Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

imac: File privileges for ‘staff’ and ‘everyone’ were changed to ‘read and write’ instead of default ‘read only’ I did not initiate this change.

The only security vulnerability I can think of was when I was installing an antivirus (mcafee) it redirected to a malicious website, I will not share the link but it is a Thai website (it is written in Thai characters) parodying the official Mcafee activate page.


I was able to activate the product via assistance through the mcafee tech support phone number provided on the physical product box and installed mcafee through the real mcafee website by manually typing the correct url and disabling siri suggestions, and url auto fill in addition to clearing safari history.


I have too many files to keep track so I cannot tell if any changes occured however recently I discovered file privileges were changed from ‘read only’ to ‘read and write’ for all users, could this be a glitch or evidence of hacker activity?


My imac only connects to the internet when I need to update applications perhaps 10-20 minutes every week or so. Wifi is usually disabled and computer is unpowered when not in use.


’Last’ command in terminal does not show evidence of suspicious user logins, there are several bizarre files including strange plist files under the folder ‘sharing’ in my user library but otherwise there is nothing remarkable. There are no unusual files in launchagents. Furthermore I will be doing a screen share with apple soon to ascertain if these files are legitimate.


Any idea why these privileges would be altered? I did not perform these changes so I was hoping for some insight regarding this. Fear mongering is not appreciated. I hope it has something to do with Mcafee. I will provide the potentially malicious link if requested for reference.


There was no evidence of malicious downloads from the link however I am concerned about arbitrary code execution.


To emphasize my mac is almost never connected to wifi, and never while I am working. There is no excessive heat or loud fans/ sluggish performance.


I appreciate your help. I do not appreciate Fear Mongering.

iMac 27″, macOS 12.4

Posted on Jul 9, 2022 12:43 AM

Reply
Question marked as Best reply

Posted on Jul 11, 2022 2:21 PM

I have determined the cause of this issue. If anyone is interested, the issue is due to flash drive file transfer. Files transferred to the computer via usb have read and write granted to everyone.


Therefore at least there is no evidence that this specific incident was caused by malware.

Similar questions

10 replies
Question marked as Best reply

Jul 11, 2022 2:21 PM in response to w0t3n

I have determined the cause of this issue. If anyone is interested, the issue is due to flash drive file transfer. Files transferred to the computer via usb have read and write granted to everyone.


Therefore at least there is no evidence that this specific incident was caused by malware.

Jul 11, 2022 11:02 AM in response to w0t3n

Personally if it was my system, I would make sure to manually transfer my data to an external drive. Then I would perform a clean install of macOS by erasing the hidden Container. Then I would either restore from a backup made before the incident occurred, or I would manually transfer my files back and manually download & install my third party apps. This is the only way to be sure your system is clean & stable and it will probably take less time than trying to figure out if something is wrong and how to fix it.


Definitely agree that a Mac does not require any anti-virus apps, cleaning apps, or third party security software since they usually cause more problems than they solve since they interfere with the normal operation of macOS. macOS already provides great built-in protection when also paired with following safe computing habits as outlined in this article written by a well respected forum contributor:

Effective defenses against malware and other threats - Apple Community


Jul 10, 2022 11:25 AM in response to w0t3n

w0t3n wrote:

I discovered file privileges were changed from ‘read only’ to ‘read and write’ for all users,


If true, this is not normal and warrants further research; however there is not enough information in your post to figure out how or why it occurred. You imply that it affects all files for all users. Are you certain it's *ALL* files and not just a certain folder or group of files? Have you checked multiple folders and their contents?


That said, your experience of being redirected to a malicious website when installing McAfee is very suspicious. Are you certain you had a legitimate copy of McAfee in the first place? And was the copy you actually installed with help from McAfee phone support from the same disk or download you used the first time when it got redirected? Are you certain the phone number on the physical box was an actual McAfee tech support line?


Despite your experience and your obvious interest in protecting your Mac, most advanced users in these forums would advise against installing any virus app, including McAfee, as unnecessary and potentially problematic in their own right.



Jul 13, 2022 3:31 PM in response to w0t3n

Well, you said: "when I was installing an antivirus (mcafee) it redirected to a malicious website," so the redirect certainly appears to have happened while you were installing McAfee antivirus and we could only conclude that it did have something to do with your antivirus software installation.


No legitimate software would redirect itself to a malicious website; and if it did, perhaps you have browser redirect malware. It would be advisable to check ... Malwarebytes is one product you could use to check; the trial version is fully functional for 14 days.

Jul 16, 2022 12:38 AM in response to MartinR

the offensive url was mymcafeeactivate.com it redirects there when attempting to type url mcafee.com/activate.


This Mac never received emails or went online (besides installing OS updates)


mymcafeeactivate.com is clean according to google browsing guide. However it is not Mcafee. I was able to access the correct mcafee website by disabling autofill url.


If you search mymcafeeactivate.com on google you can safely see what the parody site is about. It is hosted on godaddy.com and the mailing address is in arizona. Its domain is currently worth $100.

imac: File privileges for ‘staff’ and ‘everyone’ were changed to ‘read and write’ instead of default ‘read only’ I did not initiate this change.

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.