Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • SEARCH
  • Home
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 7539463
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: May 30, 20262026-05-30T07:23:20+00:00 2026-05-30T07:23:20+00:00

Recently seen in my (Snow Leopard) Mac Mini’s /var/log/secure.log : Feb 17 06:31:32 mini

  • 0

Recently seen in my (Snow Leopard) Mac Mini’s /var/log/secure.log:

    Feb 17 06:31:32 mini sshd[37945]: Invalid user charles from 220.248.31.177
    Feb 17 06:31:34 mini sshd[37947]: Invalid user charlie from 220.248.31.177
    Feb 17 06:31:37 mini sshd[37949]: Invalid user charlotte from 220.248.31.177
    Feb 17 06:31:39 mini sshd[37951]: Invalid user chase from 220.248.31.177
    Feb 17 06:31:42 mini sshd[37953]: Invalid user cher from 220.248.31.177
    Feb 17 06:31:44 mini sshd[37955]: Invalid user chester from 220.248.31.177
    Feb 17 06:31:47 mini sshd[37957]: Invalid user chile from 220.248.31.177
    Feb 17 06:31:49 mini sshd[37959]: Invalid user chip from 220.248.31.177

There are also a whole bunch of these:

    Feb 17 13:55:23 mini sshd[43204]: Invalid user beth from 23.19.81.173
    Feb 17 13:55:23 mini sshd[43206]: in pam_sm_authenticate(): Failed to determine Kerberos principal name.
    Feb 17 13:55:23 mini sshd[43204]: error: PAM: authentication error for illegal user beth from 23.19.81.173 via 192.168.0.2
    Feb 17 13:55:23 mini sshd[43204]: Failed keyboard-interactive/pam for invalid user beth from 23.19.81.173 port 59508 ssh2
    Feb 17 13:55:29 mini sshd[43207]: reverse mapping checking getaddrinfo for 23.19.81.173.rdns.ubiquity.io [23.19.81.173] failed - POSSIBLE BREAK-IN ATTEMPT!

Everything begins around 6 Feb and continues until 20 Feb, when I discovered it and deactivated my router’s port 22 forwarding. The attempts come from many ip addresses, China, North America, God knows where else (I didn’t check them all), but the ups are always grouped in long sessions as you see here. Megabytes-worth. There doesn’t seem to be any indication of a successful login — I have a non-standard username — but here’s the funny part that has me worried…

I only bothered to check the logs because I couldn’t login to a certain second account — the password had changed. Frustrated, I tried to log in as root, but root password had changed as well. However, the password for my regular user login — which is always logged in — hadn’t changed.

I fixed the passwords, had to single-user as usual to do root. All else seems to be normal, but the password changes have me worried — a lot. Has anyone heard of this kind of thing? Any way to know if I was hacked?

Much obliged.

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-05-30T07:23:22+00:00Added an answer on May 30, 2026 at 7:23 am

    If your passwords changed on your system without your knowledge — and you’re the only one who has access — then you likely have already been compromised. Nuke and pave.

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

I've seen a lot of code recently formatted as the following: A: if ($var=='test'){
I recently reinstalled Snow Leopard on my iMac. Installing previous versions of the iPhone
Having recently seen a presentation of Clojure Protocols, I was quite impressed by the
I have recently seen new Iron languages get released into the .Net realm. So
Recently i've seen lots of modern web pages that can be scrolled using the
Recently I have seen this code in a WebSite, and my question is the
recently I have seen this code arrMove = new List<int[]>(4); m_pppiCaseMoveDiagLine = new int[64][][];
Recently, I had seen some D flip-flop RTL code in verilog like this: module
I've seen an interesting code base recently, where some arguments were passed to methods
I've seen the experimental API for using Bluetooth has been recently released and I

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.