a network hardware vendor on the front page for including back doors. A philosophy like "SaaS vendors know they can't allow security breaches" is really glossing over the need for layers of security and knowing that it's ultimately all on the trustworthiness of specifically who is involved.
- numair 5y agoThe good thing about the fact that Atlassian offers both on-prem and cloud versions of their offerings is, everyone is now aware of the awful engineering practices that underpin their products. We have to assume that there are problems of a similar nature in their cloud service, which is way more of a problem considering the number of orgs that depend on the JIRA SaaS offering. Maybe the founders could have used some of that time spent planning a tunnel between their side-by-side $100M houses, or engaged in Twitter rants, to actually bother delivering value to customers. It’s only a matter of time before this product suite is disrupted, and it might represent one of the most obvious low-hanging opportunities in our entire industry. I still remember being in line at a WWDC a few years back, overhearing someone ask a developer, “where do you work?” When the developer responded with “HipChat,” the other person immediately chuckled and said, “oh — Atlassian... I’m sorry” — and then everyone around them also started laughing. It’s amazing that this company continues to fall up, and that the founders have taken on roles as the ruling digital gurus of Australia (shows you why it’s so easy for the government to run circles around the local tech industry and pass whatever laws they want).
- pletnes 5y agoThere are many jira alternatives out there, from what I can tell. Why are they not disrupted already, if it’s such a low hanging fruit? (Honest question - I don’t have any personal preference)
- cogman10 5y agoAtlassian products are vast, integrated, and support all the crazy draconian processes that every insane project manager wants to implement. You can't easily dump Jira if you are using Jira, confluence, bitbucket, and whatever their CI/CD product is called (bamboo?)
- nerdponx 5y agoHow many PMs actually use those features? In my organization, for example, I don't see any reason why we should prefer Atlassian over Taiga, other than familiarity and inertia.
- dijit 5y ago> The vulnerability only affects on-premise servers, not those hosted in the cloud. This is a dangerous statement to make and should be revised to say: > The vulnerability only affects standalone versions of the software, not the managed service of confluence provided directly by Atlassian. The problem with the former is that lesser technical people, especially directors, might assume they're fine because their standalone instances are hosted on GCP/AWS/Azure, which counts to them as "cloud".
- Lndlrd 5y ago99% agreed. Reserving 1% because I'd strike "lesser technical" from your final sentence. The misleading quote is simply not correct. It is misleading because it's not true. It says Confluence hosted in the cloud is not vulnerable. False statement that can mislead anyone regardless of how technical they are.
- repsilat 5y ago> regardless of how technical they are They said "lesser technical people", not "less-technical people". A more technical person might not be able to read between the lines, but a better technical person should.
- roozbeh18 5y agoits' misleading and it gives off the notion that the cloud is more secure so you should migrate your instance to our managed "Cloud" version.
- sharken 5y agoBut in this case it's literally the cloud product that is more secure.
- Galanwe 5y agoLet's say 99.5%, because Atlassian hosted offering is called "Atlassian Cloud"
- rick_ross 5y agoI know a guy who said “We don’t show up on Shodan because Shodan only groups by IP and does not know the VirtualHost, we’re fine”
- achillean 5y agoFYI: Shodan also does monthly hostname-based scans of the Internet where we set the "Host"/ SNI headers. We use our own DNS DB to grab a list of hostnames/ IPs to launch scans of: https://www.shodan.io/domain/ycombinator.com https://www.shodan.io/domain/ycombinator.com At the moment, I think we're checking around 600 million hostnames.
- tgsovlerkhgsel 5y agoIs that DNS DB publicly accessible?
- achillean 5y agoYes, via the API. Btw all of our websites are entirely built on the same public Shodan API that everybody else has access to.
- rbanffy 5y agoI hope they can find what they are looking for, because, with the built-in search, I sure can’t.
- qwertox 5y agoIt is awful, the worst "search engine" which exists. I absolutely hate it and this is the only thing which wants to make me move away from Confluence. When you need it the most, and this happens often, you know that you definitely cannot rely on it. Any data you put in there is lost, unless you have a good hierarchy and know what to find where without relying on the search.
- mrweasel 5y agoThe search engine will happily search any attached pdfs and return those. It just won't search the actual Confluence pages, which seems like it would be easier.
- kilobaud 5y agoI use this browser extension which seems OK https://chrome.google.com/webstore/detail/confluence-quick-search/gimcmmlpmjffkpbomagapjhdfbbeldfk https://chrome.google.com/webstore/detail/confluence-quick-s...
- rbanffy 5y agoWe have an internal search engine. It made Confluence usable.
- lamontcg 5y agoAtlassian has been producing remotely exploitable code for a decade now. https://www.cvedetails.com/product/8170/Atlassian-Jira.html?vendor_id=3578 https://www.cvedetails.com/product/8170/Atlassian-Jira.html?... I would also say based on experience that if they tell you that an exploit can't be used against any of their other software that you shouldn't ever believe them.
- dwild 5y ago> An OGNL injection vulnerability exists that would allow an authenticated user, and in some instances unauthenticated user, to execute arbitrary code on a Confluence Server or Data Center instance. For god sake, can we all agree to stop using OGNL at this point? At my previous job I kept having to fix OGNL vulnerabilities on our stack, it was awful. Don't remember Apple developer portal hack? OGNL What about Equifax? OGNL This thing is so freakingly insecure it's crazy.
- zepto 5y agoCan anyone comment on what the value of this attack is to the attackers?
- aynyc 5y agoOne of the companies I know use it for HR, payroll and account receivables. If you hack into that, you can get a lot of information.
- plaidfuji 5y agoArbitrary code execution in an on-premise server? You can basically stage an attack on any other internal resources (core infrastructure, databases, endpoints) that are visible from there, with the benefit of already being behind at least one layer of firewall/security.
- zepto 5y ago> Arbitrary code execution in an on-premise server? That doesn’t explain what the benefit of the attack is. It just explains that it’s an effective attack.
- CRConrad 5y agoHow is anybody supposed to be able to answer that question, then? It obviously depends on what other services are running on that server, and what your cracked account has access to. Access the janitor's account on the facilities Jira, which is all that runs on an old Pentium II in the broom cupboard and you get one set of benefits; access the CFO's on the Big Money Server and you get something else entirely. How on Earth did you manage not to realise this by yourself?
- danielscrubs 5y agoI look up to Atlassian. Somehow they continue to easily sell even though so many hates it. I don't know what the secret sauce is... but I want it.
- laurent92 5y agoAnd look at the stock. If someone told me it would ever reach $180, would have been shocked. It’s now $384. And it’s outperforming the expectations all the time. All the people who claim it is awful software, they ignore how many people love the Atlassian suite.
- kortilla 5y agoNot that many people “love” it, that’s why it’s always surprising how well it does. It’s pretty unpleasant to use but there isn’t really anything else out there that’s so well integrated so they keep winning despite the pain.
- birdyrooster 5y agoIt's like Microsoft in the 90s, everyone wants to hate on the company but their sales department just laughs and pens another huge contract
- mdoms 5y agoAtlassian doesn't have a sales department (or at least this was the case for well over a decade, perhaps it could have changed now).
- birdyrooster 5y agoI get what you are saying, but it is a semantically spin.
- markus_zhang 5y agoThey have pretty much everything in the package. You don't really have a lot of alternatives out there that are in the package.
- diebeforei485 5y agoWhy is Confluence so popular anyway? Why not just use any free wiki software?
- deanCommie 5y agoBecause most free wiki software is kind of bland and terrible. Don't get me wrong, they are amazing for what they are but they don't scream "professional". But actually that's not the key point. Nobody buys just Confluence. That would be silly. A bland and terrible (but free) wiki software is definitely better than Confluence. People buy JIRA. And then you've bought into the Atlassian ecosystem, and you want the nice tight integration with your wiki software
- bratbag 5y agoIt's easier for non-techs to pick up. Confluence is often where the long-term docs for product/design oriented team members end up living, or at least being linked. The easy two-way connection between Jira and confluence uses syntax any social media user will be familiar with, so non-techies can link the 'what' with the 'why' in a task before engineers even see them in a grooming session. Anything that moves documentation and ticket preparation effort away from engineers/tech leads/team leads has a significant hidden saving.
- bhauer 5y agoAdmittedly low-value comment: Can we appreciate the amazing vulnerability name? Confluenza. https://censys.io/blog/cve-2021-26084-confluenza/ https://censys.io/blog/cve-2021-26084-confluenza/
- darepublic 5y agoThe hackers will see how bad our team burndown rate is
- oars 5y agoYou just made my day. Thank you.
- hughw 5y agoUse the flaw to deploy the patch, I say.
- riffic 5y agoAtlassian software are some of the most annoying to self-administrate. avoid it if you can.
- escot 5y agoSeems odd that the Priority is "Low" on the ticket https://jira.atlassian.com/browse/CONFSERVER-67940 https://jira.atlassian.com/browse/CONFSERVER-67940
- wly_cdgr 5y agoWould sure be a shame if the only way to fix this was to delete all copies of Atlassian software from every computer worldwide
- bgro 5y agoI spent years "working on" (battling) our own company-hosted Atlassian suite. I'm a software engineer / architect and was thrown admin powers to get a project up and running. It was constant a battle of "the critical basic feature you need in this micro version is broken" and other critical functions being hidden in random places. I applied to their engineering team citing my experience and ability to help with a lot of these things, but never even heard a response. Current alternative software suites I've seen are beyond terrible or generally non-existent / missing major features. I'm sure there's some "pretty SaaS solutions" out there from a startup that charges exorbitant prices, but I don't believe their back end or security are going to be any better.