Thursday, May 15, 2025
Germany Latest News
  • Sports
  • USA
  • Asia
  • Health
  • Life Style
  • Tech
  • Science
  • Latin America
  • Africa
  • Europe
No Result
View All Result
Germany Latest News

macOS bug lets you log in as admin with no password required

by The Editor
November 29, 2017
in Tech
0
macOS bug lets you log in as admin with no password required
EnlargePatrick Wardle

In one of Apple's biggest security blunders in years, a bug in macOS High Sierra allows untrusted users to gain unfettered administrative control without any password.

The bypass works by putting the word "root" (without the quotes) in the user name field of a login window, moving the cursor into the password field, and then hitting enter button with the password field empty. With that—after a few tries in some cases—the latest version of Apple's operating system logs the user in with root privileges. Ars reporters were able to replicate the behavior multiple times on three Macs. The flaw isn't present on previous macOS versions.

The password bypass can be exploited in a variety of ways, depending on the way the targeted Mac has been set up. When full-disk encryption is turned off, an untrusted user can turn on a Mac that's fully powered down and log in as root. Exploiting the vulnerability was also not possible when a Mac was turned on and the screen was password protected. Even on Macs that have filevault turned on, the bypass can also be used to make unauthorized changes to the Mac System Preferences (including disabling filevault), or the bypass can be used to log in as root after logging out of an existing account but not turning off the machine. The behavior observed in Ars tests and reported on social media was extremely inconsistent, so results are likely to vary widely.

The upshot of all of this: as long as someone has filevault turned on, their files are most likely safe from this exploit as long as their Mac is turned off before an attacker gets hold of it. Locking a screen with a password also appeared to protect a computer while it's unattended.

Privilege escalation

Of more concern is that malicious hackers can exploit this vulnerability to give their malware unfettered control over the computer and OS. Such escalation-of-privilege exploits have become increasingly valuable over the past decade as a way to defeat modern OS defenses. A key protection found in virtually all OSes is to restrict the privileges given to running software. As a result, even when attackers succeed in executing malicious code, they're unable to get the malware permanently installed or to access sensitive parts of the OS.

"This looks like something that a piece of malware or an attacker could use in a multistage attack," Patrick Wardle, a researcher with security firm Synack, told Ars. In cases such as these, attackers use one exploit to run their malicious code and a second exploit to escalate the privileges of that code so it can perform actions that the OS normally wouldn't allow. "This appears to be one way malware or an attacker would be able to do that."

Amit Serper, principal security researcher at Cybereason, said his tests showed the vulnerability is located in com.apple.loginwindow, a macOS component that's one of at least two ways users can log into accounts. He said he was unable to reproduce the exploit using a Mac's terminal window, although he said he saw reports on Twitter from other people who said the bypass worked using the terminal window as well. Whatever the case, he agreed with Wardle that the flaw likely represents a major privilege-escalation vulnerability that can be exploited easily by malware developers.

"If they're using API (programming interface) calls, it's a matter of writing the appropriate code," Serper told Ars. "An attacker should be able to trigger it."

The vulnerability can also have dire consequences for people who have made their Macs accessible through remote management screen sharing provided through macOS or third-party services. Will Dormann, a vulerability analyst at CERT, said on Twitter that having remote options turned on will allow attackers to remotely access the machine with no password required. Results from a quick search that were posted on Twitter showed more than 105,000 Macs alone had the VNC remote desktop app installed. To check if remote management or screen sharing is on, users can check the Sharing menu in System Preferences.

The bug came to light Tuesday morning when a Mac user contacted Apple support representatives over Twitter:

Dear @AppleSupport, we noticed a *HUGE* security issue at MacOS High Sierra. Anyone can login as "root" with empty password after clicking on login button several times. Are you aware of it @Apple?

— Lemi Orhan Ergin (@lemiorhan) November 28, 2017

Remember goto fail?

A vulnerability that logs users in as root without requiring any password at all is extraordinary, both because of the lack of testing it suggests on the part of Apple developers and the potential harm it presents to end users. The last time in recent memory Apple made an error of this magnitude was the so-called goto fail bug that gave attackers an easy way to bypass TLS encryption. It took Apple four days to patch the critical flaw, which got its name from one of the lines of code responsible for the vulnerability.

Apple representatives issued the following statement:

We are working on a software update to address this issue. In the meantime, setting a root password prevents unauthorized access to your Mac. To enable the Root User and set a password, please follow the instructions here: https://support.apple.com/en-us/HT204012. If a Root User is already enabled, to ensure a blank password is not set, please follow the instructions from the "Change the root password" section.

Some people have reported they're unable to update their Macs using the instructions supplied by Apple. As others have pointed out, another way users can set their root password to do the following:

  • open a terminal window
  • type 'sudo su' – use your own password to authenticate. You are now root.
  • Type 'passwd' and change follow instructions on screen to change the password

Passwords should be at least 13 characters long, randomly generated, and contain a mixture of numbers, upper- and lower-case letters, and symbols. As an added layer of security, users should also ensure they have filevault turned on.

Some researchers are speculating unsecured root account doesn't exist until someone with physical access to the Mac attempts to log in while leaving the password blank. That has prompted advice Mac users not test their systems lest they create a persistent root user account that wasn't there previously. Other researchers report here and here being able to exploit the weakness to remotely log into a Mac try, with no previous local login attempts.

This post was updated extensively over several hours as new details became available.

Original Article

Ars Technica

Related posts

What Are the Pros and Cons of Sperm Freezing Technology?

What Are the Pros and Cons of Sperm Freezing Technology?

September 8, 2023
How Tech Partnerships Can Keep the E-Commerce Boom Going?

How Tech Partnerships Can Keep the E-Commerce Boom Going?

September 8, 2023
EnlargePatrick Wardle

In one of Apple's biggest security blunders in years, a bug in macOS High Sierra allows untrusted users to gain unfettered administrative control without any password.

The bypass works by putting the word "root" (without the quotes) in the user name field of a login window, moving the cursor into the password field, and then hitting enter button with the password field empty. With that—after a few tries in some cases—the latest version of Apple's operating system logs the user in with root privileges. Ars reporters were able to replicate the behavior multiple times on three Macs. The flaw isn't present on previous macOS versions.

The password bypass can be exploited in a variety of ways, depending on the way the targeted Mac has been set up. When full-disk encryption is turned off, an untrusted user can turn on a Mac that's fully powered down and log in as root. Exploiting the vulnerability was also not possible when a Mac was turned on and the screen was password protected. Even on Macs that have filevault turned on, the bypass can also be used to make unauthorized changes to the Mac System Preferences (including disabling filevault), or the bypass can be used to log in as root after logging out of an existing account but not turning off the machine. The behavior observed in Ars tests and reported on social media was extremely inconsistent, so results are likely to vary widely.

The upshot of all of this: as long as someone has filevault turned on, their files are most likely safe from this exploit as long as their Mac is turned off before an attacker gets hold of it. Locking a screen with a password also appeared to protect a computer while it's unattended.

Privilege escalation

Of more concern is that malicious hackers can exploit this vulnerability to give their malware unfettered control over the computer and OS. Such escalation-of-privilege exploits have become increasingly valuable over the past decade as a way to defeat modern OS defenses. A key protection found in virtually all OSes is to restrict the privileges given to running software. As a result, even when attackers succeed in executing malicious code, they're unable to get the malware permanently installed or to access sensitive parts of the OS.

"This looks like something that a piece of malware or an attacker could use in a multistage attack," Patrick Wardle, a researcher with security firm Synack, told Ars. In cases such as these, attackers use one exploit to run their malicious code and a second exploit to escalate the privileges of that code so it can perform actions that the OS normally wouldn't allow. "This appears to be one way malware or an attacker would be able to do that."

Amit Serper, principal security researcher at Cybereason, said his tests showed the vulnerability is located in com.apple.loginwindow, a macOS component that's one of at least two ways users can log into accounts. He said he was unable to reproduce the exploit using a Mac's terminal window, although he said he saw reports on Twitter from other people who said the bypass worked using the terminal window as well. Whatever the case, he agreed with Wardle that the flaw likely represents a major privilege-escalation vulnerability that can be exploited easily by malware developers.

"If they're using API (programming interface) calls, it's a matter of writing the appropriate code," Serper told Ars. "An attacker should be able to trigger it."

The vulnerability can also have dire consequences for people who have made their Macs accessible through remote management screen sharing provided through macOS or third-party services. Will Dormann, a vulerability analyst at CERT, said on Twitter that having remote options turned on will allow attackers to remotely access the machine with no password required. Results from a quick search that were posted on Twitter showed more than 105,000 Macs alone had the VNC remote desktop app installed. To check if remote management or screen sharing is on, users can check the Sharing menu in System Preferences.

The bug came to light Tuesday morning when a Mac user contacted Apple support representatives over Twitter:

Dear @AppleSupport, we noticed a *HUGE* security issue at MacOS High Sierra. Anyone can login as "root" with empty password after clicking on login button several times. Are you aware of it @Apple?

— Lemi Orhan Ergin (@lemiorhan) November 28, 2017

Remember goto fail?

A vulnerability that logs users in as root without requiring any password at all is extraordinary, both because of the lack of testing it suggests on the part of Apple developers and the potential harm it presents to end users. The last time in recent memory Apple made an error of this magnitude was the so-called goto fail bug that gave attackers an easy way to bypass TLS encryption. It took Apple four days to patch the critical flaw, which got its name from one of the lines of code responsible for the vulnerability.

Apple representatives issued the following statement:

We are working on a software update to address this issue. In the meantime, setting a root password prevents unauthorized access to your Mac. To enable the Root User and set a password, please follow the instructions here: https://support.apple.com/en-us/HT204012. If a Root User is already enabled, to ensure a blank password is not set, please follow the instructions from the "Change the root password" section.

Some people have reported they're unable to update their Macs using the instructions supplied by Apple. As others have pointed out, another way users can set their root password to do the following:

  • open a terminal window
  • type 'sudo su' – use your own password to authenticate. You are now root.
  • Type 'passwd' and change follow instructions on screen to change the password

Passwords should be at least 13 characters long, randomly generated, and contain a mixture of numbers, upper- and lower-case letters, and symbols. As an added layer of security, users should also ensure they have filevault turned on.

Some researchers are speculating unsecured root account doesn't exist until someone with physical access to the Mac attempts to log in while leaving the password blank. That has prompted advice Mac users not test their systems lest they create a persistent root user account that wasn't there previously. Other researchers report here and here being able to exploit the weakness to remotely log into a Mac try, with no previous local login attempts.

This post was updated extensively over several hours as new details became available.

Original Article

Ars Technica

Previous Post

Bitcoin crosses $10,000 milestone

Next Post

Ajit Pai blames Cher and Hulk actor for ginning up net neutrality support

Next Post
Ajit Pai blames Cher and Hulk actor for ginning up net neutrality support

Ajit Pai blames Cher and Hulk actor for ginning up net neutrality support

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

RECOMMENDED NEWS

Sportscaster Dick Enberg has died at age 82

Sportscaster Dick Enberg has died at age 82

7 years ago
Here Are The Betting Props For Todays Senate Hearing With Christine Blasey Ford, Kavanaugh

Here Are The Betting Props For Todays Senate Hearing With Christine Blasey Ford, Kavanaugh

7 years ago
A police officer and two employees were killed in Chicago hospital shooting

A police officer and two employees were killed in Chicago hospital shooting

6 years ago
Tesla pulls the wraps off Software Version 9 update     – Roadshow

Tesla pulls the wraps off Software Version 9 update – Roadshow

7 years ago

FOLLOW US

  • 139 Followers
  • 87.2k Followers
  • 202k Subscribers

BROWSE BY CATEGORIES

  • 1xbet Casino Russia
  • 1xbet Russian Top
  • Africa
  • Asia
  • Europe
  • Health
  • latest news
  • Latin America
  • Life Style
  • Mail Order Brides
  • Mostbet
  • Online dating
  • onlyfans
  • Pin Up
  • Pin Up Russia
  • Science
  • Sports
  • Tech
  • Uncategorized
  • USA

BROWSE BY TOPICS

2018 League Bali United Beijing BlackBerry Brazil Broja Budget Travel Bundesliga California Champions League Chelsea China Chopper Bike Coronavirus COVID COVID-19 Crime Doctor Terawan EU France French German Istana Negara Italy Kazakhstan Market Stories Mexico National Exam Nigeria Omicron Pakistan Police protests Qatar Ronaldo Russia Smart Voting Sweden TikTok Trump UK Ukraine US vaccine Visit Bali
No Result
View All Result

Recent Posts

  • OnlyFans Platform Analysis
  • How to Day German Fashion
  • Southeast Continental Capabilities
  • What is a Mail Order Wife?
  • What to Discuss on a First Date?

Categories

  • 1xbet Casino Russia
  • 1xbet Russian Top
  • Africa
  • Asia
  • Europe
  • Health
  • latest news
  • Latin America
  • Life Style
  • Mail Order Brides
  • Mostbet
  • Online dating
  • onlyfans
  • Pin Up
  • Pin Up Russia
  • Science
  • Sports
  • Tech
  • Uncategorized
  • USA

Tags

2018 League Bali United Beijing BlackBerry Brazil Broja Budget Travel Bundesliga California Champions League Chelsea China Chopper Bike Coronavirus COVID COVID-19 Crime Doctor Terawan EU France French German Istana Negara Italy Kazakhstan Market Stories Mexico National Exam Nigeria Omicron Pakistan Police protests Qatar Ronaldo Russia Smart Voting Sweden TikTok Trump UK Ukraine US vaccine Visit Bali
Federal Government focuses on “integrated security”
latest news

Federal Government focuses on “integrated security”

by The Editor
June 14, 2023
0

Berlin (dpa) – The Federal Government is responding to the challenges of an increasingly unstable world order by means of a “policy...

Read more

Recent News

  • OnlyFans Platform Analysis
  • How to Day German Fashion
  • Southeast Continental Capabilities

Category

  • 1xbet Casino Russia
  • 1xbet Russian Top
  • Africa
  • Asia
  • Europe
  • Health
  • latest news
  • Latin America
  • Life Style
  • Mail Order Brides
  • Mostbet
  • Online dating
  • onlyfans
  • Pin Up
  • Pin Up Russia
  • Science
  • Sports
  • Tech
  • Uncategorized
  • USA

Recent News

OnlyFans Platform Analysis

June 12, 2024

How to Day German Fashion

May 5, 2024
  • About
  • Advertise
  • Careers
  • Contact

© 2025 JNews - Premium WordPress news & magazine theme by Jegtheme.

No Result
View All Result
  • Sports
  • USA
  • Asia
  • Health
  • Life Style
  • Tech
  • Science
  • Latin America
  • Africa
  • Europe

© 2025 JNews - Premium WordPress news & magazine theme by Jegtheme.