ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    macOS High Sierra login flaw - root

    IT Discussion
    security apple macos macos 10.13
    12
    33
    3.7k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • bbigfordB
      bbigford
      last edited by scottalanmiller

      Flaw in the login screen with the latest release. Simply typing in 'root' allows the user to login without entering a password. https://www.cnet.com/news/apple-flaw-allows-macos-high-sierra-logins-without-passwords/

      KellyK 1 Reply Last reply Reply Quote 3
      • KellyK
        Kelly @bbigford
        last edited by

        @bbigford said in Apple login flaw - root:

        Flaw in the login screen with the latest release. Simply typing in 'root' allows the user to login without entering a password. https://www.cnet.com/news/apple-flaw-allows-macos-high-sierra-logins-without-passwords/

        Best part is, if the machine is logged in, this will bypass filevault.

        DustinB3403D 1 Reply Last reply Reply Quote 2
        • DustinB3403D
          DustinB3403 @Kelly
          last edited by DustinB3403

          @kelly said in macOS High Sierra login flaw - root:

          @bbigford said in Apple login flaw - root:

          Flaw in the login screen with the latest release. Simply typing in 'root' allows the user to login without entering a password. https://www.cnet.com/news/apple-flaw-allows-macos-high-sierra-logins-without-passwords/

          Best part is, if the machine is logged in, this will bypass filevault.

          Well of course, you're root at that point and get do do whatever you want.

          rm -rf *.*
          
          KellyK 1 Reply Last reply Reply Quote 0
          • KellyK
            Kelly @DustinB3403
            last edited by

            @dustinb3403 said in macOS High Sierra login flaw - root:

            @kelly said in macOS High Sierra login flaw - root:

            @bbigford said in Apple login flaw - root:

            Flaw in the login screen with the latest release. Simply typing in 'root' allows the user to login without entering a password. https://www.cnet.com/news/apple-flaw-allows-macos-high-sierra-logins-without-passwords/

            Best part is, if the machine is logged in, this will bypass filevault.

            Well of course, you're root at that point and get do do whatever you want.

            rm -rf *.*
            

            If the computer is off, and then powered on the flaw cannot bypass filevault since the "disabled" root account doesn't have its own key to decrypt.

            1 Reply Last reply Reply Quote 0
            • nadnerBN
              nadnerB
              last edited by nadnerB

              Obligatory: Macs don't get viruses
              Obviously there's no need for a virus, when the front door doesn't lock

              1 Reply Last reply Reply Quote 3
              • dbeatoD
                dbeato
                last edited by

                Lemi Orhan let them know here:
                https://twitter.com/lemiorhan/status/935578694541770752
                Same here:
                https://twitter.com/lemiorhan/status/935581020774117381

                Workaround is here:
                https://github.com/rtrouton/rtrouton_scripts/tree/master/rtrouton_scripts/block_root_account_login

                1 Reply Last reply Reply Quote 0
                • dbeatoD
                  dbeato
                  last edited by

                  Applied it on all the Macs we had at the office.

                  1 Reply Last reply Reply Quote 0
                  • caramelC
                    caramel
                    last edited by

                    Today is a day of fail.

                    1 Reply Last reply Reply Quote 1
                    • s.hacklemanS
                      s.hackleman
                      last edited by

                      The quick fix is sudo pwd to change the root password to something non-blank. I assume apple with have a fix out quick.

                      1 Reply Last reply Reply Quote 1
                      • WLS-ITGuyW
                        WLS-ITGuy
                        last edited by

                        Why is root enabled by default?

                        RojoLocoR s.hacklemanS 2 Replies Last reply Reply Quote 0
                        • RojoLocoR
                          RojoLoco @WLS-ITGuy
                          last edited by

                          @wls-itguy said in macOS High Sierra login flaw - root:

                          Why is root enabled by default?

                          Because apple sucks ass?

                          WLS-ITGuyW 1 Reply Last reply Reply Quote 0
                          • WLS-ITGuyW
                            WLS-ITGuy @RojoLoco
                            last edited by

                            @rojoloco said in macOS High Sierra login flaw - root:

                            @wls-itguy said in macOS High Sierra login flaw - root:

                            Why is root enabled by default?

                            Because apple sucks ass?

                            OK. Because that was the answer I was looking for :SMH

                            RojoLocoR 1 Reply Last reply Reply Quote 0
                            • K
                              Kris_K
                              last edited by

                              Check the app store for new updates. There's an update available to fix this one.

                              1 Reply Last reply Reply Quote 0
                              • RojoLocoR
                                RojoLoco @WLS-ITGuy
                                last edited by RojoLoco

                                This post is deleted!
                                s.hacklemanS 1 Reply Last reply Reply Quote 1
                                • s.hacklemanS
                                  s.hackleman @RojoLoco
                                  last edited by Minion Queen

                                  @rojoloco said in macOS High Sierra login flaw - root:

                                  @wls-itguy said in macOS High Sierra login flaw - root:

                                  @rojoloco said in macOS High Sierra login flaw - root:

                                  @wls-itguy said in macOS High Sierra login flaw - root:

                                  Why is root enabled by default?

                                  Because apple sucks ass?

                                  OK. Because that was the answer I was looking for :SMH

                                  For as logical and well mannered as people here are, it is frustrating to even visit Mango and try to have a conversation as an Apple user.

                                  RojoLocoR DashrenderD 2 Replies Last reply Reply Quote 2
                                  • s.hacklemanS
                                    s.hackleman @WLS-ITGuy
                                    last edited by

                                    @wls-itguy said in macOS High Sierra login flaw - root:

                                    Why is root enabled by default?

                                    It isn't the bug is doing a PW check against the disabled account, or is enabling this disabling the account for the check.

                                    1 Reply Last reply Reply Quote 0
                                    • RojoLocoR
                                      RojoLoco @s.hackleman
                                      last edited by

                                      @s-hackleman said in macOS High Sierra login flaw - root:

                                      @rojoloco said in macOS High Sierra login flaw - root:

                                      @wls-itguy said in macOS High Sierra login flaw - root:

                                      @rojoloco said in macOS High Sierra login flaw - root:

                                      @wls-itguy said in macOS High Sierra login flaw - root:

                                      Why is root enabled by default?

                                      Because apple sucks ass?

                                      OK. Because that was the answer I was looking for :SMH

                                      0_1511991108142_n5FkD7N.jpg

                                      seriously.... fuck crapple in their self righteous ass....

                                      For as logical and well mannered as people, it is frustrating to even visit Mango and try to have a conversation as an Apple user.

                                      Logical and well mannered apple users are the tiny minority.

                                      s.hacklemanS 1 Reply Last reply Reply Quote 0
                                      • s.hacklemanS
                                        s.hackleman @RojoLoco
                                        last edited by

                                        @rojoloco said in macOS High Sierra login flaw - root:

                                        @s-hackleman said in macOS High Sierra login flaw - root:

                                        @rojoloco said in macOS High Sierra login flaw - root:

                                        @wls-itguy said in macOS High Sierra login flaw - root:

                                        @rojoloco said in macOS High Sierra login flaw - root:

                                        @wls-itguy said in macOS High Sierra login flaw - root:

                                        Why is root enabled by default?

                                        Because apple sucks ass?

                                        OK. Because that was the answer I was looking for :SMH

                                        0_1511991108142_n5FkD7N.jpg

                                        seriously.... fuck crapple in their self righteous ass....

                                        For as logical and well mannered as people, it is frustrating to even visit Mango and try to have a conversation as an Apple user.

                                        Logical and well mannered apple users are the tiny minority.

                                        As are educated and logical places on the internet to have conversations about technology... so let's keep this one.

                                        RojoLocoR 1 Reply Last reply Reply Quote 1
                                        • RojoLocoR
                                          RojoLoco @s.hackleman
                                          last edited by

                                          @s-hackleman said in macOS High Sierra login flaw - root:

                                          @rojoloco said in macOS High Sierra login flaw - root:

                                          @s-hackleman said in macOS High Sierra login flaw - root:

                                          @rojoloco said in macOS High Sierra login flaw - root:

                                          @wls-itguy said in macOS High Sierra login flaw - root:

                                          @rojoloco said in macOS High Sierra login flaw - root:

                                          @wls-itguy said in macOS High Sierra login flaw - root:

                                          Why is root enabled by default?

                                          Because apple sucks ass?

                                          OK. Because that was the answer I was looking for :SMH

                                          0_1511991108142_n5FkD7N.jpg

                                          seriously.... fuck crapple in their self righteous ass....

                                          For as logical and well mannered as people, it is frustrating to even visit Mango and try to have a conversation as an Apple user.

                                          Logical and well mannered apple users are the tiny minority.

                                          As are educated and logical places on the internet to have conversations about technology... so let's keep this one.

                                          Educated and logical places on the internet are more prevalent than non-shitty apple users, soooo.........

                                          WLS-ITGuyW 1 Reply Last reply Reply Quote -1
                                          • WLS-ITGuyW
                                            WLS-ITGuy @RojoLoco
                                            last edited by WLS-ITGuy

                                            @rojoloco said in macOS High Sierra login flaw - root:

                                            @s-hackleman said in macOS High Sierra login flaw - root:

                                            @rojoloco said in macOS High Sierra login flaw - root:

                                            @s-hackleman said in macOS High Sierra login flaw - root:

                                            @rojoloco said in macOS High Sierra login flaw - root:

                                            @wls-itguy said in macOS High Sierra login flaw - root:

                                            @rojoloco said in macOS High Sierra login flaw - root:

                                            @wls-itguy said in macOS High Sierra login flaw - root:

                                            Why is root enabled by default?

                                            Because apple sucks ass?

                                            OK. Because that was the answer I was looking for :SMH

                                            0_1511991108142_n5FkD7N.jpg

                                            seriously.... fuck crapple in their self righteous ass....

                                            For as logical and well mannered as people, it is frustrating to even visit Mango and try to have a conversation as an Apple user.

                                            Logical and well mannered apple users are the tiny minority.

                                            As are educated and logical places on the internet to have conversations about technology... so let's keep this one.

                                            Educated and logical places on the internet are more prevalent than non-shitty apple users, soooo.........

                                            That could mean that both this place and non-shitty apple users are equally rare. Why you gotta be a douche-canoe?

                                            RojoLocoR 1 Reply Last reply Reply Quote -1
                                            • 1
                                            • 2
                                            • 1 / 2
                                            • First post
                                              Last post