Live data from Hacker News

Cracking OSX Lion passwords

defenceindepth.net

81–82 of 82 posts

Re: Cracking OSX Lion passwords

#81

Earlier quoted context omitted.

Think of any system as a castle. Having access to an interactive shell is like standing outside the King's bedroom. Sure, you might not have the keys to the bedroom door, but you've already made it past the archers, the moat, the drawbridge, the boiling oil, and the King's personal body guards. You don't put a 3 ton door on the King's bedroom and say, "Well, that should keep the invading army out!" No, you strengthen…

That an attacker has physical access does mean that your computer is compromised, so you're half right. If you seriously think having an account on a machine is as good as having the root account, then you should call up every shared hosting provider and let them know. They hand out accounts to any asshole with $10.

I can create an account on the machine without having root access. Which gives me a shell. Which means I can exploit a flaw to change root password. Which means I have access to cookies and other fun things. Which means I can probably access that person's gmail which is pretty much game over, man.

Bedroom analogy is wrong. The computer is the castle. They have it. The problem is that your lord knows the secret entrance to your main castle (in the cloud). You want one of two things to happen: Keep the lord safe, or kill the lord so his secrets are gone with him. The attacker formatting the machine, or replacing the hard drive is fine, he already physically has it, just like he can take the vault and throw it outside and make a new one. However you don't want him accessing that vault.

Re: Cracking OSX Lion passwords

#82

Earlier quoted context omitted.

The file includes all password hashes, including root. So crack that, then you have superuser.

By default, Mac OS X disables the root user: http://support.apple.com/kb/ht1528 That said, reset or crack any admin's password and you can go to town with sudo.

Default user can use sudo with it's password. That's all you really need.
Post reply on HN