Little Snitch sends outgoing requests with Airport off

Noob, just downloaded Little Snitch on MBP, getting familiar with background processes and shell scripts. Let x = variables.
LS is showing my mDNSResponder sending out a 225.etc request after I turn Airport off. No other machines on network are runing.
When I DLed Little Snitch and began running it, neither configd nor SystemUIServer were on the LS register. After restart, both showed up and have been sitting contentedly.
When Airport is on, Finder via nmblookup is sending a request to [x].255 about every minute that I have Safari open. When I turn Airport off, then back on, and I'm running LS, Safari to verisign connection shows up and configd connection shows up at ff[x:xx].
My concerns: Former employer is after my intellectual property. I had MBP connected on a daily basis to WiFi and certain sharing elements on with firewall off (stupid, I know, but I didn't know nad hadn't thought about it, and co. in question was pretty technologically dinosauric). Connected to same network by ethernet occasionally, and installed by disk a Windows partition and Open Office by disk given by employers' IT staff.
What's the possibility that a keystroke logger was put on my machine by an Admin of network I connected to, and is there any way to detect and disable said keylogger? Also, is there any way--outside of reverse-lookup, SPAM blacklisting sites--to check destinations of remote connections my comp might be making to an external server?

FWIW, mDNSResponder is the process responsible for [Bonjour|http://developer.apple.com/networking/bonjour/faq.html], Apple's name for its implementation of the popular zero-configuration networking technology. (That's what allows your Mac to discover & use network printers, local servers, etc.) And as mentioned [here|http://support.apple.com/kb/HT3789], it is also used in Snow Leopard for unicast DNS resolution; without it, that OS cannot resolve hostnames like www.apple.com.
Likewise, [nmblookup|http://developer.apple.com/library/mac/#documentation/Darwin/Referen ce/ManPages/man1/nmblookup.1.html] is the process that supports the OS X implementation of [Samba|http://en.wikipedia.org/wiki/Samba_(software)], which allows file & printer sharing between Windows & UNIX type OS's.
[configd|http://developer.apple.com/library/mac/#DOCUMENTATION/Darwin/Reference/ ManPages/man8/configd.8.html] is an essential process that among many other things supplies the dynamic network port configurations that support the above & many other network processes.
So it is perfectly normal for these processes to periodically generate outbound network activity & by itself that does not mean a key logger is installed in your system.

Similar Messages

  • I have an imac g4 purchased Dec 2003 runnung OS 10.5.8.  It runs fine with airport off, but when I turn airport on it freezes with the black page,  "restart by holding power key . . ."  I swapped the airport extreme card with the one in my ibook G4 (purch

    i have an imac g4 purchased Dec 2003 runnung OS 10.5.8.  It runs fine with airport off, but when I turn airport on it freezes with the black page,  "restart by holding power key . . ."  I swapped the airport extreme card with the one in my ibook G4 (purchased same date and running same OS).  No change in operation.
    I am running wifi from verizon.  Recently changed from mifi2200 to jetpak 4620 in a 3G location.  Ibook running fine, desktop freezes.  If I can boot desktop in safe mode and get airport turned off in time. then I can reboot regularly and imac runs flawlessly with no wireless.Have run disk utilities and TechTool Pro rebuild etc, but nothing has worked.  How do I fine the culprit?

    the power logix thing was really sad. apple changed so much after 10.4.8 that there wasn't a viable way to patch the software.
    That statement is precisely why I don't believe in blindly updating the OS, especially in a non-standard machine.
    We can't expect third parties to support us forever, and it is shameful to break something that works fine, except that we updated the OS....
    I think that any upgrade or modification to a machine or the OS greatly increases the risk of trouble or incompatibility with current configuration and "new" system files.
    After all, the component or software could only be tested as far as the current OS version when the component or software was released.
    Beyond that, we are all "beta testing".
    Following a beta tester protocol, and applying updates to a cloned system drive first, is a prudent way to approach updates, and not only for older, heavily modified machines.
    After 10.4.8 and moreso with Leopard, the focus is primarily on Intel architecture, not PPC architecture.
    Like it or not, we are all updating to the abyss of the extinction of our machines, unless we can be satisfied with the last stable version of OS that works well with our hardware and software.
    I wish they would include the latest pkgs at least with software update.
    Yes, having individual packages, rather than lump "OS X 10.x.x" updates would be nice.
    This way, one could update as one sees fit. That is to say, for example, fix the Quicktime, but leave my Network alone, etc., etc.
    In all fairness, Apple does provide for some breakdown of updates, but I believe there is much room for improvement, especially, as you point out, with regard to the core services portion of the OS.
    Until then, I'll leave Software Update disabled.......

  • Little snitch denying outgoing connections of weird hostnames

    Hi
    Recently, I am monitoring every outgoing connection from my macbook pro through little snitch. Sometimes when I want to connect to the Internet I receive alerts that some strange looking hostname is going to have some outgoing connection through port 80. The hostnames I am talking about mostly consist of some unintelligible words such as "zvamnzqdopv" , "ogqyazfk", "odxjltwzwm"  and "wpnclfbvs.test.com" with the same IP of (50.23.225.49) and "htxmaklhxqpku" with (198.105.254.11) IP address. I also need to mention that the outgoing connection for the second IP (198.105.254.11)  is when I set my dns servers as google's that is 4.2.2.4 and 8.8.8.8 (I do that for having a faster Internet connection). Looking up the IP addresses in http://ip-lookup.net/ I get the following for both IPs
    The first IP:
    NetRange:  50.22.0.0 - 50.23.255.255
    CIDR:  50.22.0.0/15
    OriginAS: AS36351
    NetName: SOFTLAYER-4-9
    NetHandle: NET-50-22-0-0-1
    Parent: NET-50-0-0-0-0
    NetType: Direct Allocation
    RegDate: 2010-11-01
    Updated: 2013-07-12
    Ref: http://whois.arin.net/rest/net/NET-50-22-0-0-1
    OrgName: SoftLayer Technologies Inc.
    OrgId: SOFTL
    Address: 4849 Alpha Rd.
    City: Dallas
    StateProv: TX
    PostalCode: 75244
    Country: US
    RegDate: 2005-10-26
    Updated: 2013-02-20
    Ref: http://whois.arin.net/rest/org/SOFTL
    and the Second IP
    NetRange:  198.105.240.0 - 198.105.255.255
    CIDR:  198.105.240.0/20
    OriginAS: 
    NetName: SEARCHGUIDE
    NetHandle: NET-198-105-240-0-1
    Parent: NET-198-0-0-0-0
    NetType: Direct Assignment
    RegDate: 2012-07-10
    Updated: 2012-07-10
    Ref: http://whois.arin.net/rest/net/NET-198-105-240-0-1
    OrgName: Search Guide Inc
    OrgId: SG-63
    Address: 1942 Broadway
    Address: Suite 319
    City: Boulder
    StateProv: CO
    PostalCode: 80302
    Country: US
    RegDate: 2012-06-26
    Updated: 2012-06-26
    Comment: Standard NOC hours are 7am to 6pm EST
    Ref: http://whois.arin.net/rest/org/SG-63
    Can anyone tell me why I have the mentioned outgoing connections from my computer? Are these indicative of some malicious activity undergoing in my system?
    Any ideas will be appreciated.
    Thanks

    FWIW, mDNSResponder is the process responsible for [Bonjour|http://developer.apple.com/networking/bonjour/faq.html], Apple's name for its implementation of the popular zero-configuration networking technology. (That's what allows your Mac to discover & use network printers, local servers, etc.) And as mentioned [here|http://support.apple.com/kb/HT3789], it is also used in Snow Leopard for unicast DNS resolution; without it, that OS cannot resolve hostnames like www.apple.com.
    Likewise, [nmblookup|http://developer.apple.com/library/mac/#documentation/Darwin/Referen ce/ManPages/man1/nmblookup.1.html] is the process that supports the OS X implementation of [Samba|http://en.wikipedia.org/wiki/Samba_(software)], which allows file & printer sharing between Windows & UNIX type OS's.
    [configd|http://developer.apple.com/library/mac/#DOCUMENTATION/Darwin/Reference/ ManPages/man8/configd.8.html] is an essential process that among many other things supplies the dynamic network port configurations that support the above & many other network processes.
    So it is perfectly normal for these processes to periodically generate outbound network activity & by itself that does not mean a key logger is installed in your system.

  • Updates window running incessently. What's wrong? btw, I use Little Snitch but no requests

    I upgraded to Firefox 5, both before and after the Update Window would act like an Update was coming but it just runs nonstop.
    I am using Little Snitch, which stays on, however never has an access request Permission shown up. And I cannot turn it off just in case Firefox is going to offer an update, in case it is the LIttle Snitch software that it's not requesting Permission from.
    Is there a bug in that trouble somewhere?

    hello JoanAnswer, if the automatic update doesn't work, please download a fresh copy of firefox 25 from https://www.mozilla.org/firefox/all/ and install it on top of your current version.
    [[Install Firefox on Mac]]

  • Printing with Airport off?

    Is this normal? Or does turning Airport off only deactivate reception of wireless signals? Or do signals sent to the Extreme for printing not use Airport?

    Bill from Germany wrote:
    Is this normal? Or does turning Airport off only deactivate reception of wireless signals? Or do signals sent to the Extreme for printing not use Airport?
    Some questions that might help people give you useful advice:
    - Is your printer connected to an AirPort base station?
    - When you say "AirPort off", do you mean that (1) your AirPort base station is powered off, (2) your computer's AirPort circuitry is off, (3) that you've disabled wireless operation of your AirPort base station, or (4) something else?
    - How does your computer communicate with your AirPort base station, by Wi-Fi or Ethernet?

  • ? poppings noises with airport off helpppp

    Hi guys i'm getting several pops and clicks when listening to my already recorded tracks I've never had this problem, I even check the latest drivers for the ff800 and I'm up to date. checked the precision 8 spkrs there fine when playing itunes or playing waveburner. I saw the earlier post and was hopeing it had the answer. any suggestions this new problem blows

    Hey guys u won't believe it I've been trying different things all day, so just for the heck of it i turned the airport on. that worked my songs r thumpin again thxxxx for trying guys i can't believe a whole creative day waisted i won't be doing any kind of updates soon. thxxx guys i'm heading to the gym to burn off some steam i'll start fresh tomorrow. thxxx anyway

  • Error while trying to send soap request with Altova

    Hello,
    I m getting this error, can anyone help me please?
    ERROR org.apache.axis2.transport.http.AxisServlet - java.lang.NullPointerException

    With so little information, I doubt anyone will be able to help you out. Altova forums could be better place to lookout for the solution.

  • My auto-complete has recently stopped working and I am getting a message saying: "You sent invalid values. Please send a request with correct values." - Why??

    The error message is appearing where the auto-complete options should be appearing

    This issue can be caused by corrupted cookies.
    Clear the cache and the cookies from sites that cause problems.
    * "Clear the Cache": Tools > Options > Advanced > Network > Offline Storage (Cache): "Clear Now"
    * "Remove the Cookies" from sites causing problems: Tools > Options > Privacy > Cookies: "Show Cookies"

  • Via headers in outgoing requests

    When creating an outgoing request with SipFactory or proxy using OCCAS the request does not have a top via before it is sent on network.
    Initially the via transport and address cannot be set until the request is bound to an interface but parameters like the branch could be useful. Other JSR-289 containers expose this header with empty address and transport but allow adding additional parameters.
    This could be used when selecting outgoing telephony network port on for Cisco GW by adding a "x-route-tag" on top Via.
    Is this a configurable behavior or am I the only one trying to use "x-route-tag" using OCCAS?
    An other observation we did was when receiving an branch response in the proxy the top via was already popped. Normally you pop the via on the final response before you send it again to servlet JSR-116 style. But the initial branch response should not have the via popped since valuable information may be lost.
    Is this a related problem?
    /Henrik

    Hello Henrik,
    You point valid use-cases which have not been addressed in OCCAS.
    Could you please work with support to get an Enhancement filed?
    Thanks,
    Mihir

  • Is there a way to force firefox to send ajax-request when user clicks on a link and redirect occurs?

    I'm trying to send ajax-request with web-analytics data when user clicks on a link. But Firefox cancels the request and moves to the link location. Sync requests or waiting for response is not an option because performance is critical.

    Correct me if I'm wrong here:
    <code>jQuery.data()</code> saves the <code>{"foo": "bar"}</code> JSON object to variable <code>data</code>, and then the <code>s.tl()</code> call sends <code>data</code> to the server, right?
    You could use jQuery's [http://api.jquery.com/event.preventDefault/ <code>event.preventDefault()</code>] method to stop the browser from automatically following the link on click. You could wait until the Ajax request was finished before following the link.
    <hr>
    I hope that solved your problem!
    <i>If it did, would you please choose this answer as your solution? It would help other Firefox users to find help on the forums faster and more efficiently. Thanks!</i>
    And of course, feel free to post back if you need more help!
    Happy browsing!

  • How do I transfer files between my iMac and my MacBook Pro using an ethernet cable (not with AirPort)?

    Even though I connect my computers with an ethernet cable the files are still being transferred wirelessly.  I can tell because the transfers (usually around 4GB) take a few minutes with AirPort off, but 30 minutes to an hour with AirPort on.  I want to transer the files and still have AirPort on since I work on both computers at the same time and want to maintain the connection to the internet.

    Be sure Ethernet is listed first in System Prefs > Network.
    If it isn't, click the "gear" icon and select Set Service Order.

  • Error when sending data request

    Hi All,
       i have scheduled info package for different type data sources in bi 7.0, for this i am getting the data from  ecc 6.0 . all of this schedule's showing  the status "error when sending data request" with the following details.
    status
    diagnosis
    the request idoc could not be sent to the source system using rfc
    system response
    there is an idoc in the warehouse outbox that did not arrive in the ale inbox of the source system
      in step by step analysis it is showing
       rfc to source system successful showing with ash status
       data selection successfully stated  and finished ? show with red status
    in that details tab
    request : showing with green status
    everything ok
    extraction :showing with red status
    missing messages
    transfer(idocs and trfc) : missing messeges
    processing(data packet) : no data
        it is showing technical status with red as processing overdue
                           processing step call to source system
       so it is showing error with 0 from 0 records.
    please any body could help me for solving this error.
    regards,
    naveen.

    Hi
    Seems you have connectivity issues between the Source system and Bi system.
    You need to check whether you have data on R/3 side via RSA3 with Full / Delta Update Modes with Target System as your BI system.
    RSA13--Source System -- Right click Connection parameters/check/Restore/Activate again Say Replicate All Data Sources (If Possible , provided if you have time because it consumes lot of time )
    You need to check the tRFC Queue SM58/59 for any Stucks and WE19/20 for IDocs.
    Much of BASIS Issue .
    Hope it helps and clear

  • Mixed/multipart Request with a image file and a amr audio file

    Hi people
    I am struggling with multipart/mixed request as i am new to java and http. I basically have to write a java code to send a request with two attachments, an audio amr file and a image file of a proprietry format. following is my code
    public static void GetVideo()
         HttpURLConnection httpConnection = null;
    InputStream bis = null;
         InputStream bis1 = null;
    OutputStream bos = null;
         File audioFile = new File("voicejunk.amr");     
         File avatarFile = new File("out.frf");
         System.out.println("Entered Get Video");
         String Boundary = new String("asdfgh");
    try
    URL url = new URL("http://10.4.21.51:5006/");
    httpConnection = (HttpURLConnection) url.openConnection();
         httpConnection.setRequestProperty("Cache-control", "no-cache");
    httpConnection.setRequestProperty("Pragma", "no-cache");
    httpConnection.setRequestProperty("Content-Type", "multipart/mixed;boundary= \"asdfgh\"");
         httpConnection.setRequestProperty("video-type", "3GPP");
         httpConnection.setRequestProperty("video-encoder", "H.263");
    httpConnection.setRequestProperty("audio-encoder", "AMR-NB");
         httpConnection.setRequestProperty("video-size", "QCIF");
         httpConnection.setRequestProperty("video-fps", "10.0");
         httpConnection.setRequestProperty("video-anti-aliasing","yes");      
         httpConnection.setRequestProperty("Content-Length", Long.toString(audioFile.length()+avatarFile.length()+(3*Boundary.length())));     
         //byte[] bytes = createMessage();
         //httpConnection.setRequestProperty("Content-Length", String.valueOf(bytes.length));     
    //System.out.println("Size of: "+bytes.length);     
         httpConnection.setRequestProperty("Expect", "100-continue");          
         httpConnection.setRequestProperty("Connection", "Keep-Alive");
         //String AvatarType = new String("FRF");     
    httpConnection.setRequestMethod("POST");
         httpConnection.setDoOutput(true);     
         bos = new BufferedOutputStream(httpConnection.getOutputStream());
         bos.write(Boundary.getBytes());
         Session session = Session.getDefaultInstance(new Properties());          
         ByteArrayOutputStream baos = new ByteArrayOutputStream();
         Message msg = new MimeMessage(session);
    MimeBodyPart mbp1 = new MimeBodyPart();
    FileDataSource filedatasource1 = new FileDataSource("seestorme.frf");
    DataHandler dh1 = new DataHandler(filedatasource1);
    mbp1.setDataHandler(dh1);
    mbp1.setHeader("Content-Type", "x-seestorm-avatar/frf");
         MimeMultipart mmp = new MimeMultipart();
    mmp.addBodyPart(mbp1);
    msg.setContent(mmp);
    msg.writeTo(baos);
         bos.write(baos.toByteArray());     
    bos.write(Boundary.getBytes());
         ByteArrayOutputStream baos2 = new ByteArrayOutputStream();
         Message msg2 = new MimeMessage(session);     
         MimeBodyPart mbp2 = new MimeBodyPart();
    FileDataSource filedatasource2 = new FileDataSource("voice.amr");
    DataHandler dh2 = new DataHandler(filedatasource2);
    mbp2.setDataHandler(dh2);
    mbp2.setHeader("Content-Type", "audio/amr-nb");
         MimeMultipart mmp2 = new MimeMultipart();
    mmp2.addBodyPart(mbp2);
         msg2.setContent(mmp2);
    msg2.writeTo(baos2);
         bos.write(baos2.toByteArray());     
    bos.write(Boundary.getBytes());          
    //httpConnection.getOutputStream().write(bytes);
         //httpConnection.getOutputStream().flush();
         System.out.println("Request made");
    int result = httpConnection.getResponseCode();
         String Msg1 = new String(httpConnection.getHeaderField(0));
         String Msg2 = new String(httpConnection.getHeaderField(1));
         String Msg3 = new String(httpConnection.getHeaderField(2));
         String Msg4 = new String(httpConnection.getHeaderField(3));     
         String Msg5 = new String(httpConnection.getHeaderField(4));
         System.out.println(Msg1+" " + Msg2+" " + Msg3+" " + Msg4+" " + Msg5+" ");
    if (HttpURLConnection.HTTP_OK == result) {
              System.out.println("Received HTTP result = " + result);
    saveResponseData2(httpConnection.getInputStream(),"SeeStorm.frf");
    } else {
    System.out.println("Received HTTP result = " + result);
         catch (MessagingException me) {
    me.printStackTrace();
    catch (MalformedURLException mue) {
    mue.printStackTrace();
    } catch (ConnectException ce) {
    ce.printStackTrace();
    } catch (IOException ioe) {
         ioe.printStackTrace();
    } finally {
    if (null != bis) {
    try {
    bis.close();
    } catch (IOException ioe) {
    ioe.printStackTrace();
    if (null != httpConnection) {
    httpConnection.disconnect();
    i frankly have no idea how to create a multipart mixed request with boundaries. I get a bad http request error with the above code. Can please someone help me.
    Thanks
    Adil Saleem

    Your WriteImage servlet needs to read the image file in from wherever it is (hard drive, database, whatever), then write it back out to the browser. To do that, first use the HTTPServletResponse object to send the appropriate headers, then call the getOutputStream() method to get an output stream to write the data to. This data will be sent to the browser which, if you've set the headers correctly, will display it as an image.
    It's been a long time since I did this (we abandoned storing images in databases quite a long time ago), so I can't be more specific than that, but hopefully that'll be enough to get you going. If you run into any problems, reply and I'll see if I can help further.

  • CANNOT SEND OUTGOING MAILS FROM HOM

    i am unable to send outgoing mails with my computer from home and other few locations. However, in other places such as public libraries, coffe shops, apple stores etc the outgoing mail works perfectly. does anybody know where the problem can be? i work from home and is getting me out of my nerves. Thank you for the help

    Does web mail work?
    Have you checked the outgoing mail server settings?
    That's the smtp address of your internet provider.
    You may need to change the outgoing mail server for each location.

  • I am having issues sending outgoing mail. All my settings are correct.

    I am unable to send outgoing messages with a specific email account.  I have checked my settings with both my provider (Cablevision/Optimum) and with Apple's online check system. All are the same as I am using. Any ideas?

    BTW, Optimum does not support secure email (TLS, or Transport Level Security). That means that if you check email using a public WiFi network (such as optimumwifi) anyone sharing that hotspot can capture your user ID and password. So you should never allow the phone to check email at a public WiFi location (e.g., Starbucks).

Maybe you are looking for

  • Displaying PDF file in forms running on UNIX server

    I want to display a PDF document in the form. I have explored the following two options:- 1) Using Image item - PDF format is not supported by forms 2) OLE - Is supported only on WIN and MAC Does any body know of any reusable java bean that can be us

  • Album, supposed to be released today, pushed back date to February, but I was charged today

    This happened to everyone who preordered American Idol winner, Candice Glover's new album.  It was supposed to be relieased today; however the release date was pushed back until February.  I woke up this morning to find the "album" downloaded onto my

  • IIOMetadata metadata

    This post asks about image metadata. IIOMetadata meta = reader.getImageMetadata(0); when meta.getAsTree( meta.getNativeMetadataFormatName() ) is used to retrieve image metadata one gets Nodes like this: <javax_imageio_jpeg_image_1.0> <JPEGvariety> <a

  • Interfere into JSF lifecycle

    Hello, I was wondering how i can interfere into the render response phase. The problem is that i'm using a richfaces component responsible for polling. When changing the contents of a div (it's a wizard-like behaviour) the reponse is added/rendered i

  • Licence Change for Adobe Photoshop from Window to Mac

    Hello Everybody, my name is Sachin and i'm using Adobe Photoshop CS5.5  for Window 7 and now i got a mac so i would like to know if there is any way to change my licence for Adobe Photshop CS5.5 from window to Mac.