Be careful testing this! It appears that you're creating a "root" superuser with no password. Be sure to clean up that user afterwords. https://twitter.com/a_hailes/status/935601901839806464
macOS High Sierra: Anyone can login as “root” with empty password
351–360 of 1001 posts
Re: macOS High Sierra: Anyone can login as “root” with empty password
#352Earlier quoted context omitted.
Can't repro on a 2012 retina MBP running 10.13.1, attempting the original repro and others suggested here. Until the wife walks away from hers, it's the only machine I have available. I'm curious as to the difference, given the high number of repros.
Apparently you have to have the password field focused before you submit. Anything in the password field (including nothing) will be saved as the root password.
Re: macOS High Sierra: Anyone can login as “root” with empty password
#353I asked this in the other thread, but... does anyone know how big of a bounty the guy missed by not disclosing this responsibly? I'm guessing it probably would've been a fairly big chunk of change.
Re: macOS High Sierra: Anyone can login as “root” with empty password
#354Earlier quoted context omitted.
This vulnerability lets users activate the root user without using their password. Once done, you have opened for root without password globally. That's bad. What they should do, as responsible disclosure dictates , is report it in secret to apple, and at most publicize a workaround (activate root user, set password) without reporting the details of the vulnerability . EDIT: It does not appear to be limited to admin…
"responsible disclosure" isn't some morally unassailable high ground, but companies like apple sure want you to believe it is.
Re: macOS High Sierra: Anyone can login as “root” with empty password
#355Wow. This is fun. I remember my Windows98 had the same feature. You just use Administrator with empty password and you're in. Apple is finally catching up.
Did Windows98 even have administrator role? I mean FAT file systems don't even have file ownership right?
Re: macOS High Sierra: Anyone can login as “root” with empty password
#356AWS ReInvent 2017 is going right now in Las Vegas, the number of attendees is about 40000, and I'm wondering how many laptops can be attacked using this technique. The `root` user stays in the system, so one just need to create it and open SSH quickly, and later they can do whatever they please.
Re: macOS High Sierra: Anyone can login as “root” with empty password
#357Oh my goodness. I have a High Sierra MBP. I am scared right now BADLY
Re: macOS High Sierra: Anyone can login as “root” with empty password
#358Anyone else think it was a bad idea to disclose this so publicly over Twitter? I thought that the usual practice was to let the development team know first.
My personal policy: If there's a workaround or mitigation, then full disclosure is more responsible. If there isn't then report to developers and CERT or similar. Never report only to developers, always have a deadline for full disclosure, and always have a third-party (CERT, Project Zero, etc) to disclose if you come under legal fire.
Re: macOS High Sierra: Anyone can login as “root” with empty password
#359Re: macOS High Sierra: Anyone can login as “root” with empty password
#360Earlier quoted context omitted.
>In which case all bets are off anyways How are all bets off if they don't have access to a root user? This isn't Windows we're talking about.
If you lose physical control over the machine, all bets are off because an attacker can modify the hardware to do nefarious things.