Ausnahme gefangen: SSL certificate problem: certificate is not yet valid ๐Ÿ“Œ confluencePot - Simple Honeypot For Atlassian Confluence (CVE-2022-26134)

๐Ÿ  Team IT Security News

TSecurity.de ist eine Online-Plattform, die sich auf die Bereitstellung von Informationen,alle 15 Minuten neuste Nachrichten, Bildungsressourcen und Dienstleistungen rund um das Thema IT-Sicherheit spezialisiert hat.
Ob es sich um aktuelle Nachrichten, Fachartikel, Blogbeitrรคge, Webinare, Tutorials, oder Tipps & Tricks handelt, TSecurity.de bietet seinen Nutzern einen umfassenden รœberblick รผber die wichtigsten Aspekte der IT-Sicherheit in einer sich stรคndig verรคndernden digitalen Welt.

16.12.2023 - TIP: Wer den Cookie Consent Banner akzeptiert, kann z.B. von Englisch nach Deutsch รผbersetzen, erst Englisch auswรคhlen dann wieder Deutsch!

Google Android Playstore Download Button fรผr Team IT Security



๐Ÿ“š confluencePot - Simple Honeypot For Atlassian Confluence (CVE-2022-26134)


๐Ÿ’ก Newskategorie: IT Security Nachrichten
๐Ÿ”— Quelle: kitploit.com


ConfluencePot is a simple honeypot for the Atlassian Confluence unauthenticated and remote OGNL injection vulnerability (CVE-2022-26134).


About the vulnerability

You can find the official advisory by Atlassian to this vulerability here. For details about the inner workings and exploits in the wild you should refer to the reports by Rapid7 and Cloudflare. Affected but not yet patched systems should be deemed compromised until further investigation.

About the tool

ConfluencePot is written in Golang and implements its own HTTPS server to minimize the overall attack surface. To make it appear like a legit Confluence instance it returns a bare-bones version of a Confluence landing page. Log output is written to stdout and a log file on disk. ConfluencePot DOES NOT allow attackers to execute commands/code on your machine, it only logs requests and returns a bogus response.

Building & Running it

You need a recent version of Golang to run/build confluencePot and the appropriate privileges to bind to port 443. We recommend to execute it in a tmux session for easier handling. To run ConfluencePot you either need to create a self-signed TLS certificate with openssl or request one from e.g. Let's Encrypt.

go build confluencePot.go
./confluencePot

Testing and Issues

ConfluencePot was tested using the public exploit by Nwqda, which seems to be the most used variant in the wild at the time of writing. If you find anything wrong with confluencePot please feel free to open an issue or send us a pull request.

Follow us on Twitter --> @SI_FalconTeam <-- to stay up to date with our latest research. Stay safe!



...



๐Ÿ“Œ Awesome Honeypot Resource Collection. Including 250+ Honeypot tools, and 350+ posts about Honeypot.


๐Ÿ“ˆ 51.71 Punkte

๐Ÿ“Œ CVE-2023-22515 | Atlassian Confluence Server/Confluence Data Center up to 8.5.1 Remote Code Execution (ID 175225)


๐Ÿ“ˆ 38.1 Punkte

๐Ÿ“Œ CVE-2023-22518 | Atlassian Confluence Data Center/Confluence Server improper authorization


๐Ÿ“ˆ 38.1 Punkte

๐Ÿ“Œ CVE-2023-22522 | Atlassian Confluence Data Center/Confluence Server prior 7.19.17/8.4.5/8.5.4/8.6.2/8.7.1 Template injection


๐Ÿ“ˆ 38.1 Punkte

๐Ÿ“Œ CVE-2023-22527 | Atlassian Confluence Data Center/Confluence Server prior 8.5.4 Template injection


๐Ÿ“ˆ 38.1 Punkte

๐Ÿ“Œ CVE-2024-21672 | Atlassian Confluence Data Center/Confluence Server code injection


๐Ÿ“ˆ 38.1 Punkte

๐Ÿ“Œ CVE-2024-21674 | Atlassian Confluence Data Center/Confluence Server information disclosure


๐Ÿ“ˆ 38.1 Punkte

๐Ÿ“Œ CVE-2024-21673 | Atlassian Confluence Data Center/Confluence Server Environment code injection


๐Ÿ“ˆ 38.1 Punkte

๐Ÿ“Œ Atlassian Confluence Server/Confluence Data Center up to 6.13.17/7.4.5/7.8.2 ConfluenceResourceDownloadRewriteRule information disclosure


๐Ÿ“ˆ 36.92 Punkte

๐Ÿ“Œ Atlassian Confluence Server/Confluence Data Center up to 5.8.5 WidgetConnector Plugin server-side request forgery


๐Ÿ“ˆ 36.92 Punkte

๐Ÿ“Œ Security Honeypot: 5 Tips for Setting Up a Honeypot


๐Ÿ“ˆ 34.47 Punkte

๐Ÿ“Œ Setting up the Dshield honeypot and tcp-honeypot.py, (Wed, Jul 1st)


๐Ÿ“ˆ 34.47 Punkte

๐Ÿ“Œ Ad-honeypot-autodeploy Vulnerable Windows Domain For RDP Honeypot Automatically


๐Ÿ“ˆ 34.47 Punkte

๐Ÿ“Œ Atlassian Doxygen for Atlassian Confluence 1.3.0 renderContent Cross Site Scripting


๐Ÿ“ˆ 34.03 Punkte

๐Ÿ“Œ Atlassian Doxygen for Atlassian Confluence 1.3.0 getTemporaryDirectory tempId directory traversal


๐Ÿ“ˆ 34.03 Punkte

๐Ÿ“Œ Atlassian Doxygen for Atlassian Confluence 1.3.0 getTemporaryDirectory() tempId Directory Traversal


๐Ÿ“ˆ 34.03 Punkte

๐Ÿ“Œ Embed Dashboards into Confluence | Atlassian Analytics - Demos | Atlassian


๐Ÿ“ˆ 34.03 Punkte

๐Ÿ“Œ Atlassian Doxygen for Atlassian Confluence 1.3.0 renderContent Information Disclosure


๐Ÿ“ˆ 34.03 Punkte

๐Ÿ“Œ Atlassian Intelligence in Confluence, Jira Work Management, and Atlas | Demo Den | Atlassian


๐Ÿ“ˆ 34.03 Punkte

๐Ÿ“Œ Atlassian Doxygen for Atlassian Confluence 1.3.0 renderContent Cross Site Scripting


๐Ÿ“ˆ 34.03 Punkte

๐Ÿ“Œ Atlassian Doxygen for Atlassian Confluence 1.3.0 getTemporaryDirectory() tempId Directory Traversal


๐Ÿ“ˆ 34.03 Punkte

๐Ÿ“Œ Atlassian Doxygen for Atlassian Confluence 1.3.0 renderContent Information Disclosure


๐Ÿ“ˆ 34.03 Punkte

๐Ÿ“Œ Connect to the Atlassian Data Lake | Atlassian Analytics - Demos | Atlassian


๐Ÿ“ˆ 31.14 Punkte

๐Ÿ“Œ Adding Atlassian Analytics | Atlassian Analytics - Demos | Atlassian


๐Ÿ“ˆ 31.14 Punkte

๐Ÿ“Œ Adding Atlassian Analytics | Atlassian Analytics - Demos | Atlassian


๐Ÿ“ˆ 31.14 Punkte

๐Ÿ“Œ Connecting to the Atlassian Data Lake | Atlassian Analytics - Demos | Atlassian


๐Ÿ“ˆ 31.14 Punkte

๐Ÿ“Œ Atlassian volunteer helps families affected by birth trauma | Atlassian Foundation | Atlassian


๐Ÿ“ˆ 31.14 Punkte

๐Ÿ“Œ Confluence Server/Confluence Data Center up to 6.6.15/6.13.6/6.15.7 Page Export WEB-INF directory traversal


๐Ÿ“ˆ 26.54 Punkte

๐Ÿ“Œ Index your Confluence content using the new Confluence connector V2 for Amazon Kendra


๐Ÿ“ˆ 26.54 Punkte

๐Ÿ“Œ Vuln: Atlassian Confluence CVE-2017-16856 Multiple Cross Site Scripting Vulnerabilities


๐Ÿ“ˆ 24.83 Punkte

๐Ÿ“Œ Low CVE-2017-18085: Atlassian Confluence


๐Ÿ“ˆ 24.83 Punkte

๐Ÿ“Œ Low CVE-2017-18084: Atlassian Confluence


๐Ÿ“ˆ 24.83 Punkte

๐Ÿ“Œ Low CVE-2017-18083: Atlassian Confluence


๐Ÿ“ˆ 24.83 Punkte

๐Ÿ“Œ Low CVE-2017-18086: Atlassian Confluence


๐Ÿ“ˆ 24.83 Punkte

๐Ÿ“Œ AESDDoS bot exploits CVE-2019-3396 flaw to hit Atlassian Confluence Server


๐Ÿ“ˆ 24.83 Punkte











matomo