AFP: I'm logged in 6 times. Am I hacked?

Hello,
Tonight my server was attacked by a 'hacker'. The logs are full of successive invalid login attempts due to incorrect passwords over SMB, while the AFP side of things suggests the user may have been successful.
The "AFP -> Connections" panel of Server Manager indicated that I was logged in six times from an IP address that is not on my subnet. It sounds to me like someone hacked my account and logged in, but I'm curious why AFP/Connections would show the user logged in 6 times, instead of just once. Under what circumstances would someone have six separate connections? Shouldn't there have been just one AFP connection of that user and not six?
If the user just entered my username and then guessed at a password, and then dismisses the dialog and then connects again, would that appear as two connections? (The only MAc we have is the server, so I can't test that theory locally since AFP doesn't allow local connections via AFP)
Any theories or even actual answers would be greatly appreciated!
Thanks
woody

AFP will show one connection per share, not necessarily per user. That means if one user has 6 different sharepoints mounted, you'll see 6 connections listed in the GUI. In addition, connections can be listed for a while after the user actually disconnects - you can set how long an 'idle' connection remains listed in the server config.
That doesn't prove or disprove whether or not you've been 'hacked', but if the IP address is one you don't recognize and don't expect, then it's likely that some rogue user is mounting your server volumes.
You should check whether or not you have guest logins enabled - it may just be the user is logged in as a guest and hasn't actually compromised any of the accounts on your server.
You should also analyze why your AFP and SMB servers are accessible to the outside world. That's hardly a good practice, especially since neither of these protocols will encrypt any data sent over the wire. IMHO running these services on a public server is just asking for trouble. Turn on your firewall at the very least.

Similar Messages

  • ITunes Makes Me Log in Every Time I Open It

    iTunes v. 12.0.1.26 and Yosemite updates recently installed. 2012 27" iMac
    iTunes makes me log in every time I open it. I thought the problem was fixed in THIS THREAD and it was a very helpful set of instructions by Linc but the problem keeps recurring.
    I reposted the question in that thread, but since the thread is marked as solved I'm afraid no one will see it. So I'm reposting here.
    Situation:
    Upon opening iTunes I get messages popping up telling me to
    Sign in to iTunes to use this computer for automatic downloads
    Sign in to iTunes for iTunes Radio to use autodowload
    Sign in to iTunes to check for downloads
    (repeat of) Sign in to iTunes to use this computer for automatic downloads
    Sign in to use iTunes Store
    These happen one after another, rapidly. Every time. I called Apple help as well and they didn't have any further help.
    I've repaired permissions, trashed my plist for iTunes from my Library, done all of Linc's instruction in the other thread.

    Back up all data before proceeding.
    Launch the Keychain Access application in any of the following ways:
    ☞ Enter the first few letters of its name into a Spotlight search. Select it in the results (it should be at the top.)
    ☞ In the Finder, select Go ▹ Utilities from the menu bar, or press the key combination shift-command-U. The application is in the folder that opens.
    ☞ Open LaunchPad. Click Utilities, then Keychain Access in the icon grid.
    Select the login keychain from the list on the left side of the Keychain Access window. If your default keychain has a different name, select that.
    If the lock icon in the top left corner of the window shows that the keychain is locked, click to unlock it. You'll be prompted for the keychain password, which is the same as your login password, unless you've changed it.
    Right-click or control-click the login entry in the list. From the menu that pops up, select
              Change Settings for Keychain "login"
    In the sheet that opens, uncheck both boxes, if not already unchecked.
    From the menu bar, select
              Keychain Access ▹ Preferences ▹ First Aid
    If the box marked
              Keep login keychain unlocked
    is not checked, check it.
    Select
              Keychain Access ▹ Keychain First Aid
    from the menu bar and repair the keychain. Quit Keychain Access.

  • Why does iTunes make me log in every time I open it since upgrading to v.12.0.1.26 and Yosemite?

    Since upgrading to itunes v. 12.0.1.26 and Yosemite (same day), iTunes has been making me log in every single time I open it.
    Not only that, but it makes me log in several times, for iCloud, for iTunes match, for whatever else we do on iTunes. It gives me like five different reasons to log in, and I have to type my password in five times.
    Can anyone tell me what is going on here and how to fix it? Thanks!

    Back up all data before proceeding.
    Launch the Keychain Access application in any of the following ways:
    ☞ Enter the first few letters of its name into a Spotlight search. Select it in the results (it should be at the top.)
    ☞ In the Finder, select Go ▹ Utilities from the menu bar, or press the key combination shift-command-U. The application is in the folder that opens.
    ☞ Open LaunchPad. Click Utilities, then Keychain Access in the icon grid.
    Select the login keychain from the list on the left side of the Keychain Access window. If your default keychain has a different name, select that.
    If the lock icon in the top left corner of the window shows that the keychain is locked, click to unlock it. You'll be prompted for the keychain password, which is the same as your login password, unless you've changed it.
    Right-click or control-click the login entry in the list. From the menu that pops up, select
              Change Settings for Keychain "login"
    In the sheet that opens, uncheck both boxes, if not already unchecked.
    From the menu bar, select
              Keychain Access ▹ Preferences ▹ First Aid
    If the box marked
              Keep login keychain unlocked
    is not checked, check it.
    Select
              Keychain Access ▹ Keychain First Aid
    from the menu bar and repair the keychain. Quit Keychain Access.

  • My mac froze in an application so I shut it down by powering off with button, now when I try to turn it on I have a grey screen with Apple loge and the timer swirling but it doesn't get past this, please help!

    I Shut down my Mac by holding in the power button after my iMac froze and now when I try to turn it back it on all I get is the grey screen with Apple loge and the timer and doesn't get any further.  I have tried the diagnostic test but nothing was found.

    Take each of these steps that you haven't already tried. Stop when the problem is resolved.
    To restart an unresponsive computer, press and hold the power button for a few seconds until the power shuts off, then release, wait a few more seconds, and press it again briefly.
    Step 1
    The first step in dealing with a startup failure is to secure the data. If you want to preserve the contents of the startup drive, and you don't already have at least one current backup, you must try to back up now, before you do anything else. It may or may not be possible. If you don't care about the data that has changed since the last backup, you can skip this step.
    There are several ways to back up a Mac that is unable to start. You need an external hard drive to hold the backup data.
    a. Start up from the Recovery partition, or from a local Time Machine backup volume (option key at startup.) When the OS X Utilities screen appears, launch Disk Utility and follow the instructions in this support article, under “Instructions for backing up to an external hard disk via Disk Utility.” The article refers to starting up from a DVD, but the procedure in Recovery mode is the same. You don't need a DVD if you're running OS X 10.7 or later.
    b. If Step 1a fails because of disk errors, and no other Mac is available, then you may be able to salvage some of your files by copying them in the Finder. If you already have an external drive with OS X installed, start up from it. Otherwise, if you have Internet access, follow the instructions on this page to prepare the external drive and install OS X on it. You'll use the Recovery installer, rather than downloading it from the App Store.
    c. If you have access to a working Mac, and both it and the non-working Mac have FireWire or Thunderbolt ports, start the non-working Mac in target disk mode. Use the working Mac to copy the data to another drive. This technique won't work with USB, Ethernet, Wi-Fi, or Bluetooth.
    d. If the internal drive of the non-working Mac is user-replaceable, remove it and mount it in an external enclosure or drive dock. Use another Mac to copy the data.
    Step 2
    If the startup process stops at a blank gray screen with no Apple logo or spinning "daisy wheel," then the startup volume may be full. If you had previously seen warnings of low disk space, this is almost certainly the case. You might be able to start up in safe mode even though you can't start up normally. Otherwise, start up from an external drive, or else use the technique in Step 1b, 1c, or 1d to mount the internal drive and delete some files. According to Apple documentation, you need at least 9 GB of available space on the startup volume (as shown in the Finder Info window) for normal operation.
    Step 3
    Sometimes a startup failure can be resolved by resetting the NVRAM.
    Step 4
    If a desktop Mac hangs at a plain gray screen with a movable cursor, the keyboard may not be recognized. Press and hold the button on the side of an Apple wireless keyboard to make it discoverable. If need be, replace or recharge the batteries. If you're using a USB keyboard connected to a hub, connect it to a built-in port.
    Step 5
    If there's a built-in optical drive, a disc may be stuck in it. Follow these instructions to eject it.
    Step 6
    Press and hold the power button until the power shuts off. Disconnect all wired peripherals except those needed to start up, and remove all aftermarket expansion cards. Use a different keyboard and/or mouse, if those devices are wired. If you can start up now, one of the devices you disconnected, or a combination of them, is causing the problem. Finding out which one is a process of elimination.
    Step 7
    If you've started from an external storage device, make sure that the internal startup volume is selected in the Startup Disk pane of System Preferences.
    Start up in safe mode. Note: If FileVault is enabled in OS X 10.9 or earlier, or if a firmware password is set, or if the startup volume is a software RAID, you can’t do this. Post for further instructions.
    Safe mode is much slower to start and run than normal, and some things won’t work at all, including wireless networking on certain Macs.
    The login screen appears even if you usually log in automatically. You must know the login password in order to log in. If you’ve forgotten the password, you will need to reset it before you begin.
    When you start up in safe mode, it's normal to see a dark gray progress bar on a light gray background. If the progress bar gets stuck for more than a few minutes, or if the system shuts down automatically while the progress bar is displayed, the startup volume is corrupt and the drive is probably malfunctioning. In that case, go to Step 11. If you ever have another problem with the drive, replace it immediately.
    If you can start and log in in safe mode, empty the Trash, and then open the Finder Info window on the startup volume ("Macintosh HD," unless you gave it a different name.) Check that you have at least 9 GB of available space, as shown in the window. If you don't, copy as many files as necessary to another volume (not another folder on the same volume) and delete the originals. Deletion isn't complete until you empty the Trash again. Do this until the available space is more than 9 GB. Then restart as usual (i.e., not in safe mode.)
    If the startup process hangs again, the problem is likely caused by a third-party system modification that you installed. Post for further instructions.
    Step 8
    Launch Disk Utility in Recovery mode (see Step 1.) Select the startup volume, then run Repair Disk. If any problems are found, repeat until clear. If Disk Utility reports that the volume can't be repaired, the drive has malfunctioned and should be replaced. You might choose to tolerate one such malfunction in the life of the drive. In that case, erase the volume and restore from a backup. If the same thing ever happens again, replace the drive immediately.
    This is one of the rare situations in which you should also run Repair Permissions, ignoring the false warnings it may produce. Look for the line "Permissions repair complete" at the end of the output. Then restart as usual.
    Step 9
    If the startup device is an aftermarket SSD, it may need a firmware update and/or a forced "garbage collection." Instructions for doing this with a Crucial-branded SSD were posted here. Some of those instructions may apply to other brands of SSD, but you should check with the vendor's tech support.  
    Step 10
    Reinstall the OS. If the Mac was upgraded from an older version of OS X, you’ll need the Apple ID and password you used to upgrade.
    Step 11
    Do as in Step 9, but this time erase the startup volume in Disk Utility before installing. The system should automatically restart into the Setup Assistant. Follow the prompts to transfer the data from a Time Machine or other backup.
    Step 12
    This step applies only to models that have a logic-board ("PRAM") battery: all Mac Pro's and some others (not current models.) Both desktop and portable Macs used to have such a battery. The logic-board battery, if there is one, is separate from the main battery of a portable. A dead logic-board battery can cause a startup failure. Typically the failure will be preceded by loss of the settings for the startup disk and system clock. See the user manual for replacement instructions. You may have to take the machine to a service provider to have the battery replaced.
    Step 13
    If you get this far, you're probably dealing with a hardware fault. Make a "Genius" appointment at an Apple Store, or go to another authorized service provider.

  • HT1911 Why does Itunes have me logging in multiple times to buy a song? Somehow, my account got disabled now. It also shows that I am logged in....?

    Why does itunes have me logging in multiple times to buy a song? I can access everything else fine, but now my account is disabled for some reason although my password was entered correctly... help

    I've seen a couple of other threads over the last 10 minutes posting similar problems, so it appears to have affected other people as well - the poster on the first thread has now posted again saying that it's now working for him, so you could give it another try.
    Edit : your reply appeared as I was attempting to post this

  • Photoshop CC wont open it asks me to log in every time and when i do and it says im good to continue it just asks me to login again

    my photoshop CC will not work bridge and lightroom 5 open just fine but when i go to open photoshop it asks me to log in every time and when i do and it says im good to continue it just asks me to login again today is the first time i am experienceing this problem i have been using CC for about 2 to 3 months now need this problem fixed asap please

    Open the Desktop Application manager.  click on the little cog icon > Preferences > Account.
    If you sign out, and sign back in again, that will force the Desktop Application Manager to rescan your system and check installed Adobe apps.
    I think that the latest updates fixed the 'You have been signed out' problem.  If not the fix is a bit long winded, so try first, and if you are stuck I/we will talk you through the fix.
    Photoshop: Basic Troubleshooting steps to fix most issues

  • HT204408 When trying to log into face time I get the registering device does not have appropriate credentials, I have OSX 10.8.4 on my Mac Pro. I can log in using my IPAD

    When trying to log into face time I get the registering device does not have appropriate credentials after I sign in, I have OSX 10.8.4 on my Mac Pro. I can log into face time without a problem using my IPAD.>

    Please take each of the following steps that you haven't already tried, until the issue is reolved. If there's no resolution after Step 3, post your results.
    Step 1
    Sign out of iMessage in the Accounts tab of the preferences dialog, then sign back in.
    Step 2
    Log out of your user account and log back in.
    Step 3
    Boot in safe mode and test, then reboot as usual and test again.
    Note: If FileVault is enabled on some models, or if a firmware password is set, or if the boot volume is a software RAID, you can’t do this. Ask for further instructions.
    Safe mode is much slower to boot and run than normal, and some things won’t work at all, including sound output and  Wi-Fi on certain iMacs. The next normal boot may also be somewhat slow.
    The login screen appears even if you usually log in automatically. You must know your login password in order to log in. If you’ve forgotten the password, you will need to reset it before you begin.

  • It says error logging in every time i try converting a PDF to word docx

    it says error logging in every time i try converting a PDF to word docx. whats wrong?

    Convert how?  ExportPDF?  → http://forums.adobe.com/community/exportpdf

  • HT201493 why do I have to log on  every time I want to use this app?  Logging on is a collosal pain,

    Logging on every time makes the app much less useful.

    That wouldn't protect your friends.
    Not sure why you are averse to using a screenlock, you run a precarious line by not doing.

  • For some reason my Firefox is no longer allowing me to stay logged on to certain sites e.g. Even though I now allows click the keep the keep me logged in on facebook I now have to log on each time. How do I fix this. Kind regards Bev Greene

    For some reason my Firefox is no longer allowing me to stay logged on to certain sites e.g. Even though I now allows click the keep the keep me logged in on facebook I now have to log on each time. How do I fix this.
    Kind regards
    Bev Greene

    Websites remembering you and automatically log you in is stored in a cookie.
    * Create an allow cookie exception (Tools > Options > Privacy > Cookies: Exceptions) to keep such a cookie, especially for secure websites and if cookies expire when Firefox is closed.
    Make sure that you do not run Firefox in Private Browsing mode.
    * https://support.mozilla.com/kb/Private+Browsing
    * In [[Private Browsing]] mode all cookies are session cookies that expire if that session is ended, so websites won't remember you.
    * Do not use [[Clear Recent History]] to clear the "Cookies" and the "Site Preferences"
    Clearing "Site Preferences" clears all exceptions for cookies, images, pop-up windows, software installation, and passwords.
    * http://kb.mozillazine.org/Cookies

  • Logging start & end time of map execution

    Hello,
    I want to log start & end time of execution of my map (OWB 11g), so I've created a table for this purpose and I used it in every map that I want to log time, twice; First for logging start time, and second for end time.
    I pass a constant with SYSTIMESTAMP value through my log table and also name of my map. but the problem is, both of my records' time (start & end) are very near to each other (difference is in milliseconds!) however my map takes time for more than 2 minutes! So, I've changed my map Target Load Order to: [log table for start time] + [Main tables of my map] + [log table for end time]. I've set my map Use Target Load Ordering option True, too.
    Why it doesn't work? Is there any better solution for logging every map execution time in a table, or not?
    Please help me ...
    Thanks.

    To do that, I have created a view that lists all processes that are running or finished. The view contains fields:
    process_name
    process_type (plsqlmap, plsqlprocedure, processflow, etc)
    run_status (success, error, etc)
    start_time
    end_time
    elapse_time
    inserted
    updated
    deleted
    merged
    You could insert into your log table using select x from this view after every map, or, how I do it, is to insert into log table after every process flow. That is, after my process flow is complete I then select all of the details for the maps of the process flow and insert those details into my log table.
    Here is the SQL for my view. This is for 10.2.0.3. For
    CREATE OR REPLACE FORCE VIEW BATCH_STATUS_LOG_REP_V
    AS
    (SELECT PROCESS_NAME,
    PROCESS_TYPE_SYMBOL,
    (CASE
    WHEN RUN_STATUS_SYMBOL IN ('COMPLETE_OK', 'COMPLETE') THEN 'SUCCESS'
    WHEN RUN_STATUS_SYMBOL IN ('COMPLETE_FAILURE') THEN 'ERROR'
    WHEN RUN_STATUS_SYMBOL IN ('COMPLETE_OK_WITH_WARNINGS') THEN 'WARNINGS'
    ELSE 'NA'
    END
    ) RUN_STATUS_SYMBOL,
    START_TIME,
    END_TIME,
    ELAPSE_TIME,
    NUMBER_RECORDS_INSERTED,
    NUMBER_RECORDS_UPDATED,
    NUMBER_RECORDS_DELETED,
    NUMBER_RECORDS_MERGED
    FROM OWB_RUN.RAB_RT_EXEC_PROC_RUN_COUNTS
    WHERE TRUNC (START_TIME) >= TRUNC (SYSDATE) - 3)
    ORDER BY START_TIME DESC;

  • Oracle Performance 11g - Warning: log write elapsed time

    Hello ,
    We are facing quite bad performance with our SAP cluster running Oracle 11g .
    In the ora alert file we are having constant message for "
    Thread 1 cannot allocate new log, sequence xxxxxx
    Private strand flush not complete"
    However , this seems to be quite old as we have recently started facing the performace issue.
    Moreover , in the sid_lgwr_788.trc file we are getting warning for log write elapsed time as follow.
    *** 2013-07-25 08:43:07.098
    Warning: log write elapsed time 722ms, size 4KB
    *** 2013-07-25 08:44:07.069
    Warning: log write elapsed time 741ms, size 32KB
    *** 2013-07-25 08:44:11.134
    Warning: log write elapsed time 1130ms, size 23KB
    *** 2013-07-25 08:44:15.508
    Warning: log write elapsed time 1161ms, size 25KB
    *** 2013-07-25 08:44:19.790
    Warning: log write elapsed time 1210ms, size 10KB
    *** 2013-07-25 08:44:20.748
    Warning: log write elapsed time 544ms, size 3KB
    *** 2013-07-25 08:44:24.396
    Warning: log write elapsed time 1104ms, size 14KB
    *** 2013-07-25 08:44:28.955
    Warning: log write elapsed time 1032ms, size 37KB
    *** 2013-07-25 08:45:13.115
    Warning: log write elapsed time 1096ms, size 3KB
    *** 2013-07-25 08:45:46.995
    Warning: log write elapsed time 539ms, size 938KB
    *** 2013-07-25 08:47:55.424
    Warning: log write elapsed time 867ms, size 566KB
    *** 2013-07-25 08:48:00.288
    Warning: log write elapsed time 871ms, size 392KB
    *** 2013-07-25 08:48:04.514
    Warning: log write elapsed time 672ms, size 2KB
    *** 2013-07-25 08:48:08.788
    Warning: log write elapsed time 745ms, size 466KB
    Please advice to further understand the issue.
    Regards

    Hi,
    Seem the I/O issue, Check the metalink id
    Intermittent Long 'log file sync' Waits, LGWR Posting Long Write Times, I/O Portion of Wait Minimal (Doc ID 1278149.1)

  • Are You Having To Log In Every Time - Or Is It Just Me?

    In the past couple of days I have to log in every time I visit the forum with a fresh browser window, even though I click the [  ] Remember Me checkbox during login.
    Is this something I've neglected to flush/clear, or am I not alone?  This is a definite change between pre- and post-update, and I haven't done anything else to my system, which is otherwise functioning perfectly.
    Why is it so much to ask that things just work the way they're supposed to?  Through these little things those of us who help Adobe's customers are made to feel more and more unwanted.
    -Noel

    Hm, I seem to have worked around it...
    Somehow my "Delete Browsing History On Exit" option was set in IE.  Clearing that seems to have made it possible for me to be logged in persistently.  Perhaps someone used my computer and wanted to cover their tracks.  I'm not sure I would expect the "browsing history" to affect my login status, but I suppose it could make some kind of sense.
    I don't see how that would affect my iPhone, though, but just now I found I was persistently logged-in there as well when I started Safari.
    Possibly something was coincidentally changed at Adobe.com in the last 10 minutes?  If so, thanks for the fix, whomever did it!
    Anyway, I seem to be back to having more convenient forum access.
    -Noel

  • My creative cloud will not let me sign in. it keeps saying you have been logged out every time i sign in

    my creative cloud will not let me sign in. it keeps saying you have been logged out every time i sign in

    Hi,
    Please follow the below steps to remove the error message of "You have been signed out".
              1: Open Activity monitor from spotlight and end all Adobe related processes. You may find processes like AAMupdater, AAMupdater notifier, Adobe Crash demon process.
              2: Open a Finder window, select Go>Go to folder option, type in ~/Library and hit enter.
                             (Windows:  [System drive]:\Users\[user name]\AppData\Local\Adobe\OOBE)
              3: Now navigate to Application Support/Adobe/OOBE/.. folder.
              4: Delete opm file under OOBE.
              5: Rename OOBE to OOBEold.
              6: Check if you have AAMupdater in the same location.
              7: Please rename it to AAMupdaterold.
              8: Click on gear icon on Creative Cloud desktop app and choose Quit Creative Cloud.
              9: Then launch it, sign-in and click on Apps tab.
    The error message will be removed.

  • Log in three times after update to OS X Yosemite 10.10.1 at iTunes 12.1.0.26

    Hello,
    why I have to log in three times after update to OS X Yosemite 10.10.1 at iTunes 12.1.0.26?
    Best regards

    sa-update failed so ran with -D:
    # sa-update -D --nogpg
    Nov  5 17:41:45.618 [70835] dbg: generic: lint check of site pre files succeeded, continuing with channel updates
    Nov  5 17:41:45.618 [70835] dbg: channel: protocol family available: inet,inet6
    Nov  5 17:41:45.635 [70835] dbg: channel: no mirror file /Library/Server/Mail/Data/scanner/spamassassin/3.004000/updates_spamassassin_or g/MIRRORED.BY, will fetch it
    Nov  5 17:41:45.635 [70835] dbg: channel: DNS lookup on mirrors.updates.spamassassin.org
    Nov  5 17:43:29.858 [70835] dbg: dns: query failed: mirrors.updates.spamassassin.org => SERVFAIL
    error: no mirror data available for channel updates.spamassassin.org
    channel: MIRRORED.BY file URL was not in DNS, channel failed
    Nov  5 17:43:29.858 [70835] dbg: generic: cleaning up temporary directory/files
    Nov  5 17:43:29.858 [70835] dbg: generic: cleaning directory /tmp/.spamassassin70835D8L50dtmp
    Nov  5 17:43:29.859 [70835] dbg: diag: updates complete, exiting with code 4
    # cd /Library/Server/Mail/Data/scanner/spamassassin/3.004000/updates_spamassassin_or g
    # curl -O http://spamassassin.apache.org/updates/MIRRORED.BY
      % Total    % Received % Xferd  Average Speed   Time    Time     Time  Current
                                     Dload  Upload   Total   Spent    Left  Speed
    100   718  100   718    0     0   5854      0 --:--:-- --:--:-- --:--:--  5885
    # sa-update -D --nogpg
    Nov  5 17:49:39.044 [71190] dbg: diag: updates complete, exiting with code 0
    I can now receive new mails at both domains on my server and all of the emails received when the server was "down" are starting to trickle through.
    Thanks for your assistance.

Maybe you are looking for