4 ms·
Hello, I'm the person who wrote the blog post. I am using Transmit for Mac OS X, by Panic Software, version 4.2.
by magikarp 14y ago
Hello, I'm the person who wrote the blog post.
I am using Transmit for Mac OS X, by Panic Software, version 4.2.
- benmmurphy 14y agotransmit can be scripted so it could be anything running on the machine that is backdoored. i assume they had connection for sending commands that was separate because the sftp sounds like it was blocked but the uploading stopped apparently in response to external stimuli. seems kind of lame to have some kind of connection sending commands and then using transmit to upload files.
- pudquick 14y agoUnless you had logs in Transmit indicating it was used, I would recommend not saying they used Transmit to do it - considering OS X has a builtin command-line sftp client: http://developer.apple.com/library/mac/documentation/Darwin/Reference/ManPages/man1/sftp.1.html http://developer.apple.com/library/mac/documentation/Darwin/... If you're still concerned your machine is affected, I'd recommend getting Little Snitch - which automatically blocks connections (both in-bound and out-bound) that are not pre-approved. In addition, when it auto-blocks it records the application that was making the connection attempt in the auto-block rule. (Well, actually I'd suggest you dd a backup of the drive to analyze - then wipe and start anew.) If they hired anyone of any worth, the person installed a timed launchd (or cron) controlled script to run rarely and at odd hours to upload content from your machine to those remote locations. This kind of setup a.) would use a command-line tool for the upload and b.) unless they knew you had Transmit it would be designed around executables already included in OS X or that they installed. Unfortunately, if it has stopped, they've probably deleted the scripts and cleaned up the evidence. If you've got Time Machine running, however, you may have backed up some of their handiwork.
- nickzoic 14y agoOK, the proper way to do this is to not touch the machine at all. Shut it down and leave it alone. Maybe borrow its hard drive and back it up using 'dd'. Set up a separate Linux (etc) machine with two ethernet ports as a firewall/router, running wireshark in addition to everything else. It can now log all packets in and out of your network, and save them for later analysis. If nothing interesting happens in the time it takes you to get bored, copy just the files you really need across from your old HDD to a shiny new one.
- pudquick 14y agoGiven that the author of the blog post seems to understand cryptography - but doesn't seem to have much in the way of the forensics skill set - I did intentionally try to keep my post at the general consumer level (though I did mention dd, like you suggested). The real -legal- solution is to turn the computer off, stop touching it, and get a lawyer specializing in computer crimes. Get the machine to them so they can make an image of the drive, complete with hashes of the filesystem, so that they can prove it hasn't been tampered with past that point. Then let -them- do the investigation, with someone that has the documented skills a court would recognize. Thank you for your response, though. I was just trying to be a little more practical.
- nickzoic 14y agoGood point(s). I was more addressing the techical "How can I tell if my computer is haunted?" question than the original poster's legal issues, on which I am not at all qualified to speculate.
- weslly 14y agoWhich firewall are you using? The one builtin on OSX?
- chm 14y agoI don't want to hijack the thread, but I am using the built-in OS X firewall. Anything wrong with that?
- weslly 14y agoNope, just want to know (since I use it too but i'm looking for something better)
- andreyf 14y ago> Anything wrong with that? If you want to protect against the kind of attach he hypothesizes to have experienced, yes. Trying to catch root backdoor on your machine by running a firewall on that same machine won't be much help. He called it an "external firewall", so I imagine it was a separate machine that noticed the outgoing requests.
- chm 14y agoThat I understand, but I was wondering if there were inherent problems with the standard FW.
- memracom 14y agoYes, there are inherent problems with the built-in firewall. The bad guys know it is there so any exploit that they install will likely modify the firewall to cover their tracks. External firewalls can be trusted more than built-in software.
- jlgaddis 14y agoI would be surprised if the built-in firewall even blocks any outgoing connections by default. I'm not on my MBP at the moment so I can't check for sure.