Welcome Guest ( Log In | Register )

Outline · [ Standard ] · Linear+

 MacOS bug, Lets You Create a Root Account

views
     
TScroomaniac
post Nov 29 2017, 09:54 AM, updated 9y ago

Getting Started
**
Junior Member
269 posts

Joined: Jan 2003


QUOTE
A bug in the latest versions of macOS High Sierra allows users to create a root account with no password by repeatedly pressing a button in the preferences panel.

The only way an attacker could exploit this bug is if the macOS owner left his Mac unlocked and then left his desk.



This is all an attacker needs because with a few clicks he can create a root account that he could use at a later time to access the vulnerable device. The root account can also be used to log into the vulnerable machine remotely.

How the bug works!
Step 1: Open the macOS system preferences window
Step 2: Go to Users & Groups
Step 3: Click the lock icon in the bottom-left corner of the window
Step 4: Type "root" in the username field
Step 5: Place the cursor in the password field
Step 6: Press the Unlock button repeatedly until the user is created
These steps will create a root account on the computer with no password. An attacker could use this account at a later time to legitimately log into a victim's Mac.

The bug affects macOS High Sierra 10.13.1 and 10.13.2 Beta. Users can prevent an attacker from exploiting a bug by creating a "root" account themselves and giving it a custom password. This blocks the bug from creating another root account.

Turkish software developer Lemi Orhan Ergin discovered and tweeted about the bug earlier today. Many other macOS users independently confirmed the issue. Apple is aware of the bug and working on a patch.


Sos

MyPIA
post Nov 29 2017, 05:09 PM

Getting Started
**
Junior Member
178 posts

Joined: May 2013
From: KL/Selangor


I just tried following these steps and it worked. I wonder when will Apple patch this.
TScroomaniac
post Nov 29 2017, 06:32 PM

Getting Started
**
Junior Member
269 posts

Joined: Jan 2003


I tried it too and it worked. macOS High Sierra 10.13.1
piscesguy
post Dec 12 2017, 09:34 AM

私の名前はりゅうです
*******
Senior Member
3,965 posts

Joined: Nov 2006
i have error downloading 10.13.2

anyone experience this?

 

Change to:
| Lo-Fi Version
0.0441sec    0.30    5 queries    GZIP Disabled
Time is now: 21st December 2025 - 03:04 AM