[Infowarrior] - more on ... Re: You can log into macOS High Sierra as root with no password

Richard Forno rforno at infowarrior.org
Wed Nov 29 12:21:36 CST 2017


A fix is out from Apple this morning.


> On Nov 28, 2017, at 4:02 PM, Richard Forno <rforno at infowarrior.org> wrote:
> 
> 
> You can log into macOS High Sierra as root with no password
> By Shaun Nichols in San Francisco 28 Nov 2017 at 20:15
> 
> A trivial-to-exploit flaw in macOS High Sierra, aka macOS 10.13, allows users to gain admin rights, or log in as root, without a password.
> 
> The security bug is triggered via the authentication dialog box in Apple's operating system, which prompts you for an administrator's username and password when you need to do stuff like configure privacy and network settings.
> 
> If you type in "root" as the username, leave the password box blank, hit "enter" and then click on unlock a few times, the prompt disappears and, congrats, you now have admin rights. You can do this from the user login screen.
> 
> The vulnerability effectively allows someone with physical access to the machine to cause extra mischief, install malware, and so on. While obviously not the end of the world – certainly far from a remote hole or a disk decryption technique – it's just really, really sad to see megabucks Apple drop the ball like this.
> 
> Developer Lemi Orhan Ergan alerted the world to the flaw via Twitter ion the past hour or so:
> 
> < - >
> 
> http://www.theregister.co.uk/2017/11/28/root_access_bypass_macos_high_sierra/



More information about the Infowarrior mailing list