Who is trying to login to my OSX laptop?
December 27, 2006 7:41 PM
Subscribe
OSX Security: I followed the instructions on
this MacOSXhints article to setup my shiny new MacBook Pro to take a picture using the built-in iSight whenever there's a failed authentication attempt. I've noticed that every night at 9:53, there are multiple failed login attempts, but it's while I'm using the computer, so I end up with pictures of me.
Take a gander at this log (/var/log/asl.log). The following repeats, substituting one of many usernames for "webmaster":
[Time 2006.12.28 02:53:50 UTC] [Facility authpriv] [Sender com.apple.SecurityServer] [PID -1] [Message authinternal failed to authenticate user webmaster.] [Level 3] [UID -2] [GID -2] [Host msca-cghota-mbp17]
[Time 2006.12.28 02:53:50 UTC] [Facility authpriv] [Sender com.apple.SecurityServer] [PID -1] [Message Failed to authorize right system.login.tty by process /usr/sbin/sshd for authorization created by /usr/sbin/sshd.] [Level 5] [UID -2] [GID -2] [Host msca-cghota-mbp17]
At first I thought it was a network-based attack; however, tonight I did this while not joined to the network. The accounts scanned include: admin, ftp, ftpuser, guestuser, root, test (x12), testuser (x2), user (x4), webadmin, and webmaster.
What is going on!? If nothing else, how can I get more information about tracking this down? I'm a switcher (an MCSE from the Windows world, actually), so I'm a bit out of my depth.
posted by chota to computers & internet (16 comments total)
3 users marked this as a favorite
When you say you weren't joined to the network, was this due to you not being physically wired to an ethernet cable, or because Airport was off?
posted by tomierna at 8:44 PM on December 27, 2006