Be careful testing this! It appears that you're creating a "root" superuser with no password. Be sure to clean up that user afterwords. https://twitter.com/a_hailes/status/935601901839806464
macOS High Sierra: Anyone can login as “root” with empty password
101–110 of 1001 posts
Re: macOS High Sierra: Anyone can login as “root” with empty password
#102Apple makes it pretty easy to report vulnerabilities to: product-security@apple.com They also respond to security@apple.com but prefer the product-security address. Further, there are any number of legit bug bounty programs out there like ZDI that would pay for a bug like this then immediately disclose to Apple for it to be fixed. Disclosing an 0Day root authentication bypass vulnerability on Twitter isn't cool, even…
It's the neighborly thing to do, but people are under no obligation to report vulns privately. The blame lies squarely on Apple, not on the messenger. The fact that we know about it means we can take steps to mitigate the damage.
There is blame on both.
If you leave your key in your front door lock and I blast out on twitter your address and tell people about it, I think I have some responsibility.
Re: macOS High Sierra: Anyone can login as “root” with empty password
#103A quick mitigation workaround: If you follow the steps here https://support.apple.com/en-us/HT204012 to disable the root account until the point where you open and authenticate the Directory Utility, in the Edit menu there's a "Change Root Password" option. Set a good password there and disable the root account again. Now people making use of this vulnerability will still be able to re-enable the root account (that's…
Re: macOS High Sierra: Anyone can login as “root” with empty password
#104I can't seem to reproduce it locally. 10.13.1… Anyone else having issues? I've upgraded a through a couple versions of OS X on this machine - maybe that makes a difference?
Re: macOS High Sierra: Anyone can login as “root” with empty password
#105It looks to me like my root user is disabled.
When I type "root" into the username field and click unlock (in System Preferences > Users & Groups) "root" is replaced with my username and the dialog shakes... I have to type root in each time, but it never unlocks. 10.13.1
Edit: trying it after logging out keeps "root" in the username field, but never logs me in... tried 20+ times
Re: macOS High Sierra: Anyone can login as “root” with empty password
#106For those who can't make it happen, it requires that the root account is disabled, which is the default. If you already enabled the root account for some other reason (which apparently I had on one of my Macs, although I don't know why) then that prevents it from working. It seems like the best mitigation for the moment might be to enable the root user and set a password for it.
Re: macOS High Sierra: Anyone can login as “root” with empty password
#107In the meantime, if you'd like to protect your mac, you can set a password for root by going to: System Preferences > Users & Groups > Login Options > Join > Open Directory Utility > Edit > Change Root Password
Standalone iMac here - the 'Join' button is disabled. So is this vulnerability only for Macs on a network? EDIT: My bad - editing was locked on that screen. Got it now... EDIT2: Root user is disabled on mine. Is that enough, given that this bug seems to create a new root user each time? Should I enable root user and set a password rather than leave it disabled?
Re: macOS High Sierra: Anyone can login as “root” with empty password
#108Excuse my language, but this was a dick move to post this publicly, especially on Twitter. Go through private bug channels properly for something as serious as this. Of course doing it that way doesn't give you your 15 minutes of interweb fame.
this is too serious to hide. better to tell users how to fix it than wait until apple releases something
Re: macOS High Sierra: Anyone can login as “root” with empty password
#109Be careful testing this! It appears that you're creating a "root" superuser with no password. Be sure to clean up that user afterwords. https://twitter.com/a_hailes/status/935601901839806464
/System/Library/CoreServices/Applications/Directory Utility.app
Edit > Change Root Password