Live data from Hacker News

macOS High Sierra: Anyone can login as “root” with empty password

twitter.com

101–110 of 1001 posts

Re: macOS High Sierra: Anyone can login as “root” with empty password

#101
post #38

Be careful testing this! It appears that you're creating a "root" superuser with no password. Be sure to clean up that user afterwords. https://twitter.com/a_hailes/status/935601901839806464

It's worse than that. You're enabling the root user EVERY time you use this vulnerability. Even if you disable the root user in Directory Utility, logging in with root and no password will re-enable the root user.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#102

Apple makes it pretty easy to report vulnerabilities to: product-security@apple.com They also respond to security@apple.com but prefer the product-security address. Further, there are any number of legit bug bounty programs out there like ZDI that would pay for a bug like this then immediately disclose to Apple for it to be fixed. Disclosing an 0Day root authentication bypass vulnerability on Twitter isn't cool, even…

It's the neighborly thing to do, but people are under no obligation to report vulns privately. The blame lies squarely on Apple, not on the messenger. The fact that we know about it means we can take steps to mitigate the damage.

The blame lies squarely on Apple, not on the messenger.

There is blame on both.

If you leave your key in your front door lock and I blast out on twitter your address and tell people about it, I think I have some responsibility.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#103
post #90

A quick mitigation workaround: If you follow the steps here https://support.apple.com/en-us/HT204012 to disable the root account until the point where you open and authenticate the Directory Utility, in the Edit menu there's a "Change Root Password" option. Set a good password there and disable the root account again. Now people making use of this vulnerability will still be able to re-enable the root account (that's…

if you disable the root account you can log in again without a password, even when you set one.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#104
post #12

I can't seem to reproduce it locally. 10.13.1… Anyone else having issues? I've upgraded a through a couple versions of OS X on this machine - maybe that makes a difference?

It took 3 tries for me and then it worked.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#105
I mean, I only tried 15 times, I don't know if that counts as "several" but this doesn't work for me.

It looks to me like my root user is disabled.

When I type "root" into the username field and click unlock (in System Preferences > Users & Groups) "root" is replaced with my username and the dialog shakes... I have to type root in each time, but it never unlocks. 10.13.1

Edit: trying it after logging out keeps "root" in the username field, but never logs me in... tried 20+ times

Re: macOS High Sierra: Anyone can login as “root” with empty password

#106
post #94

For those who can't make it happen, it requires that the root account is disabled, which is the default. If you already enabled the root account for some other reason (which apparently I had on one of my Macs, although I don't know why) then that prevents it from working. It seems like the best mitigation for the moment might be to enable the root user and set a password for it.

Once you disable the root account you can log in without a password again :/

Re: macOS High Sierra: Anyone can login as “root” with empty password

#107
post #56

In the meantime, if you'd like to protect your mac, you can set a password for root by going to: System Preferences > Users & Groups > Login Options > Join > Open Directory Utility > Edit > Change Root Password

Standalone iMac here - the 'Join' button is disabled. So is this vulnerability only for Macs on a network? EDIT: My bad - editing was locked on that screen. Got it now... EDIT2: Root user is disabled on mine. Is that enough, given that this bug seems to create a new root user each time? Should I enable root user and set a password rather than leave it disabled?

The bug enables the root user, so leaving it disabled won't save you. Set a password for root, then you should be good to go.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#108

Excuse my language, but this was a dick move to post this publicly, especially on Twitter. Go through private bug channels properly for something as serious as this. Of course doing it that way doesn't give you your 15 minutes of interweb fame.

this is too serious to hide. better to tell users how to fix it than wait until apple releases something

Yeh, except for the millions of MacOS users out there, like my parents who don't read Twitter, or HN or any of the other sites people think that everyone stays up on. They are the targets.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#109
post #38

Be careful testing this! It appears that you're creating a "root" superuser with no password. Be sure to clean up that user afterwords. https://twitter.com/a_hailes/status/935601901839806464

Until this is fixed it's probably better to use Directory Utility to enable root with a strong password.

/System/Library/CoreServices/Applications/Directory Utility.app

Edit > Change Root Password

Post reply on HN