AFP: I'm logged in 6 times. Am I hacked?
Hello,
Tonight my server was attacked by a 'hacker'. The logs are full of successive invalid login attempts due to incorrect passwords over SMB, while the AFP side of things suggests the user may have been successful.
The "AFP -> Connections" panel of Server Manager indicated that I was logged in six times from an IP address that is not on my subnet. It sounds to me like someone hacked my account and logged in, but I'm curious why AFP/Connections would show the user logged in 6 times, instead of just once. Under what circumstances would someone have six separate connections? Shouldn't there have been just one AFP connection of that user and not six?
If the user just entered my username and then guessed at a password, and then dismisses the dialog and then connects again, would that appear as two connections? (The only MAc we have is the server, so I can't test that theory locally since AFP doesn't allow local connections via AFP)
Any theories or even actual answers would be greatly appreciated!
Thanks
woody
AFP will show one connection per share, not necessarily per user. That means if one user has 6 different sharepoints mounted, you'll see 6 connections listed in the GUI. In addition, connections can be listed for a while after the user actually disconnects - you can set how long an 'idle' connection remains listed in the server config.
That doesn't prove or disprove whether or not you've been 'hacked', but if the IP address is one you don't recognize and don't expect, then it's likely that some rogue user is mounting your server volumes.
You should check whether or not you have guest logins enabled - it may just be the user is logged in as a guest and hasn't actually compromised any of the accounts on your server.
You should also analyze why your AFP and SMB servers are accessible to the outside world. That's hardly a good practice, especially since neither of these protocols will encrypt any data sent over the wire. IMHO running these services on a public server is just asking for trouble. Turn on your firewall at the very least.
Similar Messages
-
ITunes Makes Me Log in Every Time I Open It
iTunes v. 12.0.1.26 and Yosemite updates recently installed. 2012 27" iMac
iTunes makes me log in every time I open it. I thought the problem was fixed in THIS THREAD and it was a very helpful set of instructions by Linc but the problem keeps recurring.
I reposted the question in that thread, but since the thread is marked as solved I'm afraid no one will see it. So I'm reposting here.
Situation:
Upon opening iTunes I get messages popping up telling me to
Sign in to iTunes to use this computer for automatic downloads
Sign in to iTunes for iTunes Radio to use autodowload
Sign in to iTunes to check for downloads
(repeat of) Sign in to iTunes to use this computer for automatic downloads
Sign in to use iTunes Store
These happen one after another, rapidly. Every time. I called Apple help as well and they didn't have any further help.
I've repaired permissions, trashed my plist for iTunes from my Library, done all of Linc's instruction in the other thread.Back up all data before proceeding.
Launch the Keychain Access application in any of the following ways:
☞ Enter the first few letters of its name into a Spotlight search. Select it in the results (it should be at the top.)
☞ In the Finder, select Go ▹ Utilities from the menu bar, or press the key combination shift-command-U. The application is in the folder that opens.
☞ Open LaunchPad. Click Utilities, then Keychain Access in the icon grid.
Select the login keychain from the list on the left side of the Keychain Access window. If your default keychain has a different name, select that.
If the lock icon in the top left corner of the window shows that the keychain is locked, click to unlock it. You'll be prompted for the keychain password, which is the same as your login password, unless you've changed it.
Right-click or control-click the login entry in the list. From the menu that pops up, select
Change Settings for Keychain "login"
In the sheet that opens, uncheck both boxes, if not already unchecked.
From the menu bar, select
Keychain Access ▹ Preferences ▹ First Aid
If the box marked
Keep login keychain unlocked
is not checked, check it.
Select
Keychain Access ▹ Keychain First Aid
from the menu bar and repair the keychain. Quit Keychain Access. -
Since upgrading to itunes v. 12.0.1.26 and Yosemite (same day), iTunes has been making me log in every single time I open it.
Not only that, but it makes me log in several times, for iCloud, for iTunes match, for whatever else we do on iTunes. It gives me like five different reasons to log in, and I have to type my password in five times.
Can anyone tell me what is going on here and how to fix it? Thanks!Back up all data before proceeding.
Launch the Keychain Access application in any of the following ways:
☞ Enter the first few letters of its name into a Spotlight search. Select it in the results (it should be at the top.)
☞ In the Finder, select Go ▹ Utilities from the menu bar, or press the key combination shift-command-U. The application is in the folder that opens.
☞ Open LaunchPad. Click Utilities, then Keychain Access in the icon grid.
Select the login keychain from the list on the left side of the Keychain Access window. If your default keychain has a different name, select that.
If the lock icon in the top left corner of the window shows that the keychain is locked, click to unlock it. You'll be prompted for the keychain password, which is the same as your login password, unless you've changed it.
Right-click or control-click the login entry in the list. From the menu that pops up, select
Change Settings for Keychain "login"
In the sheet that opens, uncheck both boxes, if not already unchecked.
From the menu bar, select
Keychain Access ▹ Preferences ▹ First Aid
If the box marked
Keep login keychain unlocked
is not checked, check it.
Select
Keychain Access ▹ Keychain First Aid
from the menu bar and repair the keychain. Quit Keychain Access. -
I Shut down my Mac by holding in the power button after my iMac froze and now when I try to turn it back it on all I get is the grey screen with Apple loge and the timer and doesn't get any further. I have tried the diagnostic test but nothing was found.
Take each of these steps that you haven't already tried. Stop when the problem is resolved.
To restart an unresponsive computer, press and hold the power button for a few seconds until the power shuts off, then release, wait a few more seconds, and press it again briefly.
Step 1
The first step in dealing with a startup failure is to secure the data. If you want to preserve the contents of the startup drive, and you don't already have at least one current backup, you must try to back up now, before you do anything else. It may or may not be possible. If you don't care about the data that has changed since the last backup, you can skip this step.
There are several ways to back up a Mac that is unable to start. You need an external hard drive to hold the backup data.
a. Start up from the Recovery partition, or from a local Time Machine backup volume (option key at startup.) When the OS X Utilities screen appears, launch Disk Utility and follow the instructions in this support article, under “Instructions for backing up to an external hard disk via Disk Utility.” The article refers to starting up from a DVD, but the procedure in Recovery mode is the same. You don't need a DVD if you're running OS X 10.7 or later.
b. If Step 1a fails because of disk errors, and no other Mac is available, then you may be able to salvage some of your files by copying them in the Finder. If you already have an external drive with OS X installed, start up from it. Otherwise, if you have Internet access, follow the instructions on this page to prepare the external drive and install OS X on it. You'll use the Recovery installer, rather than downloading it from the App Store.
c. If you have access to a working Mac, and both it and the non-working Mac have FireWire or Thunderbolt ports, start the non-working Mac in target disk mode. Use the working Mac to copy the data to another drive. This technique won't work with USB, Ethernet, Wi-Fi, or Bluetooth.
d. If the internal drive of the non-working Mac is user-replaceable, remove it and mount it in an external enclosure or drive dock. Use another Mac to copy the data.
Step 2
If the startup process stops at a blank gray screen with no Apple logo or spinning "daisy wheel," then the startup volume may be full. If you had previously seen warnings of low disk space, this is almost certainly the case. You might be able to start up in safe mode even though you can't start up normally. Otherwise, start up from an external drive, or else use the technique in Step 1b, 1c, or 1d to mount the internal drive and delete some files. According to Apple documentation, you need at least 9 GB of available space on the startup volume (as shown in the Finder Info window) for normal operation.
Step 3
Sometimes a startup failure can be resolved by resetting the NVRAM.
Step 4
If a desktop Mac hangs at a plain gray screen with a movable cursor, the keyboard may not be recognized. Press and hold the button on the side of an Apple wireless keyboard to make it discoverable. If need be, replace or recharge the batteries. If you're using a USB keyboard connected to a hub, connect it to a built-in port.
Step 5
If there's a built-in optical drive, a disc may be stuck in it. Follow these instructions to eject it.
Step 6
Press and hold the power button until the power shuts off. Disconnect all wired peripherals except those needed to start up, and remove all aftermarket expansion cards. Use a different keyboard and/or mouse, if those devices are wired. If you can start up now, one of the devices you disconnected, or a combination of them, is causing the problem. Finding out which one is a process of elimination.
Step 7
If you've started from an external storage device, make sure that the internal startup volume is selected in the Startup Disk pane of System Preferences.
Start up in safe mode. Note: If FileVault is enabled in OS X 10.9 or earlier, or if a firmware password is set, or if the startup volume is a software RAID, you can’t do this. Post for further instructions.
Safe mode is much slower to start and run than normal, and some things won’t work at all, including wireless networking on certain Macs.
The login screen appears even if you usually log in automatically. You must know the login password in order to log in. If you’ve forgotten the password, you will need to reset it before you begin.
When you start up in safe mode, it's normal to see a dark gray progress bar on a light gray background. If the progress bar gets stuck for more than a few minutes, or if the system shuts down automatically while the progress bar is displayed, the startup volume is corrupt and the drive is probably malfunctioning. In that case, go to Step 11. If you ever have another problem with the drive, replace it immediately.
If you can start and log in in safe mode, empty the Trash, and then open the Finder Info window on the startup volume ("Macintosh HD," unless you gave it a different name.) Check that you have at least 9 GB of available space, as shown in the window. If you don't, copy as many files as necessary to another volume (not another folder on the same volume) and delete the originals. Deletion isn't complete until you empty the Trash again. Do this until the available space is more than 9 GB. Then restart as usual (i.e., not in safe mode.)
If the startup process hangs again, the problem is likely caused by a third-party system modification that you installed. Post for further instructions.
Step 8
Launch Disk Utility in Recovery mode (see Step 1.) Select the startup volume, then run Repair Disk. If any problems are found, repeat until clear. If Disk Utility reports that the volume can't be repaired, the drive has malfunctioned and should be replaced. You might choose to tolerate one such malfunction in the life of the drive. In that case, erase the volume and restore from a backup. If the same thing ever happens again, replace the drive immediately.
This is one of the rare situations in which you should also run Repair Permissions, ignoring the false warnings it may produce. Look for the line "Permissions repair complete" at the end of the output. Then restart as usual.
Step 9
If the startup device is an aftermarket SSD, it may need a firmware update and/or a forced "garbage collection." Instructions for doing this with a Crucial-branded SSD were posted here. Some of those instructions may apply to other brands of SSD, but you should check with the vendor's tech support.
Step 10
Reinstall the OS. If the Mac was upgraded from an older version of OS X, you’ll need the Apple ID and password you used to upgrade.
Step 11
Do as in Step 9, but this time erase the startup volume in Disk Utility before installing. The system should automatically restart into the Setup Assistant. Follow the prompts to transfer the data from a Time Machine or other backup.
Step 12
This step applies only to models that have a logic-board ("PRAM") battery: all Mac Pro's and some others (not current models.) Both desktop and portable Macs used to have such a battery. The logic-board battery, if there is one, is separate from the main battery of a portable. A dead logic-board battery can cause a startup failure. Typically the failure will be preceded by loss of the settings for the startup disk and system clock. See the user manual for replacement instructions. You may have to take the machine to a service provider to have the battery replaced.
Step 13
If you get this far, you're probably dealing with a hardware fault. Make a "Genius" appointment at an Apple Store, or go to another authorized service provider. -
Why does itunes have me logging in multiple times to buy a song? I can access everything else fine, but now my account is disabled for some reason although my password was entered correctly... help
I've seen a couple of other threads over the last 10 minutes posting similar problems, so it appears to have affected other people as well - the poster on the first thread has now posted again saying that it's now working for him, so you could give it another try.
Edit : your reply appeared as I was attempting to post this -
my photoshop CC will not work bridge and lightroom 5 open just fine but when i go to open photoshop it asks me to log in every time and when i do and it says im good to continue it just asks me to login again today is the first time i am experienceing this problem i have been using CC for about 2 to 3 months now need this problem fixed asap please
Open the Desktop Application manager. click on the little cog icon > Preferences > Account.
If you sign out, and sign back in again, that will force the Desktop Application Manager to rescan your system and check installed Adobe apps.
I think that the latest updates fixed the 'You have been signed out' problem. If not the fix is a bit long winded, so try first, and if you are stuck I/we will talk you through the fix.
Photoshop: Basic Troubleshooting steps to fix most issues -
When trying to log into face time I get the registering device does not have appropriate credentials after I sign in, I have OSX 10.8.4 on my Mac Pro. I can log into face time without a problem using my IPAD.>
Please take each of the following steps that you haven't already tried, until the issue is reolved. If there's no resolution after Step 3, post your results.
Step 1
Sign out of iMessage in the Accounts tab of the preferences dialog, then sign back in.
Step 2
Log out of your user account and log back in.
Step 3
Boot in safe mode and test, then reboot as usual and test again.
Note: If FileVault is enabled on some models, or if a firmware password is set, or if the boot volume is a software RAID, you can’t do this. Ask for further instructions.
Safe mode is much slower to boot and run than normal, and some things won’t work at all, including sound output and Wi-Fi on certain iMacs. The next normal boot may also be somewhat slow.
The login screen appears even if you usually log in automatically. You must know your login password in order to log in. If you’ve forgotten the password, you will need to reset it before you begin. -
It says error logging in every time i try converting a PDF to word docx
it says error logging in every time i try converting a PDF to word docx. whats wrong?
Convert how? ExportPDF? → http://forums.adobe.com/community/exportpdf
-
Logging on every time makes the app much less useful.
That wouldn't protect your friends.
Not sure why you are averse to using a screenlock, you run a precarious line by not doing. -
For some reason my Firefox is no longer allowing me to stay logged on to certain sites e.g. Even though I now allows click the keep the keep me logged in on facebook I now have to log on each time. How do I fix this.
Kind regards
Bev GreeneWebsites remembering you and automatically log you in is stored in a cookie.
* Create an allow cookie exception (Tools > Options > Privacy > Cookies: Exceptions) to keep such a cookie, especially for secure websites and if cookies expire when Firefox is closed.
Make sure that you do not run Firefox in Private Browsing mode.
* https://support.mozilla.com/kb/Private+Browsing
* In [[Private Browsing]] mode all cookies are session cookies that expire if that session is ended, so websites won't remember you.
* Do not use [[Clear Recent History]] to clear the "Cookies" and the "Site Preferences"
Clearing "Site Preferences" clears all exceptions for cookies, images, pop-up windows, software installation, and passwords.
* http://kb.mozillazine.org/Cookies -
Logging start & end time of map execution
Hello,
I want to log start & end time of execution of my map (OWB 11g), so I've created a table for this purpose and I used it in every map that I want to log time, twice; First for logging start time, and second for end time.
I pass a constant with SYSTIMESTAMP value through my log table and also name of my map. but the problem is, both of my records' time (start & end) are very near to each other (difference is in milliseconds!) however my map takes time for more than 2 minutes! So, I've changed my map Target Load Order to: [log table for start time] + [Main tables of my map] + [log table for end time]. I've set my map Use Target Load Ordering option True, too.
Why it doesn't work? Is there any better solution for logging every map execution time in a table, or not?
Please help me ...
Thanks.To do that, I have created a view that lists all processes that are running or finished. The view contains fields:
process_name
process_type (plsqlmap, plsqlprocedure, processflow, etc)
run_status (success, error, etc)
start_time
end_time
elapse_time
inserted
updated
deleted
merged
You could insert into your log table using select x from this view after every map, or, how I do it, is to insert into log table after every process flow. That is, after my process flow is complete I then select all of the details for the maps of the process flow and insert those details into my log table.
Here is the SQL for my view. This is for 10.2.0.3. For
CREATE OR REPLACE FORCE VIEW BATCH_STATUS_LOG_REP_V
AS
(SELECT PROCESS_NAME,
PROCESS_TYPE_SYMBOL,
(CASE
WHEN RUN_STATUS_SYMBOL IN ('COMPLETE_OK', 'COMPLETE') THEN 'SUCCESS'
WHEN RUN_STATUS_SYMBOL IN ('COMPLETE_FAILURE') THEN 'ERROR'
WHEN RUN_STATUS_SYMBOL IN ('COMPLETE_OK_WITH_WARNINGS') THEN 'WARNINGS'
ELSE 'NA'
END
) RUN_STATUS_SYMBOL,
START_TIME,
END_TIME,
ELAPSE_TIME,
NUMBER_RECORDS_INSERTED,
NUMBER_RECORDS_UPDATED,
NUMBER_RECORDS_DELETED,
NUMBER_RECORDS_MERGED
FROM OWB_RUN.RAB_RT_EXEC_PROC_RUN_COUNTS
WHERE TRUNC (START_TIME) >= TRUNC (SYSDATE) - 3)
ORDER BY START_TIME DESC; -
Oracle Performance 11g - Warning: log write elapsed time
Hello ,
We are facing quite bad performance with our SAP cluster running Oracle 11g .
In the ora alert file we are having constant message for "
Thread 1 cannot allocate new log, sequence xxxxxx
Private strand flush not complete"
However , this seems to be quite old as we have recently started facing the performace issue.
Moreover , in the sid_lgwr_788.trc file we are getting warning for log write elapsed time as follow.
*** 2013-07-25 08:43:07.098
Warning: log write elapsed time 722ms, size 4KB
*** 2013-07-25 08:44:07.069
Warning: log write elapsed time 741ms, size 32KB
*** 2013-07-25 08:44:11.134
Warning: log write elapsed time 1130ms, size 23KB
*** 2013-07-25 08:44:15.508
Warning: log write elapsed time 1161ms, size 25KB
*** 2013-07-25 08:44:19.790
Warning: log write elapsed time 1210ms, size 10KB
*** 2013-07-25 08:44:20.748
Warning: log write elapsed time 544ms, size 3KB
*** 2013-07-25 08:44:24.396
Warning: log write elapsed time 1104ms, size 14KB
*** 2013-07-25 08:44:28.955
Warning: log write elapsed time 1032ms, size 37KB
*** 2013-07-25 08:45:13.115
Warning: log write elapsed time 1096ms, size 3KB
*** 2013-07-25 08:45:46.995
Warning: log write elapsed time 539ms, size 938KB
*** 2013-07-25 08:47:55.424
Warning: log write elapsed time 867ms, size 566KB
*** 2013-07-25 08:48:00.288
Warning: log write elapsed time 871ms, size 392KB
*** 2013-07-25 08:48:04.514
Warning: log write elapsed time 672ms, size 2KB
*** 2013-07-25 08:48:08.788
Warning: log write elapsed time 745ms, size 466KB
Please advice to further understand the issue.
RegardsHi,
Seem the I/O issue, Check the metalink id
Intermittent Long 'log file sync' Waits, LGWR Posting Long Write Times, I/O Portion of Wait Minimal (Doc ID 1278149.1) -
Are You Having To Log In Every Time - Or Is It Just Me?
In the past couple of days I have to log in every time I visit the forum with a fresh browser window, even though I click the [ ] Remember Me checkbox during login.
Is this something I've neglected to flush/clear, or am I not alone? This is a definite change between pre- and post-update, and I haven't done anything else to my system, which is otherwise functioning perfectly.
Why is it so much to ask that things just work the way they're supposed to? Through these little things those of us who help Adobe's customers are made to feel more and more unwanted.
-NoelHm, I seem to have worked around it...
Somehow my "Delete Browsing History On Exit" option was set in IE. Clearing that seems to have made it possible for me to be logged in persistently. Perhaps someone used my computer and wanted to cover their tracks. I'm not sure I would expect the "browsing history" to affect my login status, but I suppose it could make some kind of sense.
I don't see how that would affect my iPhone, though, but just now I found I was persistently logged-in there as well when I started Safari.
Possibly something was coincidentally changed at Adobe.com in the last 10 minutes? If so, thanks for the fix, whomever did it!
Anyway, I seem to be back to having more convenient forum access.
-Noel -
my creative cloud will not let me sign in. it keeps saying you have been logged out every time i sign in
Hi,
Please follow the below steps to remove the error message of "You have been signed out".
1: Open Activity monitor from spotlight and end all Adobe related processes. You may find processes like AAMupdater, AAMupdater notifier, Adobe Crash demon process.
2: Open a Finder window, select Go>Go to folder option, type in ~/Library and hit enter.
(Windows: [System drive]:\Users\[user name]\AppData\Local\Adobe\OOBE)
3: Now navigate to Application Support/Adobe/OOBE/.. folder.
4: Delete opm file under OOBE.
5: Rename OOBE to OOBEold.
6: Check if you have AAMupdater in the same location.
7: Please rename it to AAMupdaterold.
8: Click on gear icon on Creative Cloud desktop app and choose Quit Creative Cloud.
9: Then launch it, sign-in and click on Apps tab.
The error message will be removed. -
Hello,
why I have to log in three times after update to OS X Yosemite 10.10.1 at iTunes 12.1.0.26?
Best regardssa-update failed so ran with -D:
# sa-update -D --nogpg
Nov 5 17:41:45.618 [70835] dbg: generic: lint check of site pre files succeeded, continuing with channel updates
Nov 5 17:41:45.618 [70835] dbg: channel: protocol family available: inet,inet6
Nov 5 17:41:45.635 [70835] dbg: channel: no mirror file /Library/Server/Mail/Data/scanner/spamassassin/3.004000/updates_spamassassin_or g/MIRRORED.BY, will fetch it
Nov 5 17:41:45.635 [70835] dbg: channel: DNS lookup on mirrors.updates.spamassassin.org
Nov 5 17:43:29.858 [70835] dbg: dns: query failed: mirrors.updates.spamassassin.org => SERVFAIL
error: no mirror data available for channel updates.spamassassin.org
channel: MIRRORED.BY file URL was not in DNS, channel failed
Nov 5 17:43:29.858 [70835] dbg: generic: cleaning up temporary directory/files
Nov 5 17:43:29.858 [70835] dbg: generic: cleaning directory /tmp/.spamassassin70835D8L50dtmp
Nov 5 17:43:29.859 [70835] dbg: diag: updates complete, exiting with code 4
# cd /Library/Server/Mail/Data/scanner/spamassassin/3.004000/updates_spamassassin_or g
# curl -O http://spamassassin.apache.org/updates/MIRRORED.BY
% Total % Received % Xferd Average Speed Time Time Time Current
Dload Upload Total Spent Left Speed
100 718 100 718 0 0 5854 0 --:--:-- --:--:-- --:--:-- 5885
# sa-update -D --nogpg
Nov 5 17:49:39.044 [71190] dbg: diag: updates complete, exiting with code 0
I can now receive new mails at both domains on my server and all of the emails received when the server was "down" are starting to trickle through.
Thanks for your assistance.
Maybe you are looking for
-
Excise duty not getting captured for export scenario-Urgent
Dear All, When I am creating the export sales scenario then excise component is showing in condition records, even while creating the excise invoice the excise component reflects in the invoice. But once the excise invoice is saved & i go to display
-
Print is small and in middle top of page. When I click Print Preview, the page is now smaller than it was the day before. I've tried config reset printer-printer. Shrink to fit, custom printing sizes, adjusted font size, etc, etc. Nothing has work. N
-
SD related user-exits scenarios
Hi Gurus, Can anyone of you please send me some real time SD related user-exits scenarios. Thanks, Rajeev !!!
-
Mutiple currency via Pre-approved expenditure batches...
Dear Dina, In PAE batches can we enter the expense transaction in other than functional currency...which field is enhancing such foreign currency transaction..... do rate types(corporate) work behind it for converting to functional currency... plssss
-
Dear all, is there any TC/Report which I can use to receive the following data for customer invoices: - Customer No - Name - Invoice No. - Inovice date - Amount - Insured amount (KNB1-VLIBB) - Text Please let me know. Thankds Josip