Hacking - help reading Console
My My apologies for the super newbie post, but I need some help, and if any of you understand the console and can help me out here, it'd be so much appreciated!
I let my boyfriend use my guest account on my macbook while I was away. I found some funny things in Console.. to the untrained eye, it looks like hacking. Of course, I might just be a silly suspicious girlfriend..
But I have no idea if he could be trying to get my password for some reason.
Can anyone tell me, by what is in Console, if he is trying to hack my password?
I'll select in bold the commands that worry me the most..
Thank you so much!
5/15/14 8:00:44.000 PM kernel: MacAuthEvent en1 Auth result for: 00:22:3f:37:7f:3c MAC AUTH succeeded
5/15/14 8:00:44.000 PM kernel: wlEvent: en1 en1 Link UP virtIf = 0
5/15/14 8:00:44.000 PM kernel: AirPort: Link Up on en1
5/15/14 8:00:44.000 PM kernel: en1: BSSID changed to 00:22:3f:37:7f:3c
5/15/14 8:00:44.352 PM com.apple.SecurityServer: Session 100023 created
5/15/14 8:00:44.413 PM configd: network configuration changed.
5/15/14 8:00:44.416 PM [0x0-0x13013].com.spotify.client: 00:00:44.415 I [ap_connection_impl.cpp:911 ] Connecting to AP ap.gslb.spotify.com:4070
5/15/14 8:00:44.440 PM loginwindow: Login Window Started Security Agent
5/15/14 8:00:44.446 PM UserEventAgent: CaptiveNetworkSupport:CaptivePublishState:1211 en1 - Probe
5/15/14 8:00:44.447 PM UserEventAgent: CaptiveNetworkSupport:CaptiveStartDetect:2322 Bypassing probe on NETGEAR because signature is in the known good cache
5/15/14 8:00:44.447 PM UserEventAgent: CaptiveNetworkSupport:CaptivePublishState:1211 en1 - Unknown
5/15/14 8:00:44.449 PM configd: network configuration changed.
5/15/14 8:00:45.705 PM [0x0-0x13013].com.spotify.client: 00:00:45.704 I [ap_connection_impl.cpp:551 ] Connected to AP: 193.182.8.30:4070
5/15/14 8:00:47.072 PM SecurityAgent: Echo enabled
5/15/14 8:00:47.072 PM SecurityAgent: Echo enabled
5/15/14 8:00:47.110 PM airportd: _doAutoJoin: Already associated to “NETGEAR”. Bailing on auto-join.
5/15/14 8:00:47.187 PM SecurityAgent: User info context values set for Guest
5/15/14 8:00:47.187 PM SecurityAgent: User info context values set for Guest
5/15/14 8:00:48.000 PM kernel: utun_ctl_connect: creating interface utun0
5/15/14 8:00:48.000 PM kernel: utun0: attached with 0 suspended link-layer multicast membership(s)
5/15/14 8:00:48.253 PM [0x0-0x13013].com.spotify.client: 00:00:48.252 I [autoupdate.cpp:462 ] AutoUpdate [448 90800296 0]
5/15/14 8:00:48.253 PM [0x0-0x13013].com.spotify.client: 00:00:48.253 I [autoupdate.cpp:547 ] AutoUpdate initializing [FULL 2227c6de69cf3873cedd01f37fd4d10957380508 91000014 0 0x0]
5/15/14 8:00:48.253 PM [0x0-0x13013].com.spotify.client: 00:00:48.253 I [autoupdate.cpp:441 ] AutoUpdate waiting 0 seconds
5/15/14 8:00:48.389 PM UserEventAgent: CaptiveNetworkSupport:CaptivePublishState:1211 en1 - PreProbe
5/15/14 8:00:48.393 PM configd: network configuration changed.
5/15/14 8:00:48.486 PM [0x0-0x13013].com.spotify.client: 00:00:48.485 I [ad_chooser.cpp:1150 ] Found ad (time = 1400198447, adclass = 'tower', time left = 120, length = 30)
5/15/14 8:00:48.487 PM [0x0-0x13013].com.spotify.client: 00:00:48.486 I [ad_chooser.cpp:1150 ] Found ad (time = 1400198447, adclass = 'tower', time left = 120, length = 30)
5/15/14 8:00:48.784 PM [0x0-0x13013].com.spotify.client: 00:00:48.784 I [autoupdate.cpp:561 ] AutoUpdate starting download
5/15/14 8:00:48.794 PM [0x0-0x13013].com.spotify.client: 00:00:48.793 3 [playlist_be_pl4_context.cpp:400 ] [spotify:user:129770633:playlist:3BSNNw4Sj2eocFZqdwm3Ke] Synchronization starting: DIFF (from revision 15,09f2f61a71877cfcfe8fed9916b09d88732ea3f9)
5/15/14 8:00:48.794 PM [0x0-0x13013].com.spotify.client: 00:00:48.793 3 [playlist_be_pl4_context.cpp:400 ] [spotify:user:m83spotify:playlist:4W2m1FwDU3vLsjd6sYfHaY] Synchronization starting: HEAD (from revision 0,726f6f7400000000000000000000000000000000)
5/15/14 8:00:48.794 PM [0x0-0x13013].com.spotify.client: 00:00:48.793 3 [playlist_be_pl4_context.cpp:400 ] [spotify:user:imaginedragonsofficial:playlist:2hyXzZLirttmHDNsABWTBL] Synchronization starting: DIFF (from revision 26,ed7b3d640ab8e4a67b3735d914f11217bf5fc57f)
5/15/14 8:00:48.794 PM [0x0-0x13013].com.spotify.client: 00:00:48.793 3 [playlist_be_pl4_context.cpp:400 ] [spotify:user:123805322:playlist:7GKy27iOiMxcvF3lK1HA0q] Synchronization starting: DIFF (from revision 13,239af14531e2e2f70ce7f668c2758bd873017da7)
5/15/14 8:00:48.794 PM [0x0-0x13013].com.spotify.client: 00:00:48.793 3 [playlist_be_pl4_context.cpp:400 ] [spotify:user:rhino_records:playlist:7aw20b4F3dYJ0XN2TZQMJX] Synchronization starting: DIFF (from revision 6,ea624438a57ab43853ca1f221cf7d440d491bd36)
5/15/14 8:00:48.800 PM [0x0-0x13013].com.spotify.client: 00:00:48.799 I [ad_chooser.cpp:1150 ] Found ad (time = 1400198447, adclass = 'tower', time left = 120, length = 30)
5/15/14 8:00:50.465 PM awacsd: RouteDiscovery: sendmsg error (6): Device not configured
5/15/14 8:00:54.535 PM configd: network configuration changed.
5/15/14 8:00:54.547 PM [0x0-0x13013].com.spotify.client: 00:00:54.546 I [ap_handler_impl.cpp:2141 ] Forced disconnect from AP
5/15/14 8:00:54.798 PM [0x0-0x13013].com.spotify.client: 00:00:54.798 I [ap_connection_impl.cpp:911 ] Connecting to AP ap.gslb.spotify.com:80
5/15/14 8:00:55.152 PM UserEventAgent: CaptiveNetworkSupport:CaptivePublishState:1211 en1 - Probe
5/15/14 8:00:55.153 PM UserEventAgent: CaptiveNetworkSupport:CaptiveStartDetect:2322 Bypassing probe on NETGEAR because signature is in the known good cache
5/15/14 8:00:55.153 PM UserEventAgent: CaptiveNetworkSupport:CaptivePublishState:1211 en1 - Unknown
5/15/14 8:00:55.154 PM configd: network configuration changed.
5/15/14 8:00:55.466 PM awacsd: RouteDiscovery: sendmsg error (6): Device not configured
5/15/14 8:00:56.749 PM [0x0-0x13013].com.spotify.client: 00:00:56.748 I [ap_connection_impl.cpp:551 ] Connected to AP: 193.182.8.35:80
5/15/14 8:00:58.389 PM [0x0-0x13013].com.spotify.client: 00:00:58.388 I [autoupdate.cpp:462 ] A
5/15/14 8:01:20.990 PM com.apple.authorizationhost.00000000-0000-0000-0000-0000000186B7: creating home directories for (Loreleis-MacBook-Pro.local)
5/15/14 8:01:20.990 PM com.apple.authorizationhost.00000000-0000-0000-0000-0000000186B7: created (/Users/Guest)
5/15/14 8:01:23.690 PM sandboxd: ([54]) applepushservice(54) deny file-read-data /private/etc/master.passwd
5/15/14 8:01:26.163 PM xpchelper: for uid: 501 -- timeout while waiting on FSEvents flush; clearing cache.
5/15/14 8:01:31.798 PM mcxalr_agent: Listener client (pid: 5157) entering listen mode for uid: 201
5/15/14 8:01:31.976 PM loginwindow: Login Window - Returned from Security Agent
5/15/14 8:01:32.000 PM kernel: mcxalr{0} 64-bit Build date: Jun 30 2013 18:58:34
5/15/14 8:01:32.000 PM kernel: mcxalr{1} Started
5/15/14 8:01:32.000 PM kernel: mcxalr{2} Management ENABLED for uid: 201
5/15/14 8:01:32.000 PM kernel: calling mpo_policy_init for mcxalr
5/15/14 8:01:32.000 PM kernel: Security policy loaded: MCX App Launch (mcxalr)
5/15/14 8:01:32.000 PM kernel: mcxalr{3} Auth provider registered. connection: 1 uid: 201 version: 1
5/15/14 8:01:32.609 PM loginwindow: USER_PROCESS: 5083 console
5/15/14 8:01:33.173 PM airportd: _doAutoJoin: Already associated to “NETGEAR”. Bailing on auto-join.
5/15/14 8:01:37.067 PM UserEventAgent: CaptiveNetworkSupport:CNSServerRegisterUserAgent:187 new user agent port: 18839
5/15/14 8:01:55.000 PM kernel: CODE SIGNING: cs_invalid_page(0x10ed2a000): p=5159[parentalcontrols] clearing CS_VALID
5/15/14 8:01:58.000 PM kernel: mcxalr{4} ** Denying execute for uid=201 path=/Applications/Utilities/Adobe Application Manager/UWA/UpdaterStartupUtility
5/15/14 8:01:58.000 PM kernel: mcxalr{5} ** Denying execute for uid=201 path=/Library/Google/GoogleSoftwareUpdate/GoogleSoftwareUpdate.bundle/Contents/ Resources/GoogleSoftwareUpdateAgent.app/Contents/MacOS/GoogleSoftwareUpdateAgent
5/15/14 8:01:58.000 PM kernel: mcxalr{6} ** Denying execute for uid=201 path=/Applications/App Store.app/Contents/Resources/appstoreupdateagent
5/15/14 8:02:06.068 PM com.apple.dock.extra: 2014-05-15 20:02:06.064 com.apple.dock.extra[5213:1a07] Could not connect the action buttonPressed: to target of class NSApplication
5/15/14 8:02:06.068 PM com.apple.dock.extra: 2014-05-15 20:02:06.068 com.apple.dock.extra[5213:1a07] Could not connect the action buttonPressed: to target of class NSApplication
5/15/14 8:02:06.069 PM com.apple.dock.extra: 2014-05-15 20:02:06.068 com.apple.dock.extra[5213:1a07] Could not connect the action buttonPressed: to target of class NSApplication
5/15/14 8:02:06.070 PM com.apple.dock.extra: 2014-05-15 20:02:06.068 com.apple.dock.extra[5213:1a07] Could not connect the action buttonPressed: to target of class NSApplication
5/15/14 8:02:14.586 PM [0x0-0x13013].com.spotify.client: 00:02:14.585 E [watchdog.cpp:194 ] High-latency (gui, 1573)
5/15/14 8:02:16.760 PM [0x0-0x13013].com.spotify.client: [0515/200216:ERROR:connection.cc(799)] sqlite error 1802, errno 0: disk I/O error
5/15/14 8:02:16.760 PM [0x0-0x13013].com.spotify.client: [0515/200216:ERROR:connection.cc(799)] sqlite error 1, errno 0: SQL logic error or missing database
5/15/14 8:02:45.124 PM PubSubAgent: SQL Error: SQLITE_CANTOPEN[14.0]: Database file not found
5/15/14 8:03:16.981 PM [0x0-0x13013].com.spotify.client: 00:03:16.980 E [watchdog.cpp:194 ] High-latency (gui, 3969)
5/15/14 8:03:18.673 PM sandboxd: ([5235]) webfilterproxyd(5235) deny job-creation
5/15/14 8:03:56.262 PM com.apple.SecurityServer: Killing auth hosts
5/15/14 8:03:56.262 PM com.apple.SecurityServer: Session 100019 destroyed
5/15/14 8:04:25.000 PM kernel: (default pager): [KERNEL]: ps_select_segment - send HI_WAT_ALERT
5/15/14 8:04:33.000 PM kernel: macx_swapon SUCCESS
5/15/14 8:04:47.797 PM sandboxd: ([5245]) PluginProcess(5245) deny file-read-xattr /Users/Guest/Library/Preferences
5/15/14 8:04:48.000 PM kernel: IOSurface: buffer allocation size is zero
5/15/14 8:05:37.970 PM [0x0-0x13013].com.spotify.client: [0515/200537:ERROR:connection.cc(799)] sqlite error 1802, errno 0: disk I/O error
5/15/14 8:05:37.970 PM [0x0-0x13013].com.spotify.client: [0515/200537:ERROR:connection.cc(799)] sqlite error 1, errno 0: SQL logic error or missing database
5/15/14 8:06:45.000 PM kernel: AppleUSBMultitouchDriver::validateChecksum - 512-byte packet checksum is incorrect (expected 0x8ed, checksum bytes were 0x0)
5/15/14 8:07:45.000 PM kernel: IOSurface: buffer allocation size is zero
5/15/14 8:08:09.776 PM com.apple.SecurityServer: Session 100025 created
5/15/14 8:09:06.168 PM [0x0-0x13013].com.spotify.client: [0515/200906:ERROR:connection.cc(799)] sqlite error 1802, errno 0: disk I/O error
5/15/14 8:09:06.168 PM [0x0-0x13013].com.spotify.client: [0515/200906:ERROR:connection.cc(799)] sqlite error 1, errno 0: SQL logic error or missing database
5/15/14 8:09:36.099 PM SoftwareUpdateCheck: SoftwareUpdateCheck (Launch): user 501 not on-console
5/15/14 8:09:36.100 PM com.apple.launchd.peruser.501: (com.apple.softwareupdateagent) Throttling respawn: Will start in 1497 seconds
5/15/14 8:18:37.000 PM kernel: CODE SIGNING: cs_invalid_page(0x1000): p=5274[GoogleSoftwareUp] clearing CS_VALID
5/15/14 8:21:13.888 PM [0x0-0x13013].com.spotify.client: 00:21:13.888 E [watchdog.cpp:194 ] High-latency (gui, 2905)
5/15/14 8:32:36.860 PM mDNSResponder: ERROR: socket closed prematurely tcpInfo->nread = 0
5/15/14 8:32:36.860 PM mDNSResponder: tcpCallback: stream connection for _printer._tcp.97558637.members.btmm.icloud.com. (PTR) failed, retrying in 900000 ms
5/15/14 8:39:33.181 PM SoftwareUpdateCheck: SoftwareUpdateCheck (Launch): user 501 not on-console
5/15/14 8:39:33.182 PM com.apple.launchd.peruser.501: (com.apple.softwareupdateagent) Throttling respawn: Will start in 1500 seconds
5/15/14 9:00:18.000 PM kernel: mcxalr{7} ** Denying execute for uid=201 path=/Library/Google/GoogleSoftwareUpdate/GoogleSoftwareUpdate.bundle/Contents/ Resources/GoogleSoftwareUpdateAgent.app/Contents/MacOS/GoogleSoftwareUpdateAgent
5/15/14 9:05:19.035 PM PluginProcess: kCGErrorIllegalArgument: _CGSFindSharedWindow: WID 2688
5/15/14 9:05:19.035 PM PluginProcess: kCGErrorFailure: Set a breakpoint @ CGErrorBreakpoint() to catch errors as they are logged.
5/15/14 9:05:19.035 PM PluginProcess: kCGErrorIllegalArgument: CGSRemoveSurface: Invalid window 0xa80
5/15/14 9:09:33.908 PM SoftwareUpdateCheck: SoftwareUpdateCheck (Launch): user 501 not on-console
5/15/14 9:09:33.909 PM com.apple.launchd.peruser.501: (com.apple.softwareupdateagent) Throttling respawn: Will start in 1500 seconds
5/15/14 9:17:20.000 PM kernel: CODE SIGNING: cs_invalid_page(0x1000): p=5300[GoogleSoftwareUp] clearing CS_VALID
5/15/14 9:29:12.000 PM kernel: (default pager): [KERNEL]: ps_select_segment - send HI_WAT_ALERT
5/15/14 9:29:13.000 PM kernel: macx_swapon SUCCESS
5/15/14 9:39:34.146 PM SoftwareUpdateCheck: SoftwareUpdateCheck (Launch): user 501 not on-console
5/15/14 9:39:34.147 PM com.apple.launchd.peruser.501: (com.apple.softwareupdateagent) Throttling respawn: Will start in 1500 seconds
5/15/14 9:59:01.000 PM kernel: mcxalr{8} ** Denying execute for uid=201 path=/Library/Google/GoogleSoftwareUpdate/GoogleSoftwareUpdate.bundle/Contents/ Resources/GoogleSoftwareUpdateAgent.app/Contents/MacOS/GoogleSoftwareUpdateAgent
5/15/14 10:09:34.463 PM SoftwareUpdateCheck: SoftwareUpdateCheck (Launch): user 501 not on-console
5/15/14 10:09:34.464 PM com.apple.launchd.peruser.501: (com.apple.softwareupdateagent) Throttling respawn: Will start in 1500 seconds
5/15/14 10:16:03.000 PM kernel: CODE SIGNING: cs_invalid_page(0x1000): p=5316[GoogleSoftwareUp] clearing CS_VALID
5/15/14 10:19:10.289 PM PluginProcess: kCGErrorIllegalArgument: _CGSFindSharedWindow: WID 2704
5/15/14 10:19:10.289 PM PluginProcess: kCGErrorIllegalArgument: CGSRemoveSurface: Invalid window 0xa90
5/15/14 10:21:13.346 PM mDNSResponder: ERROR: socket closed prematurely tcpInfo->nread = 0
5/15/14 10:39:34.800 PM SoftwareUpdateCheck: SoftwareUpdateCheck (Launch): user 501 not on-console
5/15/14 10:39:34.801 PM com.apple.launchd.peruser.501: (com.apple.softwareupdateagent) Throttling respawn: Will start in 1500 seconds
5/15/14 10:50:48.560 PM com.apple.launchd.peruser.501: (com.facebook.videochat.Leathur.updater[5323]) Tried to setup shared memory more than once
5/15/14 10:54:16.140 PM mDNSResponder: ERROR: socket closed prematurely tcpInfo->nread = 0
5/15/14 10:54:16.140 PM mDNSResponder: tcpCallback: stream connection for _printer._tcp.97558637.members.btmm.icloud.com. (PTR) failed, retrying in 900000 ms
5/15/14 10:57:44.000 PM kernel: mcxalr{9} ** Denying execute for uid=201 path=/Library/Google/GoogleSoftwareUpdate/GoogleSoftwareUpdate.bundle/Contents/ Resources/GoogleSoftwareUpdateAgent.app/Contents/MacOS/GoogleSoftwareUpdateAgent
5/15/14 11:08:42.580 PM mDNSResponder: ERROR: socket closed prematurely tcpInfo->nread = 0
5/15/14 11:08:42.580 PM mDNSResponder: tcpCallback: stream connection for _pdl-datastream._tcp.97558637.members.btmm.icloud.com. (PTR) failed, retrying in 900000 ms
5/15/14 11:09:21.199 PM sandboxd: ([5235]) webfilterproxyd(5235) deny network-inbound 192.168.1.11:50687
5/15/14 11:09:35.132 PM SoftwareUpdateCheck: SoftwareUpdateCheck (Launch): user 501 not on-console
5/15/14 11:09:35.133 PM com.apple.launchd.peruser.501: (com.apple.softwareupdateagent) Throttling respawn: Will start in 1500 seconds
5/15/14 11:09:35.967 PM mDNSResponder: ERROR: socket closed prematurely tcpInfo->nread = 0
5/15/14 11:09:35.967 PM mDNSResponder: tcpCallback: stream connection for _smb._tcp.97558637.members.btmm.icloud.com. (PTR) failed, retrying in 900000 ms
5/15/14 11:14:47.000 PM kernel: CODE SIGNING: cs_invalid_page(0x1000): p=5335[GoogleSoftwareUp] clearing CS_VALID
5/15/14 11:18:50.647 PM sandboxd: ([5235]) webfilterproxyd(5235) deny network-inbound192.168.1.11:50701
5/15/14 11:19:37.160 PM PluginProcess: kCGErrorIllegalArgument: _CGSFindSharedWindow: WID 2716
5/15/14 11:19:37.161 PM PluginProcess: kCGErrorIllegalArgument: CGSRemoveSurface: Invalid window 0xa9c
5/15/14 11:21:04.574 PM PluginProcess: kCGErrorIllegalArgument: _CGSFindSharedWindow: WID 2681
5/15/14 11:21:04.574 PM PluginProcess: kCGErrorIllegalArgument: CGSRemoveSurface: Invalid window 0xa79
5/15/14 11:21:05.298 PM loginwindow: sendQuitEventToApp (EEventManager): AESendMessage returned error -1712
5/15/14 11:21:05.777 PM PluginProcess: kCGErrorIllegalArgument: _CGSFindSharedWindow: WID 2696
5/15/14 11:21:05.777 PM PluginProcess: kCGErrorIllegalArgument: CGSRemoveSurface: Invalid window 0xa88
5/15/14 11:21:07.791 PM loginwindow: Application hardKill returned -600
5/15/14 11:21:08.315 PM mcxalr_agent: Disconnect request received. Reason: unmanage
5/15/14 11:21:08.339 PM loginwindow: DEAD_PROCESS: 5083 console
5/15/14 11:21:08.530 PM loginwindow: Application hardKill returned -600
5/15/14 11:21:09.000 PM kernel: mcxalr{10} Management DISABLED for uid: 201
5/15/14 11:21:11.826 PM WindowServer: _CGXPostKillRequest(): Not implemented; nothing should be calling this anymore.
5/15/14 11:21:12.609 PM UserEventAgent: CaptiveNetworkSupport:UserAgentDied:139 User Agent @port=18839 Died