HACKED: Oracle WebLogic Bitcoin/Blockchain Mining HACK Event
Apply below procedure to mitigate the HACKING event!
2 min readAug 20, 2024
Procedure to Mitigate Oracle WebLogic HACKING Event Mitigate Oracle WebLogic Server
If you have below script in your bash profile and a suspicious cronjob in your server. This means you have been HACKED. Your Oracle WebLogic server has been hacked. That’s why your server’s CPU usage is high and bitcoin mining is consuming your server’s CPUs.
Apply below procedure to mitigate the HACKING event!
- Close and disable outbound internet access from your server.
- Close and disable inbound internet access to your WebLogic console and managed server ports.
- Disable WebLogic t3 protocol access.
- Apply the latest Oracle WebLogic patches.
- Apply the latest Java JDK update to your environment.
- Disable WebLogic console access from internet permanently.
- Put Reverse proxy webserver infront of Oracle WebLogic http ports.
Mining Script for WebLogic Hacking
Oracle WebLogic Mining HACK Script
✅ LinkedIn Follow
Follow to learn…
Follow on LinkedIn: https://linkedin.com/in/mfevzikorkutata