image
image

|


Go Back   macosx.com > Mac Help Forums > Unix & X11

Reply
 
Thread Tools
  #1  
Old February 27th, 2006, 09:00 PM
Registered User
 
Join Date: Sep 2000
Location: San Francisco
Posts: 221
Thanks: 0
Thanked 0 Times in 0 Posts
ericmurphy is on a distinguished road
Security threat? Exploit attempt?

I was going through my system log recently, for a completely unrelated reason, when I came across the following entries:


Feb 27 17:04:23 DeepBlu DirectoryService[38]: Failed Authentication return is being delayed due to over five recent auth failures for username: <user2>.
Feb 27 17:18:06 DeepBlu DirectoryService[38]: Failed Authentication return is being delayed due to over five recent auth failures for username: <user3>.
Feb 27 17:21:15 DeepBlu DirectoryService[38]: Failed Authentication return is being delayed due to over five recent auth failures for username: <user1>.
Feb 27 17:23:41 DeepBlu DirectoryService[38]: Failed Authentication return is being delayed due to over five recent auth failures for username: <user1>.

(Obviously I replaced the names of actual user accounts with <userx>)

Is this evidence of an attempt to break into my system? It looks like an attempt to login (not sure whether via ssh, ftp, etc) one each of three different accounts (there are five other accounts, but these would be the three most obvious to someone who knows me pretty well). Fortunately, none of the three are administrative accounts, but it's got me worried nevertheless. Only one of these accounts is likely to be used on any given day, and these log entries are all within a few minutes of each other.

Or are these just common system errors?
Reply With Quote
  #2  
Old February 28th, 2006, 06:07 AM
bbloke's Avatar
Registered User
 
Join Date: Jun 2002
Location: UK
Posts: 1,337
Thanks: 0
Thanked 6 Times in 5 Posts
bbloke has a spectacular aura aboutbbloke has a spectacular aura about
I've seen something like that within the logs of an IRIX workstation, and I would guess it was, in my case, an automated attempt to login to the system using common usernames. In your case, assuming your account names are obscure (i.e. not something like "john!"), then it could well be that someone who knows you is trying to get in, unless your usernames and passwords were somehow easy to intercept at another point (eg. not using ssh or sftp, but using unencrypted methods instead).

There are a few things you can do, such as avoid enabling the root account (trying to login as "root" is a fairly reasonable guess if the attempts are indeed automated), don't enable any services unless really necessary, restrict remote logins to certain users, ensure your firewall is on, use NAT and port forwarding if behind a router, and you can deny access to certain IP addresses if you have frequent connection attempts from one location... or... better yet... deny access to all IP addresses except a very, very limited few!
Reply With Quote
  #3  
Old February 28th, 2006, 06:14 PM
tomdkat's Avatar
Registered User
 
Join Date: Aug 2005
Posts: 194
Thanks: 5
Thanked 0 Times in 0 Posts
tomdkat is on a distinguished road
What is "DirectoryService"?

Peace...
Reply With Quote
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
itunes freezes when i attempt to autofill aa1919 Hardware & Peripherals 0 February 2nd, 2006 08:30 PM
Security threat? Orbit Mac OS X System & Mac Software 5 August 2nd, 2004 09:13 PM
Security exploit in SoftwareUpdate? didde Apple News, Rumors & Discussion 3 July 9th, 2002 11:55 AM
Attempt to load failed Jadey Site Discussion 6 August 6th, 2001 07:38 AM
Security hole to Exploit FUGGER Apple News, Rumors & Discussion 0 August 1st, 2001 05:26 PM


All times are GMT -5. The time now is 10:54 PM.


Mac Support® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.1.0
Copyright 2000-2008 DigitalCrowd, Inc.