ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    macOS High Sierra login flaw - root

    IT Discussion
    security apple macos macos 10.13
    12
    33
    3.7k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • KellyK
      Kelly @bbigford
      last edited by

      @bbigford said in Apple login flaw - root:

      Flaw in the login screen with the latest release. Simply typing in 'root' allows the user to login without entering a password. https://www.cnet.com/news/apple-flaw-allows-macos-high-sierra-logins-without-passwords/

      Best part is, if the machine is logged in, this will bypass filevault.

      DustinB3403D 1 Reply Last reply Reply Quote 2
      • DustinB3403D
        DustinB3403 @Kelly
        last edited by DustinB3403

        @kelly said in macOS High Sierra login flaw - root:

        @bbigford said in Apple login flaw - root:

        Flaw in the login screen with the latest release. Simply typing in 'root' allows the user to login without entering a password. https://www.cnet.com/news/apple-flaw-allows-macos-high-sierra-logins-without-passwords/

        Best part is, if the machine is logged in, this will bypass filevault.

        Well of course, you're root at that point and get do do whatever you want.

        rm -rf *.*
        
        KellyK 1 Reply Last reply Reply Quote 0
        • KellyK
          Kelly @DustinB3403
          last edited by

          @dustinb3403 said in macOS High Sierra login flaw - root:

          @kelly said in macOS High Sierra login flaw - root:

          @bbigford said in Apple login flaw - root:

          Flaw in the login screen with the latest release. Simply typing in 'root' allows the user to login without entering a password. https://www.cnet.com/news/apple-flaw-allows-macos-high-sierra-logins-without-passwords/

          Best part is, if the machine is logged in, this will bypass filevault.

          Well of course, you're root at that point and get do do whatever you want.

          rm -rf *.*
          

          If the computer is off, and then powered on the flaw cannot bypass filevault since the "disabled" root account doesn't have its own key to decrypt.

          1 Reply Last reply Reply Quote 0
          • nadnerBN
            nadnerB
            last edited by nadnerB

            Obligatory: Macs don't get viruses
            Obviously there's no need for a virus, when the front door doesn't lock

            1 Reply Last reply Reply Quote 3
            • dbeatoD
              dbeato
              last edited by

              Lemi Orhan let them know here:
              https://twitter.com/lemiorhan/status/935578694541770752
              Same here:
              https://twitter.com/lemiorhan/status/935581020774117381

              Workaround is here:
              https://github.com/rtrouton/rtrouton_scripts/tree/master/rtrouton_scripts/block_root_account_login

              1 Reply Last reply Reply Quote 0
              • dbeatoD
                dbeato
                last edited by

                Applied it on all the Macs we had at the office.

                1 Reply Last reply Reply Quote 0
                • caramelC
                  caramel
                  last edited by

                  Today is a day of fail.

                  1 Reply Last reply Reply Quote 1
                  • s.hacklemanS
                    s.hackleman
                    last edited by

                    The quick fix is sudo pwd to change the root password to something non-blank. I assume apple with have a fix out quick.

                    1 Reply Last reply Reply Quote 1
                    • WLS-ITGuyW
                      WLS-ITGuy
                      last edited by

                      Why is root enabled by default?

                      RojoLocoR s.hacklemanS 2 Replies Last reply Reply Quote 0
                      • RojoLocoR
                        RojoLoco @WLS-ITGuy
                        last edited by

                        @wls-itguy said in macOS High Sierra login flaw - root:

                        Why is root enabled by default?

                        Because apple sucks ass?

                        WLS-ITGuyW 1 Reply Last reply Reply Quote 0
                        • WLS-ITGuyW
                          WLS-ITGuy @RojoLoco
                          last edited by

                          @rojoloco said in macOS High Sierra login flaw - root:

                          @wls-itguy said in macOS High Sierra login flaw - root:

                          Why is root enabled by default?

                          Because apple sucks ass?

                          OK. Because that was the answer I was looking for :SMH

                          RojoLocoR 1 Reply Last reply Reply Quote 0
                          • K
                            Kris_K
                            last edited by

                            Check the app store for new updates. There's an update available to fix this one.

                            1 Reply Last reply Reply Quote 0
                            • RojoLocoR
                              RojoLoco @WLS-ITGuy
                              last edited by RojoLoco

                              This post is deleted!
                              s.hacklemanS 1 Reply Last reply Reply Quote 1
                              • s.hacklemanS
                                s.hackleman @RojoLoco
                                last edited by Minion Queen

                                @rojoloco said in macOS High Sierra login flaw - root:

                                @wls-itguy said in macOS High Sierra login flaw - root:

                                @rojoloco said in macOS High Sierra login flaw - root:

                                @wls-itguy said in macOS High Sierra login flaw - root:

                                Why is root enabled by default?

                                Because apple sucks ass?

                                OK. Because that was the answer I was looking for :SMH

                                For as logical and well mannered as people here are, it is frustrating to even visit Mango and try to have a conversation as an Apple user.

                                RojoLocoR DashrenderD 2 Replies Last reply Reply Quote 2
                                • s.hacklemanS
                                  s.hackleman @WLS-ITGuy
                                  last edited by

                                  @wls-itguy said in macOS High Sierra login flaw - root:

                                  Why is root enabled by default?

                                  It isn't the bug is doing a PW check against the disabled account, or is enabling this disabling the account for the check.

                                  1 Reply Last reply Reply Quote 0
                                  • RojoLocoR
                                    RojoLoco @s.hackleman
                                    last edited by

                                    @s-hackleman said in macOS High Sierra login flaw - root:

                                    @rojoloco said in macOS High Sierra login flaw - root:

                                    @wls-itguy said in macOS High Sierra login flaw - root:

                                    @rojoloco said in macOS High Sierra login flaw - root:

                                    @wls-itguy said in macOS High Sierra login flaw - root:

                                    Why is root enabled by default?

                                    Because apple sucks ass?

                                    OK. Because that was the answer I was looking for :SMH

                                    0_1511991108142_n5FkD7N.jpg

                                    seriously.... fuck crapple in their self righteous ass....

                                    For as logical and well mannered as people, it is frustrating to even visit Mango and try to have a conversation as an Apple user.

                                    Logical and well mannered apple users are the tiny minority.

                                    s.hacklemanS 1 Reply Last reply Reply Quote 0
                                    • s.hacklemanS
                                      s.hackleman @RojoLoco
                                      last edited by

                                      @rojoloco said in macOS High Sierra login flaw - root:

                                      @s-hackleman said in macOS High Sierra login flaw - root:

                                      @rojoloco said in macOS High Sierra login flaw - root:

                                      @wls-itguy said in macOS High Sierra login flaw - root:

                                      @rojoloco said in macOS High Sierra login flaw - root:

                                      @wls-itguy said in macOS High Sierra login flaw - root:

                                      Why is root enabled by default?

                                      Because apple sucks ass?

                                      OK. Because that was the answer I was looking for :SMH

                                      0_1511991108142_n5FkD7N.jpg

                                      seriously.... fuck crapple in their self righteous ass....

                                      For as logical and well mannered as people, it is frustrating to even visit Mango and try to have a conversation as an Apple user.

                                      Logical and well mannered apple users are the tiny minority.

                                      As are educated and logical places on the internet to have conversations about technology... so let's keep this one.

                                      RojoLocoR 1 Reply Last reply Reply Quote 1
                                      • RojoLocoR
                                        RojoLoco @s.hackleman
                                        last edited by

                                        @s-hackleman said in macOS High Sierra login flaw - root:

                                        @rojoloco said in macOS High Sierra login flaw - root:

                                        @s-hackleman said in macOS High Sierra login flaw - root:

                                        @rojoloco said in macOS High Sierra login flaw - root:

                                        @wls-itguy said in macOS High Sierra login flaw - root:

                                        @rojoloco said in macOS High Sierra login flaw - root:

                                        @wls-itguy said in macOS High Sierra login flaw - root:

                                        Why is root enabled by default?

                                        Because apple sucks ass?

                                        OK. Because that was the answer I was looking for :SMH

                                        0_1511991108142_n5FkD7N.jpg

                                        seriously.... fuck crapple in their self righteous ass....

                                        For as logical and well mannered as people, it is frustrating to even visit Mango and try to have a conversation as an Apple user.

                                        Logical and well mannered apple users are the tiny minority.

                                        As are educated and logical places on the internet to have conversations about technology... so let's keep this one.

                                        Educated and logical places on the internet are more prevalent than non-shitty apple users, soooo.........

                                        WLS-ITGuyW 1 Reply Last reply Reply Quote -1
                                        • WLS-ITGuyW
                                          WLS-ITGuy @RojoLoco
                                          last edited by WLS-ITGuy

                                          @rojoloco said in macOS High Sierra login flaw - root:

                                          @s-hackleman said in macOS High Sierra login flaw - root:

                                          @rojoloco said in macOS High Sierra login flaw - root:

                                          @s-hackleman said in macOS High Sierra login flaw - root:

                                          @rojoloco said in macOS High Sierra login flaw - root:

                                          @wls-itguy said in macOS High Sierra login flaw - root:

                                          @rojoloco said in macOS High Sierra login flaw - root:

                                          @wls-itguy said in macOS High Sierra login flaw - root:

                                          Why is root enabled by default?

                                          Because apple sucks ass?

                                          OK. Because that was the answer I was looking for :SMH

                                          0_1511991108142_n5FkD7N.jpg

                                          seriously.... fuck crapple in their self righteous ass....

                                          For as logical and well mannered as people, it is frustrating to even visit Mango and try to have a conversation as an Apple user.

                                          Logical and well mannered apple users are the tiny minority.

                                          As are educated and logical places on the internet to have conversations about technology... so let's keep this one.

                                          Educated and logical places on the internet are more prevalent than non-shitty apple users, soooo.........

                                          That could mean that both this place and non-shitty apple users are equally rare. Why you gotta be a douche-canoe?

                                          RojoLocoR 1 Reply Last reply Reply Quote -1
                                          • RojoLocoR
                                            RojoLoco @WLS-ITGuy
                                            last edited by

                                            @wls-itguy said in macOS High Sierra login flaw - root:

                                            @rojoloco said in macOS High Sierra login flaw - root:

                                            @s-hackleman said in macOS High Sierra login flaw - root:

                                            @rojoloco said in macOS High Sierra login flaw - root:

                                            @s-hackleman said in macOS High Sierra login flaw - root:

                                            @rojoloco said in macOS High Sierra login flaw - root:

                                            @wls-itguy said in macOS High Sierra login flaw - root:

                                            @rojoloco said in macOS High Sierra login flaw - root:

                                            @wls-itguy said in macOS High Sierra login flaw - root:

                                            Why is root enabled by default?

                                            Because apple sucks ass?

                                            OK. Because that was the answer I was looking for :SMH

                                            0_1511991108142_n5FkD7N.jpg

                                            seriously.... fuck crapple in their self righteous ass....

                                            For as logical and well mannered as people, it is frustrating to even visit Mango and try to have a conversation as an Apple user.

                                            Logical and well mannered apple users are the tiny minority.

                                            As are educated and logical places on the internet to have conversations about technology... so let's keep this one.

                                            Educated and logical places on the internet are more prevalent than non-shitty apple users, soooo.........

                                            That could mean that both this place and non-shitty apple users are equally rare. Why you gotta be a douche-canoe?

                                            OMG, please let me roll over and submit my soft underbelly to the apple user base.... oh, wait.....

                                            show me some non-douche canoe apple users, and I might agree.

                                            s.hacklemanS WLS-ITGuyW 2 Replies Last reply Reply Quote 0
                                            • 1
                                            • 2
                                            • 1 / 2
                                            • First post
                                              Last post