Finding Confluence servers with Rumble
The U.S. Cyber Command recently reported “mass exploitation” of a code execution vulnerability in Atlassian’s popular Confluence software (CVE-2021-26084). This vulnerability has a CVSS Base score of 9.8 (considered “critical”), requires no authentication for exploitation, and affects many on-prem versions of the product (Atlassian says that Confluence Cloud customers are not affected). Public reports of exploitation are surfacing, including a Confluence instance of the Jenkins project compromised for cryptomining purposes.
Atlassian has provided fixed versions that on-prem Confluence admins should upgrade to as soon as possible, as well as mitigations for those who cannot upgrade immediately. As an aside, there have been some interesting events around the leaking of a private exploit PoC during disclosure with a vulnerable party.
From the Services Inventory, use the following pre-built query to locate systems in your network that are running Confluence:
_asset.protocol:http AND has:http.head.xConfluenceRequestTime
Don’t have Rumble and need help finding your Confluence servers? Start your Rumble trial today.
December 3, 2021
Finding HP printers and MFPs vulnerable to Printing Shellz
Do you have HP printers and multi-function printers (MFPs)? You might want to look at the two recently published vulnerabilities that affect 150+ models. Named “Printing Shellz” by the F-Secure security researchers who reported them, these vulns have been around for ~8 …Read More
November 10, 2021
Find Nucleus TCP/IP assets with accessible FTP services
Researchers at Forescout recently published findings on a new set of 13 vulnerabilities with the Nucleus RTOS TCP/IP stack, collectively referred to as NUCLEUS:13. Originally released in 1993, Nucleus is found in many different types of products, including devices in the …Read More
October 28, 2021
Finding PAX point-of-sale devices
PAX Technologies, a China-based company that manufactures a LOT of point-of-sale (POS) terminal devices, has been in the news this week following an FBI raid of a PAX Florida facility. While the FBI didn’t officially confirm much beyond serving a court-authorized search, a …Read More