You can make a difference in the Apple Support Community!

When you sign up with your Apple Account, you can provide valuable feedback to other community members by upvoting helpful replies and User Tips.

Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

Mac was hacked on local network by roommate-how to re-install my files w/o reistalling command/terminal hack codes?

I have a Mac Book Pro running latest version on Mountian Lion
Processor 2.3 GHz Intel Core i7

Graphics Intel HD Graphics 4000 512 MB

Memory 8 GB 1600 MHz DDR3

Software OS X 10.8.3 (12D78)


My roommate hacked my Mac. I assume he did this via an old Mac he use to have access to, & then made changes via his PC & his Android phone (can tell by comparing Terminal to Access & Little Snitch) & since the codes I found all were as my User name & as Root Access... Thinking he started gaining access through the weak spot via Reboot Disk & Terminal access from there-though he denys it completely... (But I printed it all out) He accessed ALL my passwords & at the time I didn't know that as I kept trying to change things & lock things up... he was getting hidden files of EVERYTHING I WAS DOING & had remote access to my system, anything I did & camera on my mac.

He hid files with sudo codes in Terminal & had constant any access via remote access, booting, starting or turning off as well as secretly deleting any files or notactions he wanted. He was ghost.

So now not only did he has complete access to my computer & camera... He would enter my room & take what he wants & then access my computer to delete EvoCam files/videos/pics.

He also has been tracking everything I do on my computer and assume he has figured out how to hack my phone by now as well.

He will be an EX-ROOMMATE as soon as I can legally get him out. But until then I am stuck. (Buying locks for all 3 of my bedroom & closet room access doors too!)

I currently have him blocked off the local network & internet. But that won't last long.

I jcopied over to my external hard drive all my important info, pics, files and just deleted the rest.
It took many hours to get my mac to actually delete everything (I HOPE) & then finally let me re-load Mountain Lion. Now I am slowly adding back programs. I think he was also using the Windows interface & some Windows program to sneak past my firewall & all the stops I put up to block him off local.net.

Changed ALL my passwords again-already. Hopefully by zeroing out my hard drive numerous times that it deleted his lines of codes.

Tested in Terminal some of the lines of codes he used (Just lsof & ls -a, history, etc)


SOOO MY QUESTIONS ARE:

Is there a way to let him use the network without him being able to access my Mac??

I have ALL ways I can find to turn off any file sharing, local or remote access... but I did that last time & he figured out a way around it!

My Nework is on a NETGEAR Range Max N wireless router. I configured it this time via Ethernet instead of by Wireless-made my Mac only machine to make changes & only via Ethernet access. (Gave Ethernet & Wireless each their own IP address.)

I also turned off the remote access again, locked in IP addresses to specific machines/phones/Pads... IE 192.168.1.2... on Router.

I also installed Little Snitch, Have Tech Tools 6... Need a good virus protection... (did find some crap only in a couple of my emails when I used one I downloaded as a trial before the re-format... )

Worried about installing Windows again.

How do I block him from getting root access again?

How do I keep him from hidding any codes?

Thank you in advance for your help & suggestions! 🙂

MacBook Pro (Retina, Mid 2012), OS X Mountain Lion (10.8.3), Netgear router

Posted on Apr 23, 2013 4:52 AM

Reply
19 replies

Apr 23, 2013 10:48 AM in response to steve359

steve359 wrote:


Your roommate has demonstrated a complete disregard for your privacy, and may have stolen information such as credit card data and social security number. Check your credit reports at all 3 agencies, then freeze it (frozen means you need to unlock it to open more credit yourself).


Then get money from parents if the housing authority does not act within the week. Too much risk to your personal belongings in my opinion.


Remember, we're hearing only one side of the story. Frankly, I'm becoming suspicious of the original poster's story and his supposed inability to do anything about it. Can't bring the police in because the alleged perp has connections? Doesn't have any evidence he can use? It no longer smellls right to me.

Mac was hacked on local network by roommate-how to re-install my files w/o reistalling command/terminal hack codes?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.