阅读880 返回首页    go iPhone_iPad_Mac_apple


Why is Kerberos reaching out?

Why would kdc (Kerberos) want to connect to inspire.census.shodan.io on UDP port 48134, as "root"?

Is apple (my computer) sending information about my whereabouts to a third party?



It is unlikely Apple is sending anything about you to anyone.

 

More likely is that you have 3rd party software installed that is doing this.

 

Please post the EtreCheck output as a "Reply" to this thread

<https://discussions.apple.com/docs/DOC-6174> or <https://etrecheck.com>

Use the EtreCheck "Share" button to "Copy to clipboard" (See the image below)

If, AND ONLY IF, you get the error:

    "The message contains invalid characters"

then try posting to PasteBin.com, and give us a PasteBin URL link.

<https://pastebin.com/>

.

EtreCheck is a tool that helps Apple Support Community volunteers debug problems without any access to the troubled computers. Debugging problems can be a difficult task even when the machine is in front of you. Attempting it via a discussion forum is extremely difficult. EtreCheck is a great help that regards.

 

You might also consider running MalwareBytes <https://www.malwarebytes.org/>

 

Both EtreCheck and MalwareBytes were written by long time Apple Discussion Forum's Volunteers, and both contributers have earned a lot of respect in these forums.



I download your application, run it and it automagically knows that I want to show debug info regarding Kerberos activities?

What info do you need to answer my question?

What is inspire.census.shodan.io, and why is Kerberos trying to connect to it?



Are you asking or just being obtuse?

if you post an etrecheck report the volunteers here can assist with a clearer picture of what is installed and running on your system. If you don't want advice from here there are countless other forums on the web who's members would love nothing more than to waste the day guessing without usable information.



What is inspire.census.shodan.io, and why is Kerberos trying to connect to it?

That is what Google is for. 



Read this article : Prepare for macOS Sierra 10.12 with Active Directory - Apple Support



Excuse me Jimmy, why do you need to be rude? And to be clear, yes I really want to know.

 

I would say it's rather sensible to be careful and suspicious about unknown software that a complete stranger tells you to install and run. Wouldn't you?

 

Everybody aren't computer wizards. I thought that the Apple Community was a place for apple users to get help.

Why not just reinsure me that Etrecheck is indeed a legitimate software instead.

 

Anyway, BobHarris just implied, Etrecheck or not, Google is apparently better than Apple Communities to get help regarding Kerberos.



Kojoman wrote:

 

Excuse me Jimmy, why do you need to be rude? And to be clear, yes I really want to know.

 

I would say it's rather sensible to be careful and suspicious about unknown software that a complete stranger tells you to install and run. Wouldn't you?

 

Everybody aren't computer wizards. I thought that the Apple Community was a place for apple users to get help.

Why not just reinsure me that Etrecheck is indeed a legitimate software instead.

 

Anyway, BobHarris just implied, Etrecheck or not, Google is apparently better than Apple Communities to get help regarding Kerberos.

If you are not prepared to share the report here Google is much better at eliciting responses from people who have no idea.



The volunteers are unpaid, and cannot be expected to know everything.  Google craws the web to find every corner of it and index it.  The web is much larger than the Apple forums.

 

As mentioned when I asked for EtreCheck output, the author is well respected.  You can search for EtreCheck output and see thousands of posts.  You can review the output and see that it is not doing anything.  If you are truly paranoid, it is even possible to review the sources on GitHub.  The forum Volunteers depend on EtreCheck to provide useful information about a user's system without giving away any of the user's personal information.



Thank you, I'm afraid I didn't understand much of that article, but do you mean that this could be because my university is using active directory that I get these requests?

 

Here's my Etrecheck dump and thank you in advance. Sorry if questioning Etrecheck stepped on peoples toes. I wasn't aware that's how things work around here.

EtreCheck version: 3.4.2 (436)

Report generated 2017-08-18 16:03:34

Download EtreCheck from https://etrecheck.com

Runtime: 3:07

Performance: Good

 

Click the [Lookup] links for more information from Apple Support Communities.

Click the [Details] links for more information about that line.

Click the [Remove/Report] links to remove adware or update the whitelist of legitimate software.

Click the [Clean up] link to delete unused files.

 

Problem: No problem - just checking

Description:

Investigating Kerberos connections

 

Hardware Information:

    MacBook Pro (15-inch, 2016)

    [Technical Specifications] - [User Guide] - [Warranty & Service]

    MacBook Pro - model: MacBookPro13,3

    1 2,6 GHz Intel Core i7 (i7-6700HQ) CPU: 4-core

    16 GB RAM Not upgradeable

        BANK 0/DIMM0

            8 GB LPDDR3 2133 MHz ok

        BANK 1/DIMM0

            8 GB LPDDR3 2133 MHz ok

    Bluetooth: Good - Handoff/Airdrop2 supported

    Wireless:  en0: 802.11 a/b/g/n/ac

    Battery: Health = Normal - Cycle count = 66

    iCloud Quota: 2.44 GB available

 

Video Information:

    AMD Radeon Pro 450 - VRAM: 2048 MB

        Color LCD 3360 x 2100

        HP Z30i 2560 x 1600 @ 60 Hz

        LED Cinema Display 2560 x 1440

    Intel HD Graphics 530 - VRAM: 1536 MB

 

Disk Information:

    APPLE SSD SM0512L disk0: (500,28 GB) (Solid State - TRIM: Yes)

        (disk0s1) <not mounted>  [EFI]: 315 MB

        (disk0s2) <not mounted>  [CoreStorage Container]: 499.31 GB

        Recovery HD (disk0s3 - Journaled HFS+) <not mounted>  [Recovery]: 650 MB

 

USB Information:

     USB30Bus

        VIA Labs, Inc.          USB2.0 Hub             

             USB 2.0 Hub

                 USB2.0 Hub

                     USB2.0 Hub

                        Logitech USB RECEIVER

                        RODE Microphones RODE NT-USB

                        Samson Technologies Samson StudioGT

                        Apple Inc. AirPod Case

                 hub_device

                    Apple, Inc. Keyboard Hub

                        Apple, Inc Apple Keyboard

                    Apple Inc. Apple LED Cinema Display

                    Apple Inc. Display iSight

                    Apple Inc. Display Audio

        Apple Inc. iBridge

     USB31Bus

        VIA Labs, Inc.          USB3.0 Hub             

            ASIX Elec. Corp. AX88179

     USB31Bus

 

Thunderbolt Information:

    Apple Inc. thunderbolt_bus_1

    Apple Inc. thunderbolt_bus_0

 

Virtual disks:

    Mac_HD (disk1 - Journaled HFS+) /  [Startup]: 498.94 GB (368.74 GB free)

        Physical disk: disk0s2 499.31 GB Online

 

System Software:

    macOS Sierra  10.12.6 (16G29) - Time since boot: about 4 days

 

Gatekeeper:

    Mac App Store and identified developers

 

Possible adware:

    Unknown file: /Library/LaunchAgents/com.filewave.fwVNCServer.plist.bak

    /usr/local/sbin/FileWave.app/Contents/Resources/Vine Server.app/Contents/MacOS/OSXvnc-server -rfbport 20031 -rfbauth /usr/local/etc/.fwVNCServerAuth -SystemServer 1 -alwaysshared -localhost -restartonuserswitch N -UnicodeKeyboard 0 -keyboardLoading N -pressModsForKeys N -EventTap 3 -EventSource 2 -swapButtons -rendezvous N

    Unknown file: /Library/LaunchAgents/se.hj.hjServiceAgent.plist

    /usr/local/sbin/hjService.app/Contents/Library/LaunchServices/hjServiceLaunchAg ent

    Unknown file: /Library/LaunchDaemons/se.hj.hjServiceDaemon.plist

    /usr/local/sbin/hjService.app/Contents/Library/LaunchServices/hjServiceLaunchDa emon

    3 possible adware files found. [Remove/Report]

 

Clean up:

    /Library/LaunchAgents/com.cisco.anyconnect.gui.plist

        open --wait-apps /Applications/Cisco/Cisco AnyConnect Secure Mobility Client.app

        Executable not found!

    One orphan file found. [Clean up]

 

Kernel Extensions:

        /Applications/VMware Fusion.app

    [not loaded]    com.vmware.kext.vmci (7.1.2) [Lookup]

    [not loaded]    com.vmware.kext.vmioplug.14.1.4 (7.1.2) [Lookup]

    [not loaded]    com.vmware.kext.vmnet (7.1.2) [Lookup]

    [not loaded]    com.vmware.kext.vmx86 (7.1.2) [Lookup]

    [not loaded]    com.vmware.kext.vsockets (7.1.2) [Lookup]

 

        /Library/Extensions

    [loaded]    at.obdev.nke.LittleSnitch (3.7.2 - SDK 10.11) [Lookup]

    [loaded]    com.asix.driver.ax88179-178a (1.8.0 - SDK 10.10) [Lookup]

 

System Launch Agents:

    [not loaded]    7 Apple tasks

    [loaded]    158 Apple tasks

    [running]    117 Apple tasks

 

System Launch Daemons:

    [not loaded]    41 Apple tasks

    [loaded]    157 Apple tasks

    [running]    119 Apple tasks

 

Launch Agents:

    [running]    at.obdev.LittleSnitchUIAgent.plist (Objective Development Software GmbH - installed 2017-01-31) [Lookup]

    [not loaded]    com.adobe.AAM.Updater-1.0.plist (Adobe Systems, Inc. - installed 2017-08-17) [Lookup]

    [failed]    com.adobe.ARMDCHelper.cc24aef4a1b90ed56a725c38014c95072f92651fb65e1bf9c8e43c37a2 3d420d.plist (Adobe Systems, Inc. - installed 2017-01-28) [Lookup]

    [loaded]    com.adobe.AdobeCreativeCloud.plist (Adobe Systems, Inc. - installed 2017-02-06) [Lookup]

    [loaded]    com.cisco.anyconnect.gui.plist (? 40bd3462 0 - installed 2017-05-17) [Lookup] - --wait-apps: Executable not found!

    [running]    com.filewave.fwGUI.plist (? 7922b00c 351c76d7 - installed 2017-08-14) [Lookup]

    [running]    com.filewave.fwVNCServer.plist (? 9009956c cd763aa9 - installed 2017-08-14) [Lookup]

    [running]    com.filewave.fwVNCServer.plist.bak (? 9009956c cd763aa9 - installed 2017-01-27) [Lookup]

    [loaded]    com.google.keystone.agent.plist (Google, Inc. - installed 2017-07-10) [Lookup]

    [failed]    com.oracle.java.Java-Updater.plist (? d53d235d 72ac4dde - installed 2017-08-14) [Lookup]

    [running]    se.hj.hjServiceAgent.plist (? 34d9784e 44f5fef1 - installed 2014-02-13) [Lookup]

 

Launch Daemons:

    [running]    at.obdev.littlesnitchd.plist (Objective Development Software GmbH - installed 2017-01-31) [Lookup]

    [running]    com.adobe.ARMDC.Communicator.plist (Adobe Systems, Inc. - installed 2017-01-28) [Lookup]

    [running]    com.adobe.ARMDC.SMJobBlessHelper.plist (Adobe Systems, Inc. - installed 2017-01-28) [Lookup]

    [running]    com.adobe.adobeupdatedaemon.plist (Adobe Systems, Inc. - installed 2017-08-17) [Lookup]

    [running]    com.adobe.agsservice.plist (Adobe Systems, Inc. - installed 2017-01-27) [Lookup]

    [loaded]    com.adobe.fpsaud.plist (? 2afb3af7 85012398 - installed 2017-07-25) [Lookup]

    [running]    com.cisco.anyconnect.vpnagentd.plist (? f363637f eadc1166 - installed 2017-05-17) [Lookup]

    [running]    com.filewave.fwcld.plist (? 47ff865f 708447ab - installed 2017-08-14) [Lookup]

    [loaded]    com.google.keystone.daemon.plist (Google, Inc. - installed 2017-08-08) [Lookup]

    [loaded]    com.microsoft.autoupdate.helper.plist (Microsoft Corporation - installed 2017-08-16) [Lookup]

    [loaded]    com.microsoft.office.licensingV2.helper.plist (Microsoft Corporation - installed 2015-09-11) [Lookup]

    [loaded]    com.oracle.java.Helper-Tool.plist (Shell Script e3fefdd2 - installed 2017-07-22) [Lookup]

    [loaded]    net.telestream.LicensingHelper.plist (Telestream LLC - installed 2017-03-09) [Lookup]

    [running]    se.hj.hjServiceDaemon.plist (? 64038c5e a1fdedac - installed 2014-02-13) [Lookup]

 

User Launch Agents:

    [loaded]    com.adobe.AAM.Updater-1.0.plist (Adobe Systems, Inc. - installed 2017-08-17) [Lookup]

    [loaded]    com.dropbox.DropboxMacUpdate.agent.plist (Dropbox, Inc. - installed 2017-08-14) [Lookup]

 

User Login Items:

    Citations    Application

        (/Applications/Papers.app/Contents/SharedSupport/Citations.app)

    iTunesHelper    Application (Apple, Inc. - installed 2017-08-06)

        (/Applications/iTunes.app/Contents/MacOS/iTunesHelper.app)

    Dropbox    Application

        (/Applications/Dropbox.app)

    SpeechSynthesisServer    Application

        (/System/Library/Frameworks/ApplicationServices.framework/Versions/A/Frameworks /SpeechSynthesis.framework/Versions/A/SpeechSynthesisServer.app)

    BetterSnapTool    Application

        (/Applications/BetterSnapTool.app)

    AdobeResourceSynchronizer    Application - Hidden

        (/Applications/Adobe Acrobat DC/Adobe Acrobat.app/Contents/Helpers/AdobeResourceSynchronizer.app)

    Paws for Trello    Application

        (/Applications/Paws for Trello.app)

    Skype for Business    Application

        (/Applications/Skype for Business.app)

 

Internet Plug-ins:

    AdobeExManDetect: AdobeExManDetect 1.1.0.0 (installed 2017-01-27) [Lookup]

    FlashPlayer-10.6: 26.0.0.151 (installed 2017-08-14) [Lookup]

    QuickTime Plugin: 7.7.3 (installed 2017-08-06)

    AdobePDFViewerNPAPI: 17.012.20095 (installed 2017-08-14) [Lookup]

    AdobePDFViewer: 17.012.20095 (installed 2017-08-14) [Lookup]

    AdobeAAMDetect: 3.0.0.0 (installed 2017-02-06) [Lookup]

    Flash Player: 26.0.0.151 (installed 2017-08-14) Cannot contact Adobe

    PepperFlashPlayer: 26.0.0.151 (installed 2017-08-14) [Lookup]

    MeetingJoinPlugin: 1.0 (installed 2017-08-14) [Lookup]

    JavaAppletPlugin: Java 8 Update 144 build 01 (installed 2017-08-14) Check version

 

Safari Extensions:

    [enabled]    1Password - AgileBits - https://agilebits.com/onepassword (installed 2017-06-13)

 

3rd Party Preference Panes:

    Flash Player (installed 2017-07-25) [Lookup]

    Java (installed 2017-08-14) [Lookup]

 

Time Machine:

    Time Machine not configured!

 

Top Processes by CPU:

        11%   WindowServer

         6%   launchd

         3%   com.apple.WebKit.WebContent

         2%   kernel_task

         2%   mdworker

 

Top Processes by Memory:

    1.63 GB   kernel_task

    1.32 GB   Keynote

    616 MB    Microsoft Outlook

    486 MB    softwareupdated

    420 MB    Safari

 

Top Processes by Network Use:

    Input     Output    Process name

    33 MB     26 MB     mDNSResponder

    13 MB     3 MB      Dropbox

    3 MB      245 KB    netbiosd

    2 MB      687 KB    biometrickitd

    358 KB    152 KB    CalendarAgent

 

Top Processes by Energy Use:

     12.68 WindowServer

      2.86 Little Snitch Agent

      2.66 com.apple.WebKit.WebContent

      1.42 Paws for Trello

 

Virtual Memory Information:

    3.52 GB   Available RAM

    207 MB    Free RAM

    12.48 GB  Used RAM

    3.31 GB   Cached files

    288 MB    Swap Used

 

Software installs:

    Things: 3.1.2 (installed 2017-08-06)

    OneDrive: 17.3.6945 (installed 2017-08-06)

    1Password: 6.8 (installed 2017-08-06)

    Paws for Trello: 2.2.3 (installed 2017-08-06)

    Adobe Flash Player:  (installed 2017-08-06)

    Adobe Pepper Flash Player:  (installed 2017-08-07)

    Adobe Pepper Flash Player:  (installed 2017-08-14)

    Adobe Flash Player:  (installed 2017-08-14)

    AdobeAIR-26.0.0.127:  (installed 2017-08-14)

    Microsoft AutoUpdate:  (installed 2017-08-14)

    Microsoft Excel for Mac:  (installed 2017-08-14)

    Microsoft Word for Mac:  (installed 2017-08-14)

    Microsoft OneNote for Mac:  (installed 2017-08-14)

    Microsoft PowerPoint for Mac:  (installed 2017-08-14)

    Microsoft Outlook for Mac:  (installed 2017-08-14)

    JDK 8 Update 144:  (installed 2017-08-14)

    Adobe Acrobat DC (17.012.20095):  (installed 2017-08-14)

    Skype for Business:  (installed 2017-08-14)

    Microsoft AutoUpdate:  (installed 2017-08-16)

    Microsoft OneNote for Mac:  (installed 2017-08-16)

    Microsoft Excel for Mac:  (installed 2017-08-16)

    Microsoft Outlook for Mac:  (installed 2017-08-16)

    Microsoft PowerPoint for Mac:  (installed 2017-08-16)

    Microsoft Word for Mac:  (installed 2017-08-16)

    Adobe_Animate_2017_170608:  (installed 2017-08-17)

 

    Install information may not be complete.

 

Diagnostics Information:

    2017-08-14 09:29:16    Last shutdown cause: -128 - Unknown

    2017-08-14 09:28:58    Kernel Panic [Open] [Details]

        3rd Party Kernel Extensions: None



You can click on

Click the [Remove/Report] links to remove adware or update the whitelist of legitimate software.

Click the [Clean up] link to delete unused files.

You can see lot of adware in the system , some third party apps are running try to remove them .

And , thanks to Bob Harris , to be frank I am not using any apps in my system and having less knowledge about them .



Really, would you like to point out where?



You are right to question any recommendations or advice you're given, here or elsewhere.

 

There isn't any adware indicated in that report. The problem with the tool you've been recommended is that it flags anything in an alarming red message that the author of the tool doesn't know about, including any files you create yourself and put in certain locations.

 

It looks like your mac is being administered with FileWave and kerebos is likely just connecting to the domain you noticed in a perfectly routine way. This has nothing to do with apple, but whoever administers your mac.

 

I don't see anything wrong here, or anything to be alarmed about, unless that's your personal mac and someone has installed FileWave on it without your knowledge or permission.



最后更新:2017-08-19 01:59:07

  上一篇:go unable to delete an adware
  下一篇:go Is it a Good Ideal to Turn On My FileVault