3 ms·
Unless you had logs in Transmit indicating it was used, I would recommend not saying they used Transmit to do it - considering OS X has a builtin command-line s
by pudquick 14y ago
Unless you had logs in Transmit indicating it was used, I would recommend not saying they used Transmit to do it - considering OS X has a builtin command-line sftp client:
http://developer.apple.com/library/mac/documentation/Darwin/Reference/ManPages/man1/sftp.1.html http://developer.apple.com/library/mac/documentation/Darwin/...
If you're still concerned your machine is affected, I'd recommend getting Little Snitch - which automatically blocks connections (both in-bound and out-bound) that are not pre-approved. In addition, when it auto-blocks it records the application that was making the connection attempt in the auto-block rule.
(Well, actually I'd suggest you dd a backup of the drive to analyze - then wipe and start anew.)
If they hired anyone of any worth, the person installed a timed launchd (or cron) controlled script to run rarely and at odd hours to upload content from your machine to those remote locations. This kind of setup a.) would use a command-line tool for the upload and b.) unless they knew you had Transmit it would be designed around executables already included in OS X or that they installed.
Unfortunately, if it has stopped, they've probably deleted the scripts and cleaned up the evidence. If you've got Time Machine running, however, you may have backed up some of their handiwork.
- nickzoic 14y agoOK, the proper way to do this is to not touch the machine at all. Shut it down and leave it alone. Maybe borrow its hard drive and back it up using 'dd'. Set up a separate Linux (etc) machine with two ethernet ports as a firewall/router, running wireshark in addition to everything else. It can now log all packets in and out of your network, and save them for later analysis. If nothing interesting happens in the time it takes you to get bored, copy just the files you really need across from your old HDD to a shiny new one.
- pudquick 14y agoGiven that the author of the blog post seems to understand cryptography - but doesn't seem to have much in the way of the forensics skill set - I did intentionally try to keep my post at the general consumer level (though I did mention dd, like you suggested). The real -legal- solution is to turn the computer off, stop touching it, and get a lawyer specializing in computer crimes. Get the machine to them so they can make an image of the drive, complete with hashes of the filesystem, so that they can prove it hasn't been tampered with past that point. Then let -them- do the investigation, with someone that has the documented skills a court would recognize. Thank you for your response, though. I was just trying to be a little more practical.
- nickzoic 14y agoGood point(s). I was more addressing the techical "How can I tell if my computer is haunted?" question than the original poster's legal issues, on which I am not at all qualified to speculate.