6 ms·
With physical access, one has been able to create admin accounts for as long as I can remember. - Start up the Mac whilst holding down ⌘-S. This boots the Mac
by moey 12y ago
With physical access, one has been able to create admin accounts for as long as I can remember.
- Start up the Mac whilst holding down ⌘-S. This boots the Mac into Single-User Mode and provides a method of interacting with OS X via the command-line, with full root privileges.
- Then check the filesystem to ensure there are no problems: "/sbin/fsck -fy"
- Then mount the filesystem for it to be accessible: "/sbin/mount -uw /"
- Now remove this file so OS X will re-run Setup Assistant: "rm /var/db/.AppleSetupDone"
Now just restart, and enjoy the cool introduction animation as you create your admin account.
- taumhn 12y agoIf you're paranoid enough to think someone you don't trust can have physical access to your Mac, it is possible to prevent this by setting up firmware password though. See https://support.apple.com/en-us/HT204455 https://support.apple.com/en-us/HT204455
- thudson 12y agoFirmware passwords can be bypassed by a local user with a Thunderbolt Option ROM. The 10.10.2 fix for Thunderstrike left that hole open during normal boots: https://trmm.net/Thunderstrike_FAQ#Is_Thunderstrike_fixed_in_10.10.2.3F https://trmm.net/Thunderstrike_FAQ#Is_Thunderstrike_fixed_in...
- KuchenKerze 12y agoNot possible if full disk encryption is enabled. And that is a default since a year or so.
- nothrabannosir 12y agofull disk encryption only protects you from passive snooping. If someone has physical access between two of your subsequent uses, no amount of any type of encryption will save you. Except maybe some entangled quantum bit collapsing mechanism. Maybe. Think hardware keyloggers, fake MBRs, &c. OP's trick won't work, but that's an "implementation detail;" there are plenty others that will. EDIT: to clarify; that's not what you said, it's just a common enough misconception that it's worth being explicit about, here.
- KuchenKerze 12y agoOf course keyloggers etc. are a problem. But that is a different story. A bug which can be exploited just by grabbing any device might have a larger impact on the vendors reputation. A keylogger, fake smc, whatsoever ist much more dangerous for a single person, because the attacker knows what he wants on the specific device.
- sneak 12y agoThere's have to be a hardware mod if a firmware password is enabled. It prevents booting from any other media or partition without a password.
- Archio 12y agoIsn't the idea though that with physical access, the game is already over anyway? If an intruder has physical access to your machine they will eventually be able to get to anything they want. If someone really wants to protect their data, they have to count physical access as a possibility and rely on encryption and/or remote wiping - the operating system login isn't going to do much anyway.
- Vexs 12y agoYep, physical access is total access. However, this trick falls under cool-at-school-tech-labs, I'd hope enterprise systems would do something to prevent this kind of low-level shenanigans.
- TeMPOraL 12y agoSchool tech labs are modelled after the enterprise networks, the only difference is usually a bit more competent IT staff. I'd expect most of the school-lab tricks to be directly transferable to enterprise.
- matthewmacleod 12y agoYes, but that's not really a concern. Physical access with no disk encryption is always 'vulnerable'. What's pretty bad here is that any user now has a backdoor to obtaining root privileges. That's an awful security flaw.
- praseodym 12y agoEven easier is running 'resetpassword' from Terminal in Recovery mode (boot with ⌘-R). This gets you a nice GUI tool where you can reset any account passwords. But yes, this is not possible with a firmware password or with disk encryption (FileVault) enabled.
- kpcyrd 12y agoIf I understood the article correctly, this can be exploited remotely by anybody who has managed to get a shell on the system.
- jrochkind1 12y agoIt's even worse than it seems if you talk about it as 'anybody'. Most OSX boxes are probably single user devices. But you do not normally run as root/wheel, you need sudo (sometimes through a nice GUI) for software to get root privs. It's not 'somebody' as if another person were logged into their own account. It's that malware running as you can now get root, to further compromise your system, without needing a sudo password.
- mhurron 12y agoThat's how all local exploits work.
- mattrepl 12y agoJust to clarify, this is _not_ a remote vulnerability. If it was a means to create a remote shell, then it would be. An attacker would need to first find some way to gain remote access and then could use this bug to gain root privilege.
- deleted 12y ago[deleted]
- kpcyrd 12y agoThe parent comment and some of the child comments are implying you need to be physically near the system, which doesn't seem to be true. You still need to find a way to execute code on the target system (also called "getting a shell"), but this can be done over the wire, too.
- Osiris 12y agoThe first Mac I ever got, the IT department forgot to give me admin access, so I couldn't install any software. Having never used a Mac before, it took a grand total of about 15 minutes of Googling to figure out how to boot into single user mode and give myself admin access.
- cheald 12y agoLocal privilege escalation is always bad because it means you're one malware payload or RCE away from being rooted and conscripted into someone's botnet (or worse). This isn't just a physical access concern.
- andreyf 12y agoWhat about without local privilege escalation? Is there no way for a malware payload or RCE to turn your computer into a botnet without root privileges?
- dzhiurgis 12y agoThere are advertising networks that use JavaScript on client machine do distributed computing. Is that a botnet or not?
- robbintt 12y agoDo you know where I can observe this? I'd like to review the code.
- cheald 12y agoThere certainly is, but rooting a box lets you ensure that you stuff says in place. Once a box is rooted, its owner can never really be sure they have it clean without wiping and rebuilding it.
- wyager 12y agoThere's a huge difference between physical access vulnerabilities (which are basically impossible to prevent) and local privesc vulnerabilities (which can be exploited in software).
- JorgeGT 12y agoTo exemplify, for instance, this vulnerability could be packed in a phishing mail executable giving the remote attacker root access if the user falls for the trap, no?
- guipsp 12y agoYes.
- fit2rule 12y agoIt could be packaged into any executable that someone might think about downloading off the Internet for some reason. So its really, really not good. Apple need to fix this soon, or else every OSX machine out there is going to start being targeted for misuse. This is really a powerful security bug.
- alexsop2 12y agoAbout two months or three ago I stupidly changed my password to my only account to a password I promptly forgot. I was losing it when I realized what I had done. To make matters worse, I did this change a day before our office was scheduled to move to automated backups via Time Machine. Luckily after some digging I came across this fix and was back in to my computer, albeit a little shaken up by the back door.
- 0x0 12y agoThat's not very interesting. You can do the same on a linux box, passing init=/bin/sh in the boot loader, and probably the same on windows (boot a WinPE CD or a Linux live CD with NTFS3g).
- darkarmani 12y ago> With physical access What malware requires physical access? This is a local privilege escalation to root. It's only local because you need an account on the machine to make it work, but it can be bootstrapped to a remote exploit.