Parece que nadie ha participado en esta conversación desde hace mucho tiempo. Para empezar una conversación, haz una nueva pregunta.

Supervised and remote controlled? Files in Library creating and changing constantly

Hi,


It has been two years now since I start suspected my devices were somehow intervened. This is what is happening:

  • Files in /Library/ and ~/Library/ are always changing (every minute or so) even though I'm not using the computer
  • I have disabled bluetooth, airdrop, FaceTime and iMessage, but files with UUID and custom settings keeps appearing regarding those systems
  • For some days I couldn't disable bluetooth, the option was disabled in gray. There was no Profile on System > Profiles, and changes in bluetooth was allowed in Screen Time > Privacy & Content. I found a profile in /Library/Managed Preferences. I deleted and I could disabled bluetooth successfully.
  • The same for WiFi, during some days I couldn't enable it. It was blocked.
  • Every time I enter Preferences > General > Sharing :
    • Share screen is disabled (good) but allows Administrator users, even though I remove them
    • Remote session is disabled (good) but allows Administrator users, even though I remove them
    • Remote Apps session is disabled (good) but allows Administrator users, even though I remove them
  • Copy Link in Sharing Extensions keeps being activated even thou I disable every time
  • This is recent I have Screen Time enabled, but it says that my account is of a minor. I disabled it and reactivate it, and the same, it keeps telling that.
  • The settings I put on Screen Time does not work. Apps I never allowed are allowed always. It just don't work anymore.
  • I cannot log out from my Apple ID Account. The message: "A restriction setting doesn't not allow to log out"
  • I have NetBios always active on my Wifi Settings, I don't know why



These are some files changing in ~/Library/:



Files on ~/Library/Preferences/ are always changing, creating new ones or updating existing ones every minute or so

Names of those files may include:

      • com.apple.ManagedClient.plist
      • com.apple.SpeakSelection.plist
      • com.apple.imessage.plist ( I have disabled iMessages and my session is logged out)
      • com.apple.TelephonyUtilities.sharePlayAppPolicies.plist
      • com.apple.imservice.ids.FaceTime.plist ( I have disabled FaceTime and my session is logged out)
      • com.apple.imservice.ids.iMessage.plist
      • com.apple.imservice.SMS.plist
      • com.apple.ipTelephony.plist
      • com.apple.xpc.activity2.plist
      • com.apple.Bluetooth.plist (I have disabled bluetooth, but it keeps coming)
      • com.apple.commcenter.csidata.plist
      • com.apple.iChat.plist
      • com.apple.sms.plist
      • sharedfilelistd.plist
      • com.apple.CommCenter.counts.plist
      • com.apple.accountsd.plist
      • com.apple.ids.subservices.plist
      • com.apple.commcenter.plist
      • com.apple.icloud.fmfd.notbackedup.plist
      • com.apple.commcenter.data.plist
      • and many others (see additional file)


These are some files changing in /Library/Preferences:


    • System Configuration/com.apple.accounts.exists.plist
    • System Configuration/com.apple.smb.server.plist
    • System Configuration/preferences.plist
    • System Configuration/com.apple.airport.preferences.plist
    • com.apple.networkextension.uuidcache.plist
    • com.apple.networkd.plist
    • com.apple.networkd.networknomicon.plist
    • com.apple.networkd.sysctl.plist
    • com.apple.RemoteDesktop.plist
    • com.apple.driver.AppleIRController.plist
    • com.apple.RemoteManagement.plist
    • com.apple.BezelServices.plist
      • Managed Preferences/


All of them changes Modification Time from time to time even though I'm not using the computer.


Is it a malware, do I have a backdoor, or it is just normal behavior of any Mac?



Continue on additional file:







iPhone 11, iOS 17

Publicado el 16/03/2024 04:25 a. m.

Responder
2 respuestas

16/03/2024 06:49 a. m. en respuesta a ozzie1910

I don’t know… That doesn’t happen with the Mac computer I use at work. It has few files in Library and do not change every minute like in my personal computer.


And Apple devices can be hacked. Pegasus is one example: https://amp.theguardian.com/news/2021/jul/18/what-is-pegasus-spyware-and-how-does-it-hack-phones


Predator is another:

https://www.sekoia.io/en/glossary/predator-spyware/


in 2022 there were found vulnerabilities in kernel and webkit that allowed hackers gain remote control of iphones

https://www.theguardian.com/technology/2022/aug/18/apple-security-flaw-hack-iphone-ipad-macs


All Security Responses that are automatically installed every now and then on apple devices are responses after zero day vulnerabilities found. Some of them actively exploited




Supervised and remote controlled? Files in Library creating and changing constantly

Bienvenido a la Comunidad de soporte de Apple
Un foro donde los clientes de Apple se ayudan entre sí con sus productos. Comienza con tu cuenta de Apple.