4 ms·
Is a hidden account in macOS considered a feature?
In July 2020, a co-worker and I discovered that hidden accounts could be created in MacOS in a very low-tech manner. In such a manner that they do not appear in the GUI and neither appear to the command-line `dscl . -list /Users` command. Though I haven't tried this on the latest MacOS iteration, I do know that it works on many MacOS iterations and likely goes back to the early days of OS X.
I submitted this to Apple in 2020. They told me that it is not being considered a vulnerability. (I guess that means it is a feature.)
In my proof of concept to Apple, I demonstrated two types of attacks.
(1) A supply-chain attack where the account(s) could be created and be accompanied by payloads prior to adding any corporate profiles, drive encryption, and/or additional security features and the account could be accessed after these features were added.
(2) A compromise of a Mac that was already configured.
I am well beyond any non-disclosure and am looking for opinions on whether this should be considered a vulnerability before sharing further.
Note: I am aware of some documented methods of hiding accounts on MacOS and OS X, but I have never seen this method demonstrated.
-Snakeroot
- snakeroot 3y agoThis is a quick and dirty demo just to show proof of concept. https://youtu.be/oQw4x8Hn31I https://youtu.be/oQw4x8Hn31I
- codetrotter 3y agoDoes not seem significantly different from creating any other account using the command line instead. There are very many accounts on a macOS system already, none of which show up in the GUI. Probably macOS chooses to show users in the GUI only if they have a uid in a certain range and their home directory in /Users. Which is why your user “disappears” when you change the uid and the home directory in your video. Also, you said in another comment that it does not require admin privileges. But then you use the GUI to add a user, with the settings lock unlocked. That’s an admin action. Regular users without admin privileges are not able to create new users. What you are demonstrating is not an attack. This is just a quirk of how macOS chooses to present certain user accounts in the GUI and other accounts not.
- deleted 3y ago[deleted]
- neximo64 3y agoYes this is quite standard for an OS. You might want to create a user that has access to some things but isnt as annoying as you could log into it. The other way to look at it is its annoying to have an account show up on the screen that you want specifically for machine purposes or to restrict the user. Or to hide the Admin user if it is in an enterprise network. I'm assuming your 'attack' requires admin privileges, to create the account? I dont think that can be considered a vulnerability, it is almost doing exactly as expected.
- snakeroot 3y agoNo, the attack does not require admin. I demonstrated that two Apple as well.
- tssva 3y agoCreating users and groups in macOS requires administrator permissions. In the demo video you posted before creating the account you unlock the User settings panel using credentials of someone with administrator privileges.
- snakeroot 3y agoMore details added to the post about creating without any account access.
- snakeroot 3y agoTo clarify, there are two stages. The video included in the comment is just a proof of concept that MacOS will hide the account beginning with a period. In that demo, I was admin. In the demo to Apple, I demonstrated creating a new admin account that was hidden while I did not have admin access, but did have physical access to the device.
- tssva 3y agoTechnically when you boot to single user mode you are operating with admin permissions. But it is a technicality which really isn't relevant to the discussion. If someone has physical access to your device and can access single user/recovery mode then you are screwed to start with. This applies across macOS, Linux and Windows. Adding a hidden account is one of a long laundry list of exploits which can be accomplished in these modes. If you are concerned about these then you should apply a boot time password. Apple recommends doing just this help prevent single mode exploits. If you are concerned about supply chain attacks prior to receiving the device then you should be wiping the machine and reinstalling the OS prior to use. This is exactly what many organizations do.
- snakeroot 3y agoNotes added to demonstrate non-admin creation of the hidden account. 1. Force Mac to boot in "single user mode" (holding COMMAND-S at startup) 2. Command: df - to determine which volume is the system volume 3. Command: mount -uw /dev/[volume] - to permit read/write access to system volume 4. Command: rm private/var/db/.applesetupdone - to force Mac to initiate setup process on reboot 5. Command: reboot - force reboot from "single user mode" command line 6. Wait for Apple setup assistant process to initiate. Skip any unnecessary steps 7. When prompted to create username, create user as .[username] - ._localized may be an example of obfuscation (best practice, change the User ID to ensure there is not a conflict) 8. Open System Preferences, select Sharing and enable "remote login" 9. Note the IP address of the target computer from Network Preferences OR using Command: ifconfig from Terminal 10. Reboot 11. The login screen now appears with no indication of hidden admin account or that the computer had been modified 12. The attacker may now use the attack machine to open terminal and enter "ssh ._localized@[target.ip.address]" and login via shell 13. The attacker may now perform any commands he/she wishes and can navigate to the target user's files and perform full exfiltration of data using a variety of widely documented tools 14. An example of gaining access could be using "sudo chmod -R 777 *" to make the target user's files accessible 15. The attacker has full access at this point, closing the computer (if a laptop) may even keep the connection active while the computer appears to be in sleep mode.
- codetrotter 3y ago> 1. Force Mac to boot in "single user mode" (holding COMMAND-S at startup) If you have physical access to the computer and they do not have disk encryption (FileVault on macOS) enabled then all bets are off anyways.
- snakeroot 3y agoTrue. However, if this is performed in the supply chain and made to appear after like it had never been configured (by removing the .applesetupdone), then the computer would be fully compromised before any encryption is applied.
- neximo64 3y ago
- 2Gkashmiri 3y agocan you use a macbook (m1 for example) without signing up to an apple account or logging in to one?
- codetrotter 3y agoYes. You can use all macOS systems without signing into iCloud.