Scanning for Confluence CVE-2022-26134, (Fri, Mar 1st)

I have added daemonlogger [1] for packet capture and Arkime [2] to visualize the packets captured by my DShield sensor and started noticing this activity that so far only gone to TCP/8090 which is URL and base64 encoded. The DShield sensor started capturing this activity on the 12 February 2024 inbound from various IPs from various locations.

Continue reading Scanning for Confluence CVE-2022-26134, (Fri, Mar 1st)

Posted in Uncategorized

Exploit Attempts for Unknown Password Reset Vulnerability, (Wed, Feb 28th)

My Google skills let me down this morning, attempting to figure out which vulnerability is exactly being exploited by these “forgotuserpassword.action” scans. Maybe someone else can help me out here. Based on the scans, I do not believe this is a “normal” password reset vulnerability. Atlassian&#;x26;#;39;s Confluence is one suspect using a URL scheme like this, but there may be others. Here are some of the URLs:

Continue reading Exploit Attempts for Unknown Password Reset Vulnerability, (Wed, Feb 28th)

Posted in Uncategorized

Take Downs and the Rest of Us: Do they matter?, (Tue, Feb 27th)

Last week, the US Department of Justice published a press release entitled “Justice Department Conducts Court-Authorized Disruption of Botnet Controlled by the Russian Federation’s Main Intelligence Directorate of the General Staff (GRU)” [1]. The disruption targeted a botnet built using the “Moobot” malware. According to the press release, this particular botnet focused on routers made by Ubiquity, using well-known default credentials.

Continue reading Take Downs and the Rest of Us: Do they matter?, (Tue, Feb 27th)

Posted in Uncategorized