Warning: Neighbors Mac mini (10.3.9) was exploited via SSH

My neighbor called me a couple of weeks ago to say she couldn't log in to her mini. It wouldn't accept her password. I fixed it but last weekend the same thing happened again. I fixed it but decided to look around. I found a couple of perl files in her home folder, a few tgz files, and some software for running a shoutcast server. I knew right away someone had gained access to her machine. All because when I set her mini up, I turned Remote connectivity via SSH on. I checked her bash history file and found that someone had downloaded those files using the curl command from some Romanian sites. The files were definitely cracker related, although I don't remember exactly what the names were. I think one of them was spoofer or something like that.
I'm going to send an email to Apple on this in hopes that they add a security patch to 10.3.9.
I have since reinstalled OS X and NOT turned on Remote Connectivity.

how strong of a password she used, etc.
More than likely she did something to compromise the
system.
FWIW, in another posting, he mentioned that the password was the same as the username, and that it wasn't very strong...
charlie

Similar Messages

  • Neighbors Mac mini (10.3.9) was exploited via SSH

    My neighbor called me a couple of weeks ago to say she couldn't log in to her mini. It wouldn't accept her password. I fixed it but last weekend the same thing happened again. I fixed it but decided to look around. I found a couple of perl files in her home folder, a few tgz files, and some software for running a shoutcast server. I knew right away someone had gained access to her machine. All because when I set her mini up, I turned Remote connectivity via SSH on. I checked her bash history file and found that someone had downloaded those files using the curl command from some Romanian sites. The files were definitely cracker related, although I don't remember exactly what the names were. I think one of them was spoofer or something like that.
    I'm going to send an email to Apple on this in hopes that they add a security patch to 10.3.9.
    I have since reinstalled OS X and NOT turned on Remote Connectivity.

    Hi Dale,
       Are you saying that you think that Apple enables the finger daemon by default? I don't believe that to be the case. On Tiger, the /System/Library/LaunchDaemons/finger.plist file that ships with the system contains the following line:
    <key>Disabled</key>
    On Panther, the /etc/xinetd.d/finger file that ships with Panther contains the line:
    disable = yes
    Thus, on both systems, the fingerd daemon doesn't respond to finger requests from external systems. I tested that and the only thing that finger returns is the name of the remote system in square brackets.
       Also, the script kiddy attack to which I referred is nowhere near that sophisticated. I haven't actually read the script but the list of users it tries appears to always be the same. I agree with you that it might be possible to gain knowledge about the usernames on many systems, especially those running fingerd. However, excepting for finger and maybe LDAP, the methods for doing that would likely be different for different systems. This script goes for quantity instead of quality so it doesn't spend enough time on any one system to do any probing.
       As Michael says, Mac OS X ships with all services turned off, including fingerd. I don't think that Apple's firewall tool is of any use because it's "all-or-nothing". Opening a port to the world or blocking it is no different from turn the corresponding service on or off. However, I've never seen a GUI tool that did much better so I don't see that as a ding against Apple.
       I've read too many of your extremely knowledgeable posts to think that you rant arbitrarily. Of course people with such excellent reputations are allotted 5 random rants per calendar year here so you're allowed. If you post the details about the problems you're having, perhaps we could help. You should be able to solve almost any issues about services with a solid firewall.
    Gary
    ~~~~
       Am I ranting? I hope so. My ranting gets raves.

  • Can the can a Mac Mini connect to an Apple TV via Airplay?

    I don't own a Mini, but was wondering if I could project (connect wirelessly) the desktop of the Mac Mini on to a tv screen via an Apple TV. 

    What are you trying to do?  Do you want to be able to watch movies that are hosted on the mini from the various ATVs around your house?  Or do you actually want to use the computer (for computing tasks) and use your various TVs as monitors?  If it's the former, there is a native function built in to the ATV that allows you to do just that, without having to resort to a kludgy desktop sharing situation.
    Your keyboard and mouse will need to be within range of the mini in order to work.  The commands do not get sent back via the ATV.  Alternately, you could install an app like Mobile Mouse on your mini, and install the accompanying client software on an ipad or iphone and control the mini from anywhere via your home wifi.

  • I have just replaced my mac mini because previous motherboard was damaged. I want to pair with my existing wireless keyboard and mouse but can only pair with thebold mac mini which will not start. Any ideas?

    See title. How do I unpair a wireless keyboard and mouse when the previous paired mac mini is damaged and will not start?

    You should be able to go to System Preferences -> Keyboard and System Preferences -> Mouse and discover the bluetooth devices.
    Also, do you have a bluetooth icon on the top bar of your mac?  Should look sort of like this:
    If you can figure out which device is which (by trial and error, if nothing else), you can connect to them on this menu.

  • Mac Mini on Toshiba Regza Z3030 42" via DVI- HDMI

    Hello,
    I'm trying to connect a Core2Duo Mac Mini (running 10.4.11) to a 42" Toshiba Regza Z3030 Full-HD TV via a DVI-HDMI cable. The TV does 1920x1080 (both i and p), but when I select 1920x1080 (interlaced) from the display resolution menu in System Preferences, I get a black frame around the image that is twice as large on the right side of the picture than it is on the left or top/bottom sides (so even if I enable overscan, the picture is not acceptable, as it's missing a strip of the desktop on the left, top and bottom sides then).
    I'm running the TV on "Exact Scan" mode, which (according to the manual), should display a 1080 signal exactly the way it is received from the source, no stretching or scaling at all.
    Incidentally, the grey screen with the Apple logo and the spinning progress indicator fills the screen completely in 1080i, but as soon as the login panel comes up, the picture gets the black bars, so I think it's a MacOS X issue. Can I somehow tell the Mac not to switch the display settings after the booting process is finished, as the image during the boot process is perfect?
    Any hints on what I could try?
    Thanks in advance,
    Georg

    Ok, I decided to take some more time and googled for how SwitchResX actually works and what all the settings in the "custom resolution" view mean. I stumbled across a very useful tutorial in this forum thread: http://www.avsforum.com/avs-vb/showthread.php?t=751713
    Following these instructions (basically, I just had to play with the "front porch" and "back porch" parameters until the image was perfectly centered), I ended up with a custom resolution in which the image is centered, but still has black bars around it.
    Next, I simply turned on "Overscan" in the Display preferences while setting the TV's HDMI port input to "Exact Scan", meaning it will display the image exactly the way it comes over the HDMI port, without extra scaling.
    With this combination, I now ended up with a picture that fills the whole screen and has (according to a test image) a "1 to 1" pixel mapping. Also, for some reason, this new resolution that I made myself rather than taking the values off the internet "sticks" between sleep and wake cycles as well!
    For some reason, though, the TV only reported that it supports 50Hz vertical sync in 1080p when I used the "Export DDC" function in SwitchResX, even though according to the manual it also does 60Hz (and the default 1920x1080, 60Hz resolution from the Display preferences works as well). Therefore, I was only able to make my custom resolution for 50Hz, as I need the values from the DDC export as a starting point.
    I only want to use this Mac Mini/TV combination as a media center for movies and music streaming via iTunes, so I guess it won't make any difference wether I'm running it at 50Hz or 60Hz?
    Anyways, I hope this thread might help other people with the same TV who are having similar problems with their Mac Minis.

  • New 2010 Mac Mini and LG 37" Full HD (via HDMI) query..

    Hello all! I have just bought the new Mac Mini which I want to use along with my LG 37" (LH5000) full HD LCD TV.I have hooked them both up together via HDMI. When I first turned the Mac Mini on it detected various resolutions and choose 1080p. However, on this resolution the menu bar, dock finder windows etc all look too small when im sitting on the couch. Im only around 3 metres away from the TV.
    Ive changed various resolutions, in fact the 720p resolution looks bigger and better....but surely I should be using 1080p? I was wondering if any one else out there has a similar setup and what res you would recommend I should use? There are other resolutions but I assume the other ones are all Mac (computer LCD) base.
    Thanks in advance
    Ben

    Yes, this is a significant issue. And since Apple doesn't allow adjustment of type sizes throughout the OS, it can be very problematic.
    One solution is to do as you have done and run the display at a lower resolution.
    Another solution is to use the magnification tools that are provided in the Universal Access control panel (system preferences).
    Screen zoom works with any scroll mouse (you do not need to buy the MS mouse that was mentioned). Just hold the Control key on the keyboard and turn the mouse's scroll wheel. I use this a lot on my Mini connected to an HDTV.
    I also have the size of the mouse pointer arrow increased twofold using the universal access controls.
    In the Finder, you can set the Finder preferences so that file names are listed as 16 point type (and click on the set default button). Of course the menus and sidebars are still small and Apple really needs to start offering more versatile adjustments for these other interface areas (like, dare I say it… Windows allows for).
    When web browsing, you can magnify the web page in question using the COMMAND key with the + key. You can zoom back again using COMMAND and - . I use that a lot. And yes this shortcut key combo works in both Safari and Firefox.
    Lastly, make sure that the sharpness adjustment on your TV isn't turned up significantly, as this will hurt the legibility of type on the screen. The lower the sharpness is set, the more readable the text will be. You'll have to strike a balance that you're happy with between text sharpness and a satisfying sharpness for the video content you watch. On my sony tv, I have the sharpness set at about 25%.
    I should also mention that the type on the screen being to small to read is a sign that your screen size to seating distance ratio is outside of the ideal range. In other words, you're sitting too far from your current TV, or you could stand to have a bigger TV for the room in question. To better understand viewing distance versus HD display size, read this:
    http://www.crutchfield.com/S-L3GoEoljGNL/learn/learningcenter/home/TV_placement. html

  • Mac mini unable to connect to internet via router

    I can't seem to connect to the internet using my mac mini.i use a netgear wireless router which has my imac,and 2 windowsxp PC and a maxtor network drive connected ,these all work on the network.
    The macmini(no airport) is connected using an ethernet cable and a netgear powerline ethernet adaptor.
    I cant solve the problem!Can anyone help me please?
    Dan
    themint

    Hi Dan
    Have you confirmed that the Netgear Powerline adaptor works fine with other computers on your network?
    On your mini, if you go into System Preferences - Network - Built-in Ethernet, what are your TCP/IP settings? Are they the same as for the iMac?
    Matt

  • Mac Mini doesn't see PC connected via AirPort

    I created a wireless network using the AirPort built into the Mac Mini. My PC laptop connects to this network, but I can't find the PC or any of its components from the Mac. I am new to AirPort so maybe I don't know where to look. However, it seems there should be some icon for the PC on my desktop or in the finder. Is this a Mac/PC compatibility issue?

    To see the PC:
    1. In the Finder, press Command-K.
    2. Enter the PC's IP address.
    3. Authenticate with your username and password form the PC (You need a password for this to work)
    Then if you want, write an Automator app to do that for you and a keychain for your passwords.
    Hope this helps!

  • HT1338 I bought a new Mac Mini and tried to pair my keyboard with the Mac Mini. They will not pair via Bluetooth. What is wrong?

    I have recently bought a Mac Mini and tried to pair the new apple wireless keyboard with the Mac but after trying 6 times no luck. What can I do about this?

    try this method:
    You need at least a USB mouse. If you don't get any option to pair a keyboard, click through the setup until you get to the "Create Your Computer Account" screen, right click in any of the text fields and select Substitutions --> Show Substitutions.  From there click on text preferences.  The preferences pane will popup and from there you can just click the back button (next to show all) to get to the full preferences menu.  Next click on keyboard, then select setup bluetooth keyboard and you're golden. 

  • I have been using LR5 on a Mac mini. The LR was installed on an external drive. Now I would like to use Smart Previews on my Internal drive to take advantage of the speed. When I make previews they go to originals. How can I put them on the internal drive

    when started with LR 5 on my Mac I used advise from Adobe's LR5 book, I installed  it on an external drive, processing originals was a little slow so I decided to make smart previews on my internal drive to get faster processing. However the smart previews hook up with the originals and so there is no advantage just a bigger file. Is there anyway when I make the previews stay on the internal drive or am I locked in with the current setup. I can find no LR5 folders on the internal drive.
    Thanks,
    John Sr.

    Are you doing a lot of spot removal or brushing?
    This doesn't sound like a disk drive issue at all. Once Lightroom reads the file from the disk, and you are editing, the disk plays no further role. Using a faster disk drive here will not make the slightest difference.
    So, I would check your graphics drivers to see if they are up to date. I would also temporarily disable your virus checker and firewall.
    How much memory does your computer have? What CPU do you have?
    How big (in megapixels, not megabytes) are the photos you are editing?

  • 10.4.5 - mac mini can't connect to network via airport since upgrade

    I've been experiencing problems since upgrading to 10.4.3. Mainly, I've noticed that I can't easily connect to our wireless home network all the time. The pattern has been that I start by shutting down my computer completely. When I start up it again, it can't connect to the network. I have to create a new profile and then it will connect. That was buggy, but at least I found a hack. However, since upgrading to 10.4.5, I can't connect to our home network at all. The Internet Connect application says that I am connected to the base station, however I can't connect to the outside world via a shell, browser or email application. Our network is secured with a WEP and the base station is a D-Link. I searched the forums for some tips, but didn't find anything. Pointers appreciated.

    Be very careful about the sequence you do it. You must make sure that the airport connection is turned off (i.e. the airport menu icon looks more like a profiled eyeball without the iris than a series of lines like the towers of hanoi). Then create a new location in the Airport network preference, and make sure that these settings are there under Options
    1. Keep looking for recent networks
    2. Automatically add new networks to the preferred network list.
    3. Change the status of Enable interference robustness.
    And by default, join preferred networks in the Airport location.

  • Should my new Mac mini work with my HD tv via the HDMI port?

    I am using the apple HDMI cable with a Genesis brand HD tv. When I start up the mini, I see the start-up screen and the apple shows, but once it is beyond that, it disappears. The screen shows a resolution and not the "no signal" but nothing beyond that. Any ideas? Unfortunately, I can't test the VGA adapter, because I didn't buy one.
    Thanks.

    Open Displays preferences and switch to the other display (TV) or put the Mini into Mirror mode.

  • Mac Mini was unplugged while on. How should I proceed?

    My Mac Mini Server edition (2011) was accidentally unplugged while on. It rebooted fine, but I'm a bit paranoid about any unfinished procedures causing cruft in the operating system/hardware. Is there anything I should do to be sure that this incident has not negatively impacted my hardware/software such as resetting the PRAM, PMU etc.?
    Any input would be appreciated. Thanks.

    "Rapid blackout" shutdown is not good, but OSX performs several "verification checks" at startup just in case there are any incomplete operations ate shutdown.  Chances are those procedures were busier than normal during the next startup, but it recovered.
    As to the rest of the hardware rapidly shutting down, wait for any signs of issues in my opinion.
    In short, you are probably fine.  Just keep an eye on it for a day or so.
    In addition ... pulled power plug is not the only way to lose power while operating.  Blackouts (power out for several seconds) or brownouts (power blinking for a split second) or power dips (power seems always on it dips below the 120 V level) can cause issues.
    You can buy a UPS (uninterruptible power supply) that uses bateries to supplement the "power dips" or replace wall power during brownouts and blackouts.
    Units sufficient fo a macmini (500 VA units) can be had for $60.

  • Background eraser error in Photoshop on Mac Mini [was:jim]

    i am running a mac mini untill yesterday everything was good, now i get a background eraser error.

    Jim,
    What version of Ps are you running, and what is the OS version on the Mac-mini?
    What is the exact text of the error message?
    Good luck,
    Hunt
    PS - with a bit more information, a MOD will likely Edit the title of your post, for clarity, and to help other find the post, if they have the same issue.

  • RAID on Mac mini Server (2011 i7)

    I just purchased a new Mac mini Server today (the base configuration 2011 Quad Core i7 with 4GB RAM and 2x 500GB 7200RPM magnetic hard disks) and wanted to share what I've learned about setting up RAID on the system.
    First, as you may have heard, the Mac mini Server does not include any installation/reinstallation media (I was hoping for a USB reinstall key, but it seems that the new systems don't include these or optical discs; last year's Mac mini Server included handy reinstall DVDs even though the system didn't have an optical drive).  Out of the box, the new Mac mini Server has Mac OS X Lion, the iLife suite, and the Mac OS X Lion Server tools pre-installed on one of the two 500GB internal drives; the other disk is formatted as a separate, second drive.
    If this is the configuration you're looking for, you're good to go right out of the box.  As an aside, this shipping configuration is ideal for using the second disk as a Time Machine drive.  I would argue that Time Machine would be a better use of the second volume than a RAID 1 configuration, as Time Machine provides versioned backups and you don't incur the write performance penalty RAID 1 requires every time data is saved to the disk.  I would further caution that, while an internal Time Machine disk is a convenient safety measure, any critical data should be backed up outside of the system as well.
    Now for those like me who were intrigued by the opportunity to mate the Quad Core i7 with a RAID 0/striped configuration for a performance boost (or if you want to use RAID 1), a RAID configuration is possible, but it there are a few caveats.
    First, Apple has two recovery options for the new Macs: a small hidden recovery partition on the boot drive and their Internet Recovery system.  While it's possible to boot other systems from a Lion installation DVD extracted from the App Store Lion installer, such bootable optical discs will not boot the Mac mini Server at this time (this may change if Apple modifies the App Store Lion installer).  Therefore, as of right now, the recovery partition or the Internet Recovery system are the best options for installing/reinstalling on a RAID set.
    Second, if you boot the system using Command+R to access the recovery partition, you can wipe the two drives and create a RAID set, but this process will remove the recovery partition and is incompatible with FileVault encryption (a warning to this effect comes up when you try to start an install/reinstalll on a RAID set, but at that point, you've likely already erased the recovery partition in Disk Utility).  If the system boots after the recovery partition is deleted, the only install/reinstall option is Apple's Internet Recovery.
    Third, as might be expected depending upon your internet bandwidth, the Internet Recovery system can take a while to boot the recovery tools (10-15 minutes to boot on a standard cable modem connection) and to reinstall the OS (50+ minutes on a standard cable modem connection).  Internet Recovery currently reinstalls only Mac OS X Lion and the Server tools on the mini Server; there's no option to install iLife during the OS install (Apple could always change this by updating their servers, and there is a Customize button on the installer, but it is greyed out and cannot be clicked at the present).
    Fourth, once the OS is reinstalled, it's possible to reinstall the iLife applications by launching the App Store from within Mac OS and selecting Purchased.  The store will indicate that the system is eligible to download the iLife apps and you can do so by agreeing to upload system-identifying information to Apple and signing in with your Apple ID.
    I hope all this helps.  Here's a more concise step-by-step of how to set up the system with RAID:
    THINGS YOU NEED
    A fast Internet connection for the mini
    Patience
    Hold Command+R on the keyboard at start up to boot from the system's recovery partition (if the recovery partition has been deleted, the system should start from Apple's Internet Recovery system; you may need to connect to WiFi if wired ethernet isn't available)
    Once you get into the recovery utility, select Disk Utility and for each of the two hard drives:
    highlight the drive
    select the Partition tab
    select 1 Partition from the Partition Layout pulldown menu
    select Free Space from the Format pulldown menu
    click Apply
    After you've wiped both of the drives, highlight one of the disks and click the RAID tab, then create a RAID set (striped or mirrored, as you prefer)
    Quit Disk Utility and from the main recovery utility menu select Reinstall Lion (from this point on, if you have any trouble, you can restart the mini from the Internet Recovery system and return to this point, but the recovery partition will be gone as long as you keep the RAID set)
    After you install and configure Mac OS X Lion Server (which can take well over an hour to download and install), you should be able to reinstall the iLife applications by launching the App Store App and selecting Purchased, then logging in with your Apple ID and agreeing to send your system info to Apple to download the iLife Applications
    If you're using the mini as a production server, I highly suggest setting up some local, external recovery tool, as you don't want to have system downtime protracted by having to wait for an Internet Recovery boot/reinstall.  I would also beg Apple to consider this sort of scenario and to provide more supported methods for recovering and reinstalling from local media.
    Best of luck to you all.

    I found the basic principle on another forum thanks to a guy called 'e-whizz' and this what I did to make RAID 1 work on a mac mini server with LION server.
    You can easily configure the second drive on a mac mini server for a Mirrored RAID 1 set with Lion Server without either reinstalling or erasing your existing setup.
    The initial setup process takes about 30 minutes, though the rebuilding of the mirror disk will take several hours, depending on the amount of data you have on the drive. It took around 3 hours on a new mac mini server with lion server installed, nothing else configured.
    Before you start, please ensure you have a current backup of the server. Getting the following commands wrong can render you server unusable.
    What you need to use is the command line version of Disk Utility, diskutil.
    Before you start, clone the hard drive. You can use SuperDuper (or similar, I have used SuperDuper) with copying all files onto a USB memory stick. If Lion is freshly installed, 8Gb will do. SuperDuper will create a bootable copy on the USB.
    Boot the mac mini from the external USB. To do that, reboot and hold down the option key while restarting. You will see a window, select the USB drive to boot from.
    Launch the terminal and type the following command:
    diskutil list
    This gives you a list of all the drives and partitions your system knows about.
    You need to find the Server HD partition (the first disk) and the HD2 partitions (the second disk). These are the two main ~500GB drives. You will be using the disk IDENTIFIERs when issuing the diskutil commands. For a stock standard Mac Mini Server, the commands below are correct, but if you have previously changed the volume names, or repartitioned at any stage the disk identifiers and volume names may differ.
    First enable RAID mirroring on existing Server HD volume. This will create a single disk, unpaired mirror, without affecting your data.
    Using this syntax:
    diskutil appleRAID enable mirror disktomirror
    where disktomirror is your disk identifier for Server HD
    On my mac mini server, Server HD was disk0s2, so I used this command:
    diskutil appleRAID enable mirror disk0s2
    You now need to run diskutil list again to see the disk identifier for the new RAID volume. The new RAID volume will be listed as disk# on its own at the bottom of the list.
    On my mac mini server this was disk3 (disk 2 was the USB I booted from, disk 0 the first disk and disk 1 the second disk)
    Next add the disk HD2 to the Server HD raid mirror volume (on my mac, as I said before, this is disk3) as a new member.
    This step will erase disk HD2 and begin an auto repair of the Server HD.
    Using this syntax:
    diskutil appleRAID add member newdisk raidvolume
    replacing newdisk and raidvolume with your particular disk identifiers
    On my server this was:
    diskutil appleRAID add member disk1s2 disk3
    To follow the progress of rebuilding the mirror set, type
    diskutil list
    It will show you the progress in % of the rebuilding under status
    Once finished, reboot and your RAID 1 is up and running and you have also a working backup on your USB (coz' that's where you booted from ;-)
    After reboot you can check the status of your RAID with
    diskutil appleRAID list
    Both drives should show ONLINE under status, interestingly, the device node for the RAID changed on my mac mini server from disk3 to disk2
    That's it

Maybe you are looking for