Forums
New posts
Articles
Product Reviews
Policies
FAQ
Log in
Register
What's new
Search
Search
Search titles only
By:
New posts
Menu
Log in
Register
Install the app
Install
Forums
Apple Computing Products:
macOS - Operating System
Hacked
JavaScript is disabled. For a better experience, please enable JavaScript in your browser before proceeding.
You are using an out of date browser. It may not display this or other websites correctly.
You should upgrade or use an
alternative browser
.
Reply to thread
Message
<blockquote data-quote="adychis" data-source="post: 1468468" data-attributes="member: 282462"><p>I got a feeling i have been hacked, stuff disappearing off my drive, blue tooth turning on its own.... heres the log anything in that to suggest i have</p><p></p><p>[CODE]</p><p>Proto Recv-Q Send-Q Local Address Foreign Address (state) </p><p>tcp4 0 0 192.168.0.2.56751 65.55.96.11.smtp SYN_SENT </p><p>tcp4 0 0 192.168.0.2.56750 65.55.96.11.urd SYN_SENT </p><p>tcp4 0 0 192.168.0.2.56749 65.55.96.11.submission SYN_SENT </p><p>tcp4 0 0 192.168.0.2.56748 sourceforge.free.http ESTABLISHED</p><p>tcp4 0 0 192.168.0.2.56747 downloads.source.http CLOSE_WAIT </p><p>tcp4 0 0 192.168.0.2.56746 17.172.34.33.imaps SYN_SENT </p><p>tcp4 0 0 192.168.0.2.56745 17.164.0.83.imaps SYN_SENT </p><p>tcp4 0 0 192.168.0.2.56744 a92-123-83-172.d.http ESTABLISHED</p><p>tcp4 0 0 192.168.0.2.56742 images.sourcefor.http CLOSE_WAIT </p><p>tcp4 0 0 192.168.0.2.56741 host159-rangec-a.http ESTABLISHED</p><p>tcp4 0 0 192.168.0.2.56740 a92-123-83-172.d.http ESTABLISHED</p><p>tcp4 0 0 192.168.0.2.56738 a92-123-83-172.d.http ESTABLISHED</p><p>tcp4 0 0 192.168.0.2.56737 a92-123-83-172.d.http ESTABLISHED</p><p>tcp4 0 0 192.168.0.2.56736 a92-123-83-172.d.http ESTABLISHED</p><p>tcp4 0 0 192.168.0.2.56735 a92-123-83-172.d.http ESTABLISHED</p><p>tcp4 0 0 192.168.0.2.56734 a92-123-83-172.d.http ESTABLISHED</p><p>tcp4 0 0 192.168.0.2.56730 speed.xssl.net.urd SYN_SENT </p><p>tcp4 0 0 192.168.0.2.56729 speed.xssl.net.urd SYN_SENT </p><p>tcp4 0 0 192.168.0.2.56719 speed.xssl.net.pop3 SYN_SENT </p><p>tcp4 0 0 192.168.0.2.56718 lhr14s21-in-f9.1.https ESTABLISHED</p><p>tcp4 0 0 192.168.0.2.56712 speed.xssl.net.urd SYN_SENT </p><p>tcp4 0 0 localhost.9333 localhost.56296 ESTABLISHED</p><p>tcp4 0 0 localhost.56296 localhost.9333 ESTABLISHED</p><p>tcp4 0 0 192.168.0.2.56253 st11p01st-courie.https ESTABLISHED</p><p>tcp4 0 0 localhost.49154 localhost.1023 ESTABLISHED</p><p>tcp4 0 0 localhost.1023 localhost.49154 ESTABLISHED</p><p>udp4 0 0 192.168.0.2.ntp *.* </p><p>udp6 0 0 *.49765 *.* </p><p>udp4 0 0 *.49765 *.* </p><p>udp6 0 0 *.51339 *.* </p><p>udp4 0 0 *.51339 *.* </p><p>udp6 0 0 *.60911 *.* </p><p>udp4 0 0 *.60911 *.* </p><p>udp6 0 0 *.50433 *.* </p><p>udp4 0 0 *.50433 *.* </p><p>udp6 0 0 *.64045 *.* </p><p>udp4 0 0 *.64045 *.* </p><p>udp6 0 0 *.50662 *.* </p><p>udp4 0 0 *.50662 *.* </p><p>udp6 0 0 *.59624 *.* </p><p>udp4 0 0 *.59624 *.* </p><p>udp6 0 0 *.65362 *.* </p><p>udp4 0 0 *.65362 *.* </p><p>udp6 0 0 *.63258 *.* </p><p>udp4 0 0 *.63258 *.* </p><p>udp6 0 0 *.63173 *.* </p><p>udp4 0 0 *.63173 *.* </p><p>udp6 0 0 *.58803 *.* </p><p>udp4 0 0 *.58803 *.* </p><p>udp6 0 0 *.53003 *.* </p><p>udp4 0 0 *.53003 *.* </p><p>udp6 0 0 *.51868 *.* </p><p>udp4 0 0 *.51868 *.* </p><p>udp6 0 0 *.52934 *.* </p><p>udp4 0 0 *.52934 *.* </p><p>udp6 0 0 *.53485 *.* </p><p>udp4 0 0 *.53485 *.* </p><p>udp6 0 0 *.50491 *.* </p><p>udp4 0 0 *.50491 *.* </p><p>udp6 0 0 *.49275 *.* </p><p>udp4 0 0 *.49275 *.* </p><p>udp6 0 0 *.59714 *.* </p><p>udp4 0 0 *.59714 *.* </p><p>udp6 0 0 *.60934 *.* </p><p>udp4 0 0 *.60934 *.* </p><p>udp6 0 0 *.59132 *.* </p><p>udp4 0 0 *.59132 *.* </p><p>udp6 0 0 *.63105 *.* </p><p>udp4 0 0 *.63105 *.* </p><p>udp6 0 0 *.50697 *.* </p><p>udp4 0 0 *.50697 *.* </p><p>udp6 0 0 *.60448 *.* </p><p>udp4 0 0 *.60448 *.* </p><p>udp6 0 0 ady-mac-pro.ntp *.* </p><p>udp4 0 0 192.168.0.2.55514 *.* </p><p>udp4 0 0 239.255.255.250.ssdp *.* </p><p>udp4 0 0 *.* *.* </p><p>udp4 0 0 *.* *.* </p><p>udp4 0 0 *.* *.* </p><p>udp4 0 0 *.* *.* </p><p>udp6 0 0 localhost.ntp *.* </p><p>udp4 0 0 localhost.ntp *.* </p><p>udp6 0 0 localhost.ntp *.* </p><p>udp6 0 0 *.ntp *.* </p><p>udp4 0 0 *.ntp *.* </p><p>udp4 0 0 *.* *.* </p><p>udp4 0 0 *.* *.* </p><p>udp4 0 0 *.* *.* </p><p>udp4 0 0 *.* *.* </p><p>udp46 0 0 *.* *.* </p><p>udp6 0 0 *.mdns *.* </p><p>udp4 0 0 *.mdns *.* </p><p>udp4 0 0 *.netbios-dgm *.* </p><p>udp4 0 0 *.netbios-ns *.* </p><p>icm6 0 0 *.* *.*</p><p>[/CODE]</p></blockquote><p></p>
[QUOTE="adychis, post: 1468468, member: 282462"] I got a feeling i have been hacked, stuff disappearing off my drive, blue tooth turning on its own.... heres the log anything in that to suggest i have [CODE] Proto Recv-Q Send-Q Local Address Foreign Address (state) tcp4 0 0 192.168.0.2.56751 65.55.96.11.smtp SYN_SENT tcp4 0 0 192.168.0.2.56750 65.55.96.11.urd SYN_SENT tcp4 0 0 192.168.0.2.56749 65.55.96.11.submission SYN_SENT tcp4 0 0 192.168.0.2.56748 sourceforge.free.http ESTABLISHED tcp4 0 0 192.168.0.2.56747 downloads.source.http CLOSE_WAIT tcp4 0 0 192.168.0.2.56746 17.172.34.33.imaps SYN_SENT tcp4 0 0 192.168.0.2.56745 17.164.0.83.imaps SYN_SENT tcp4 0 0 192.168.0.2.56744 a92-123-83-172.d.http ESTABLISHED tcp4 0 0 192.168.0.2.56742 images.sourcefor.http CLOSE_WAIT tcp4 0 0 192.168.0.2.56741 host159-rangec-a.http ESTABLISHED tcp4 0 0 192.168.0.2.56740 a92-123-83-172.d.http ESTABLISHED tcp4 0 0 192.168.0.2.56738 a92-123-83-172.d.http ESTABLISHED tcp4 0 0 192.168.0.2.56737 a92-123-83-172.d.http ESTABLISHED tcp4 0 0 192.168.0.2.56736 a92-123-83-172.d.http ESTABLISHED tcp4 0 0 192.168.0.2.56735 a92-123-83-172.d.http ESTABLISHED tcp4 0 0 192.168.0.2.56734 a92-123-83-172.d.http ESTABLISHED tcp4 0 0 192.168.0.2.56730 speed.xssl.net.urd SYN_SENT tcp4 0 0 192.168.0.2.56729 speed.xssl.net.urd SYN_SENT tcp4 0 0 192.168.0.2.56719 speed.xssl.net.pop3 SYN_SENT tcp4 0 0 192.168.0.2.56718 lhr14s21-in-f9.1.https ESTABLISHED tcp4 0 0 192.168.0.2.56712 speed.xssl.net.urd SYN_SENT tcp4 0 0 localhost.9333 localhost.56296 ESTABLISHED tcp4 0 0 localhost.56296 localhost.9333 ESTABLISHED tcp4 0 0 192.168.0.2.56253 st11p01st-courie.https ESTABLISHED tcp4 0 0 localhost.49154 localhost.1023 ESTABLISHED tcp4 0 0 localhost.1023 localhost.49154 ESTABLISHED udp4 0 0 192.168.0.2.ntp *.* udp6 0 0 *.49765 *.* udp4 0 0 *.49765 *.* udp6 0 0 *.51339 *.* udp4 0 0 *.51339 *.* udp6 0 0 *.60911 *.* udp4 0 0 *.60911 *.* udp6 0 0 *.50433 *.* udp4 0 0 *.50433 *.* udp6 0 0 *.64045 *.* udp4 0 0 *.64045 *.* udp6 0 0 *.50662 *.* udp4 0 0 *.50662 *.* udp6 0 0 *.59624 *.* udp4 0 0 *.59624 *.* udp6 0 0 *.65362 *.* udp4 0 0 *.65362 *.* udp6 0 0 *.63258 *.* udp4 0 0 *.63258 *.* udp6 0 0 *.63173 *.* udp4 0 0 *.63173 *.* udp6 0 0 *.58803 *.* udp4 0 0 *.58803 *.* udp6 0 0 *.53003 *.* udp4 0 0 *.53003 *.* udp6 0 0 *.51868 *.* udp4 0 0 *.51868 *.* udp6 0 0 *.52934 *.* udp4 0 0 *.52934 *.* udp6 0 0 *.53485 *.* udp4 0 0 *.53485 *.* udp6 0 0 *.50491 *.* udp4 0 0 *.50491 *.* udp6 0 0 *.49275 *.* udp4 0 0 *.49275 *.* udp6 0 0 *.59714 *.* udp4 0 0 *.59714 *.* udp6 0 0 *.60934 *.* udp4 0 0 *.60934 *.* udp6 0 0 *.59132 *.* udp4 0 0 *.59132 *.* udp6 0 0 *.63105 *.* udp4 0 0 *.63105 *.* udp6 0 0 *.50697 *.* udp4 0 0 *.50697 *.* udp6 0 0 *.60448 *.* udp4 0 0 *.60448 *.* udp6 0 0 ady-mac-pro.ntp *.* udp4 0 0 192.168.0.2.55514 *.* udp4 0 0 239.255.255.250.ssdp *.* udp4 0 0 *.* *.* udp4 0 0 *.* *.* udp4 0 0 *.* *.* udp4 0 0 *.* *.* udp6 0 0 localhost.ntp *.* udp4 0 0 localhost.ntp *.* udp6 0 0 localhost.ntp *.* udp6 0 0 *.ntp *.* udp4 0 0 *.ntp *.* udp4 0 0 *.* *.* udp4 0 0 *.* *.* udp4 0 0 *.* *.* udp4 0 0 *.* *.* udp46 0 0 *.* *.* udp6 0 0 *.mdns *.* udp4 0 0 *.mdns *.* udp4 0 0 *.netbios-dgm *.* udp4 0 0 *.netbios-ns *.* icm6 0 0 *.* *.* [/CODE] [/QUOTE]
Verification
Name this item. 🍎
Post reply
Forums
Apple Computing Products:
macOS - Operating System
Hacked
Top