image
image

Go Back   macosx.com > Mac Help Forums > Mac OS X System & Mac Software

Reply
 
Thread Tools
  #1  
Old February 2nd, 2006, 01:12 PM
Registered User
 
Join Date: Dec 2005
Posts: 57
Thanks: 0
Thanked 0 Times in 0 Posts
bbolin is on a distinguished road
What is this I'm seeing in /var/log/secure.log

Feb 2 12:01:33 Mac com.apple.SecurityServer: authinternal failed to authenticate user hate.
Feb 2 12:01:33 Mac com.apple.SecurityServer: Failed to authorize right system.login.tty by process /usr/sbin/sshd for authorization created by /usr/sbin/sshd.
Feb 2 12:01:35 Mac com.apple.SecurityServer: authinternal failed to authenticate user fuck.
Feb 2 12:01:35 Mac com.apple.SecurityServer: Failed to authorize right system.login.tty by process /usr/sbin/sshd for authorization created by /usr/sbin/sshd.
Feb 2 12:01:38 Mac com.apple.SecurityServer: authinternal failed to authenticate user image.
Feb 2 12:01:38 Mac com.apple.SecurityServer: Failed to authorize right system.login.tty by process /usr/sbin/sshd for authorization created by /usr/sbin/sshd.


Attemped logins via ssh are nothing new. The above indicate there comming from com.apple.securityserver

When I attempt to simulate with a bogus login and password noting appears in the log.

Any ideas ?
Reply With Quote
  #2  
Old February 2nd, 2006, 02:14 PM
fryke's Avatar
Super Moderator
 
Join Date: Sep 2000
Location: macosx.com
Posts: 13,322
Thanks: 2
Thanked 21 Times in 19 Posts
fryke has a spectacular aura aboutfryke has a spectacular aura about
No. See: It's com.apple.SecurityServer - that's your local "SecurityServer" service for you.
__________________
MacBook Air 13" 1.6 GHz, 2 GB RAM, 80 GB HD. Mac OS X 10.5.5
Hackintosh Core2Duo 2.4 GHz, 2 GB RAM, 160 GB HD. Mac OS X 10.5.5
iPhone 3G 16 GB white, AppleTV 1G 40 GB

Mac user since 1987, Apple Product Professional 2007, 2008. Apple Certified Support Professional 10.5
Reply With Quote
  #3  
Old February 2nd, 2006, 02:22 PM
Registered User
 
Join Date: Dec 2005
Posts: 57
Thanks: 0
Thanked 0 Times in 0 Posts
bbolin is on a distinguished road
With login names like that ?

Humm
Reply With Quote
  #4  
Old February 2nd, 2006, 05:53 PM
fryke's Avatar
Super Moderator
 
Join Date: Sep 2000
Location: macosx.com
Posts: 13,322
Thanks: 2
Thanked 21 Times in 19 Posts
fryke has a spectacular aura aboutfryke has a spectacular aura about
Well, no, those are probably trying to do something from the outside. But you made it sound as if com.apple.securityserver were an outside internet node. It's not that is all I'm saying.
__________________
MacBook Air 13" 1.6 GHz, 2 GB RAM, 80 GB HD. Mac OS X 10.5.5
Hackintosh Core2Duo 2.4 GHz, 2 GB RAM, 160 GB HD. Mac OS X 10.5.5
iPhone 3G 16 GB white, AppleTV 1G 40 GB

Mac user since 1987, Apple Product Professional 2007, 2008. Apple Certified Support Professional 10.5
Reply With Quote
  #5  
Old February 2nd, 2006, 07:26 PM
ElDiabloConCaca's Avatar
U.S.D.A. Prime
 
Join Date: Aug 2001
Location: San Antonio, Texas
Posts: 10,374
Thanks: 3
Thanked 124 Times in 113 Posts
ElDiabloConCaca is a jewel in the roughElDiabloConCaca is a jewel in the roughElDiabloConCaca is a jewel in the rough
Do you have "Remote Login" enabled in the "Sharing" pane of the System Preferences? If not, then you're completely safe from ssh attacks.

Could it also be possible that someone else tried to log in locally on your machine? Or perhaps a little brother/cousin/friend/enemy/space alien was just messing around at the login screen, seeing if anything worked or would let them in?
__________________
Power Macintosh G4/500MHz "Yikes!" 10.4.11 Server • 1024MB • 3 x 120GB + 320GB • DVR-111D • 2 x Radeon 7000 PCI • 2 x 17" CRT
MacBook 2.0GHz Core 2 Duo - White 10.5.5 • 2048MB • 80GB • CD-RW/DVD-ROM
iPod Photo 60GB • iPod nano 1GB • AT&T DSL 6Mb/768k
http://www.jeffhoppe.com
Reply With Quote
  #6  
Old February 3rd, 2006, 11:57 AM
Registered User
 
Join Date: Dec 2005
Posts: 57
Thanks: 0
Thanked 0 Times in 0 Posts
bbolin is on a distinguished road
sshd is enabled. I use it for remote windoze tunneled vnc session into the mac.

It's just interesting the way Darwin reports the attempted login. Below is more of a unixy way of reporting it.

Feb 3 10:51:50 mail sshd[65841]: Failed password for illegal user foobar from x.x.x.x port 49482 ssh2

Local server name is mail. The remote host is x.x.x.x
Reply With Quote
  #7  
Old February 3rd, 2006, 01:08 PM
lurk's Avatar
Mitδ?
 
Join Date: Mar 2002
Location: Land o' skeeterz
Posts: 2,076
Thanks: 0
Thanked 0 Times in 0 Posts
lurk is on a distinguished road
All that is going on is that Apple is using the Java-esque qualified name for the service. In your original message the server name was Mac (mail in the second) and the process was com.apple.SecurityServer (sshd in the second) the original log entries did not contain any mention of the remote host.

This is exactly the same as the unixy way in your second example you are just getting thrown by the logging service name looking a bit different.
Reply With Quote
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
How Secure is Secure Empty trash? JeffCGD Mac OS X System & Mac Software 9 April 18th, 2004 12:54 AM
OS X :: how secure art thou? gerbick Apple News, Rumors & Discussion 33 March 25th, 2004 10:56 AM
802.1x Secure Implementation compton Mac OS X System & Mac Software 4 August 16th, 2003 11:04 AM
secure ftp access frenchcolumbo Apple News, Rumors & Discussion 4 October 3rd, 2000 12:21 PM


All times are GMT -5. The time now is 03:00 PM.


Mac Support® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.1.0
Copyright 2000-2008 DigitalCrowd, Inc.