4 ms·
Physical access and all bets are off. This is not a vulnerability.
by x0n 12y ago
Physical access and all bets are off. This is not a vulnerability.
- dsacco 12y agoNo, but it is interesting to know methods like this. You can achieve admin on an OS X machine by adding a new one like so: 1. Enter single user mode via cmd + s during startup. 2. Mount the hard drive via /sbin/mount/ -uw / 3. Delete the setupdone check via rm /var/db/.applesetupdone 4. Reboot, and now you are presented with the wizard for adding a new admin account.
- fuzzix 12y agoI remember someone (not me, oh no...) used one for NT4 with inadequate policies to get Admin access. Create a batch file with the content: net localgroup administrators NewUser /add ...then stick this into the 'StartUp' directory for All Users. Break something. Call support. They log in as Administrator, running your batch file in the process. NewUser would be created with Admin rights. You wouldn't promote your own login, of course.
- M4v3R 12y agoOf course this is only possible if FileVault is disabled, otherwise you would not be able to mount the hard drive without user's password.
- Leszek 12y agoIn which case, why bother with user passwords at all?
- nolok 12y agoTo ward off the dummy 99%. You can't stop a guy who knows what he's doing, but you can stop Josie from the next desk snooping around in HR's file. Also, it causes a breach, which depending on where you live might be needed to show intent.
- msl09 12y agoYou do not want that binary that you have downloaded to be able to do a privilege escalation without your consent. Also, some people may feel like changing your wallpaper to something inappropriate, but they may not be motivated enough to hack your pc.
- baby 12y agoI can't remember it correctly but there is a saying along these lines: most people would open your door if there was no lock on it. Eventhough it's useless.
- daigoba66 12y agoSame reason we put locks on our doors. If someone is really serious, he or she can (destructively) break in. But a locked door will prevent someone from casually getting in.
- audunw 12y agoBIOS password lock, and physical lock on computer and/or an environment where it is hard to open the computer without being detected (work/school) makes other options hard. This exploit you could even pull off on a school lab computer while the teacher is in the room. If he comes over while you're working, inconspicuously power off the machine.
- dguido 12y agoThis is a vulnerability. This attack does not require physical access. Do you really think that startup repair mode is required to swap the position of cmd.exe and sethc.exe?
- Someone1234 12y agoThe Repair Tool requires unrestricted physical access, it is running as administrator. The same way that a Live CD could. > Do you really think that startup repair mode is required to swap the position of cmd.exe and sethc.exe? A Live CD/DVD would work just as well. As would a USB-based OS. You could also (although it would require more work) use network boot to run your own code. There's no vulnerability, this is unfixable, you just have to secure the system using full disk encryption and secure boot.
- x0n 12y agoNo, it's not, because sethc.exe resides in %systemroot%\system32 - an area that is protected by ACLs, only allowing regular users read access. Going into startup repair mode grants system-level access to files there. Without repair mode, users cannot swap these files.
- tomp 12y agoTry doing that with my phone. I think (hope?) you wouldn't succeed.
- Someone1234 12y agoYou can do this with a phone or tablet (Android). That's essentially how many root exploits are accomplished, boot into the default recovery (typically hold volume up during power on), run a script, and recovery replaces key files which are used later to provide you with root. This is less common NOW, but back in the Android 2.xx days it was the defacto way of getting root.
- utxaa 12y agoencrypting helps no? maybe not all bets are off in that case.
- diminoten 12y agoWhat? It absolutely is a vulnerability, insofar that it allows unintended access to a computer system. That's like saying, "Car door was open, therefore not theft."