4 ms·
Yeah that was my thought initially too but there may be invisible ways to leverage an existing root user that we're not aware of. After all, this bug exists...
by devindotcom 9y ago
Yeah that was my thought initially too but there may be invisible ways to leverage an existing root user that we're not aware of. After all, this bug exists...
- stingraycharles 9y agoThe issue is that the bug leaves a password-less root account available through other means as well. Once you try to reproduce the bug, an attacker could potentially do a remote root login without password. As such, it's very dangerous for people to try to verify and should be strongly discouraged.
- mcintyre1994 9y agoIf you have remote login enabled does root/no password not work already because of the bug? It apparently does from the login screen if you have username/password mode on, so I wouldn't be surprised if it worked over remote login by default.
- djrogers 9y agoDoes not work via ssh or screen sharing based on my testing here. Seems to require physical access to the machine.
- mcintyre1994 9y agoDoes seem to work with some software: https://mobile.twitter.com/patrickwardle/status/935639234437935105 https://mobile.twitter.com/patrickwardle/status/935639234437...
- pilsetnieks 9y agoNo, it doesn't work for remote login.
- jldugger 9y agoOn most systems, root without password isn't available remotely. Is this not true on OSX?
- jldugger 9y agoApparently, High Sierra has a 'feature' that updates hashes to a new format on login, and consequently publishes a hash where there was none before. Which pretty much disables the 'no hash, no login' policies. Ooops. Donno if that's unique to the GUI, or if a simple 'sudo su -' would also trigger, as I don't own a mac.