Jump to content

[UNPATCHED] Major Apple security flaw grants admin access on macOS High Sierra without password

ItsMitch

PSA: Upgrading to macOS 10.13.1 will undo Apple’s patch for critical root vulnerability

 

@djdwosk97 thanks for letting us know!!

 

 

 

 

PREFACE; I don't know MUCH about Apple, I just use an iPhone every now and then, thank fuck I don't own a Mac.

Story went live from a guy on twitter who goes by Lemi Orhan Ergin, a security expert I guess found a huge flaw in the Apple Mac OS 10.13.1, 

Quote

 

There seems to be a major flaw in Apple’s macOS High Sierra operating system that allows anyone to log into a machine and gain system administrator access without so much as entering a password. The vulnerability was publicly disclosed on Twitter this afternoon; it’s not clear whether the problem was privately reported to Apple ahead of time, which is the encouraged practice when security vulnerabilities are uncovered. (The company maintains an invite-only bug bounty program)

 

 

 

Apple hasn't yet responded to comments from The Verge which I doubt that they'll respond really. Seems like they dun goofed, no idea why they only do an invite-only bug bounty program seems bit strange to me. Oh this can only be done on local systems it seems so if your laptop gets stolen, hackers can use this to punch into your system. 

 

 

His series of tweets:

 
Apple submitted a response to news outlets reporting the problem and issued the following: 
Quote

 

An Apple spokesperson said in an emailed statement: "We are working on a software update to address this issue. In the meantime, setting a root password prevents unauthorized access to your Mac. To enable the Root User and set a password, please follow the instructions here: https://support.apple.com/en-us/HT204012. If a Root User is already enabled, to ensure a blank password is not set, please follow the instructions from the ‘Change the root password’ section."

 

 

 

 

@hey_yo_ quick fix, can't quote properly, srry

Here's a quick fix to the vulnerability as per CNET's article https://www.cnet.com/how-to/how-to-fix-the-macos-high-sierra-password-bug/ 

  • Click the Apple logo in the menu bar and select System Preferences (or search for it in Spotlight).
  • Click Users & Groups.
  • Click the padlock icon in the lower-left corner.
  • Enter the password for your username.
  • Click Login Options.
  • Click Join or Edit next to Network Account Server.
  • Click Open Directory Utility…
  • Click the padlock icon in the lower-left corner and enter your password once more.
  • In the menu bar, click Edit and select Enable Root User. If root user is already enabled, click Change Root Password…
  • Enter a secure password and enter it a second time to verify.
  • Click OK to finish.

Once you've set a root password, the exploit will no longer work. However, if you disable the root user before Apple issues a patch for High Sierra, it will cause the bug to work again.

 

Apple has finally released a security patch to resolve this "logic error" at 8 am, this update will be pushed out later today if you didn't get it.

Statement from Apple

Quote

 

Security is a top priority for every Apple product, and regrettably, we stumbled with this release of macOS.

When our security engineers became aware of the issue Tuesday afternoon, we immediately began working on an update that closes the security hole. This morning, as of 8:00 a.m., the update is available for download, and starting later today it will be automatically installed on all systems running the latest version (10.13.1) of macOS High Sierra.

We greatly regret this error and we apologize to all Mac users, both for releasing with this vulnerability and for the concern it has caused. Our customers deserve better. We are auditing our development processes to help prevent this from happening again

 

 

 

Sources: Thanks to Corin on ShareX's discord for bringing this up |  https://www.theverge.com/2017/11/28/16711782/apple-macos-high-sierra-critical-password-security-flaw

Link to comment
Share on other sites

Link to post
Share on other sites

Quote

Anyone can login as "root" with empty password after clicking on login button several times.

They said insanity was doing the same thing over and over and expecting a different result

They thought wrong xD

Solve your own audio issues  |  First Steps with RPi 3  |  Humidity & Condensation  |  Sleep & Hibernation  |  Overclocking RAM  |  Making Backups  |  Displays  |  4K / 8K / 16K / etc.  |  Do I need 80+ Platinum?

If you can read this you're using the wrong theme.  You can change it at the bottom.

Link to comment
Share on other sites

Link to post
Share on other sites

4 minutes ago, Ryan_Vickers said:

They said insanity was doing the same thing over and over and expecting a different result

They thought wrong xD

We don't talk about that game, but we do talk about that game's villain.

Cor Caeruleus Reborn v6

Spoiler

CPU: Intel - Core i7-8700K

CPU Cooler: be quiet! - PURE ROCK 
Thermal Compound: Arctic Silver - 5 High-Density Polysynthetic Silver 3.5g Thermal Paste 
Motherboard: ASRock Z370 Extreme4
Memory: G.Skill TridentZ RGB 2x8GB 3200/14
Storage: Samsung - 850 EVO-Series 500GB 2.5" Solid State Drive 
Storage: Samsung - 960 EVO 500GB M.2-2280 Solid State Drive
Storage: Western Digital - Blue 2TB 3.5" 5400RPM Internal Hard Drive
Storage: Western Digital - BLACK SERIES 3TB 3.5" 7200RPM Internal Hard Drive
Video Card: EVGA - 970 SSC ACX (1080 is in RMA)
Case: Fractal Design - Define R5 w/Window (Black) ATX Mid Tower Case
Power Supply: EVGA - SuperNOVA P2 750W with CableMod blue/black Pro Series
Optical Drive: LG - WH16NS40 Blu-Ray/DVD/CD Writer 
Operating System: Microsoft - Windows 10 Pro OEM 64-bit and Linux Mint Serena
Keyboard: Logitech - G910 Orion Spectrum RGB Wired Gaming Keyboard
Mouse: Logitech - G502 Wired Optical Mouse
Headphones: Logitech - G430 7.1 Channel  Headset
Speakers: Logitech - Z506 155W 5.1ch Speakers

 

Link to comment
Share on other sites

Link to post
Share on other sites

And I thought it was already ready to by pass user login password on Mac... Thanks for making it easier guys!

 

Dear Apple,

 

You rock.

 

Best Wishes, and Warmest Regards...

Link to comment
Share on other sites

Link to post
Share on other sites

1 minute ago, ARikozuM said:

We don't talk about that game, but we do talk about that game's villain.

I'm pretty sure that quote predates Far Cry 3 xD

Solve your own audio issues  |  First Steps with RPi 3  |  Humidity & Condensation  |  Sleep & Hibernation  |  Overclocking RAM  |  Making Backups  |  Displays  |  4K / 8K / 16K / etc.  |  Do I need 80+ Platinum?

If you can read this you're using the wrong theme.  You can change it at the bottom.

Link to comment
Share on other sites

Link to post
Share on other sites

At least an easy fix would be giving root a password

I have a cue light I can use to show you when I’m joking, if you like.

 

Link to comment
Share on other sites

Link to post
Share on other sites

9 minutes ago, Ryan_Vickers said:

I'm pretty sure that quote predates Far Cry 3 xD

As long as you don't talk about that game. ;)

Cor Caeruleus Reborn v6

Spoiler

CPU: Intel - Core i7-8700K

CPU Cooler: be quiet! - PURE ROCK 
Thermal Compound: Arctic Silver - 5 High-Density Polysynthetic Silver 3.5g Thermal Paste 
Motherboard: ASRock Z370 Extreme4
Memory: G.Skill TridentZ RGB 2x8GB 3200/14
Storage: Samsung - 850 EVO-Series 500GB 2.5" Solid State Drive 
Storage: Samsung - 960 EVO 500GB M.2-2280 Solid State Drive
Storage: Western Digital - Blue 2TB 3.5" 5400RPM Internal Hard Drive
Storage: Western Digital - BLACK SERIES 3TB 3.5" 7200RPM Internal Hard Drive
Video Card: EVGA - 970 SSC ACX (1080 is in RMA)
Case: Fractal Design - Define R5 w/Window (Black) ATX Mid Tower Case
Power Supply: EVGA - SuperNOVA P2 750W with CableMod blue/black Pro Series
Optical Drive: LG - WH16NS40 Blu-Ray/DVD/CD Writer 
Operating System: Microsoft - Windows 10 Pro OEM 64-bit and Linux Mint Serena
Keyboard: Logitech - G910 Orion Spectrum RGB Wired Gaming Keyboard
Mouse: Logitech - G502 Wired Optical Mouse
Headphones: Logitech - G430 7.1 Channel  Headset
Speakers: Logitech - Z506 155W 5.1ch Speakers

 

Link to comment
Share on other sites

Link to post
Share on other sites

The newest version of Mac OS X I use is 10.11 El Capitan, so I guess I'm fine. 

Main System: Phobos

AMD Ryzen 7 2700 (8C/16T), ASRock B450 Steel Legend, 16GB G.SKILL Aegis DDR4 3000MHz, AMD Radeon RX 570 4GB (XFX), 960GB Crucial M500, 2TB Seagate BarraCuda, Windows 10 Pro for Workstations/macOS Catalina

 

Secondary System: York

Intel Core i7-2600 (4C/8T), ASUS P8Z68-V/GEN3, 16GB GEIL Enhance Corsa DDR3 1600MHz, Zotac GeForce GTX 550 Ti 1GB, 240GB ADATA Ultimate SU650, Windows 10 Pro for Workstations

 

Older File Server: Yet to be named

Intel Pentium 4 HT (1C/2T), Intel D865GBF, 3GB DDR 400MHz, ATI Radeon HD 4650 1GB (HIS), 80GB WD Caviar, 320GB Hitachi Deskstar, Windows XP Pro SP3, Windows Server 2003 R2

Link to comment
Share on other sites

Link to post
Share on other sites

3 minutes ago, TARS said:

At least an easy fix would be giving root a password

My mother has a iPhone 7 with TouchID... She didn't want to set a passcode nor use TouchID as it "would take too long". 

 

And before you ask: My mother wouldn't listen to me even if I were her pets' veterinarian. 

Cor Caeruleus Reborn v6

Spoiler

CPU: Intel - Core i7-8700K

CPU Cooler: be quiet! - PURE ROCK 
Thermal Compound: Arctic Silver - 5 High-Density Polysynthetic Silver 3.5g Thermal Paste 
Motherboard: ASRock Z370 Extreme4
Memory: G.Skill TridentZ RGB 2x8GB 3200/14
Storage: Samsung - 850 EVO-Series 500GB 2.5" Solid State Drive 
Storage: Samsung - 960 EVO 500GB M.2-2280 Solid State Drive
Storage: Western Digital - Blue 2TB 3.5" 5400RPM Internal Hard Drive
Storage: Western Digital - BLACK SERIES 3TB 3.5" 7200RPM Internal Hard Drive
Video Card: EVGA - 970 SSC ACX (1080 is in RMA)
Case: Fractal Design - Define R5 w/Window (Black) ATX Mid Tower Case
Power Supply: EVGA - SuperNOVA P2 750W with CableMod blue/black Pro Series
Optical Drive: LG - WH16NS40 Blu-Ray/DVD/CD Writer 
Operating System: Microsoft - Windows 10 Pro OEM 64-bit and Linux Mint Serena
Keyboard: Logitech - G910 Orion Spectrum RGB Wired Gaming Keyboard
Mouse: Logitech - G502 Wired Optical Mouse
Headphones: Logitech - G430 7.1 Channel  Headset
Speakers: Logitech - Z506 155W 5.1ch Speakers

 

Link to comment
Share on other sites

Link to post
Share on other sites

7 minutes ago, ARikozuM said:

And before you ask: My mother wouldn't listen to me even if I were her pets' veterinarian. 

Considered buying a really ill pet and having no vets around?

Link to comment
Share on other sites

Link to post
Share on other sites

Just now, SC2Mitch said:

Considered buying a really ill pet and having no vets around?

I'm saying that she wouldn't listen to me even though I'm licensed and board-certified. 

 

#MothersKnowBest

Cor Caeruleus Reborn v6

Spoiler

CPU: Intel - Core i7-8700K

CPU Cooler: be quiet! - PURE ROCK 
Thermal Compound: Arctic Silver - 5 High-Density Polysynthetic Silver 3.5g Thermal Paste 
Motherboard: ASRock Z370 Extreme4
Memory: G.Skill TridentZ RGB 2x8GB 3200/14
Storage: Samsung - 850 EVO-Series 500GB 2.5" Solid State Drive 
Storage: Samsung - 960 EVO 500GB M.2-2280 Solid State Drive
Storage: Western Digital - Blue 2TB 3.5" 5400RPM Internal Hard Drive
Storage: Western Digital - BLACK SERIES 3TB 3.5" 7200RPM Internal Hard Drive
Video Card: EVGA - 970 SSC ACX (1080 is in RMA)
Case: Fractal Design - Define R5 w/Window (Black) ATX Mid Tower Case
Power Supply: EVGA - SuperNOVA P2 750W with CableMod blue/black Pro Series
Optical Drive: LG - WH16NS40 Blu-Ray/DVD/CD Writer 
Operating System: Microsoft - Windows 10 Pro OEM 64-bit and Linux Mint Serena
Keyboard: Logitech - G910 Orion Spectrum RGB Wired Gaming Keyboard
Mouse: Logitech - G502 Wired Optical Mouse
Headphones: Logitech - G430 7.1 Channel  Headset
Speakers: Logitech - Z506 155W 5.1ch Speakers

 

Link to comment
Share on other sites

Link to post
Share on other sites

Time to head to my nearest Apple store and cause some mischief :ph34r: 

System Specs:

CPU: Ryzen 7 5800X

GPU: Radeon RX 7900 XT 

RAM: 32GB 3600MHz

HDD: 1TB Sabrent NVMe -  WD 1TB Black - WD 2TB Green -  WD 4TB Blue

MB: Gigabyte  B550 Gaming X- RGB Disabled

PSU: Corsair RM850x 80 Plus Gold

Case: BeQuiet! Silent Base 801 Black

Cooler: Noctua NH-DH15

 

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

1 hour ago, ARikozuM said:

My mother has a iPhone 7 with TouchID... She didn't want to set a passcode nor use TouchID as it "would take too long". 

 

And before you ask: My mother wouldn't listen to me even if I were her pets' veterinarian. 

Far more likely then doing a bios update for Intel processors 

I have a cue light I can use to show you when I’m joking, if you like.

 

Link to comment
Share on other sites

Link to post
Share on other sites

The issue doesn't exist in El Capitan, and presumably not in Sierra.....so ummm, how exactly did it show up in High Sierra....watcha doing Apple.

PSU Tier List | CoC

Gaming Build | FreeNAS Server

Spoiler

i5-4690k || Seidon 240m || GTX780 ACX || MSI Z97s SLI Plus || 8GB 2400mhz || 250GB 840 Evo || 1TB WD Blue || H440 (Black/Blue) || Windows 10 Pro || Dell P2414H & BenQ XL2411Z || Ducky Shine Mini || Logitech G502 Proteus Core

Spoiler

FreeNAS 9.3 - Stable || Xeon E3 1230v2 || Supermicro X9SCM-F || 32GB Crucial ECC DDR3 || 3x4TB WD Red (JBOD) || SYBA SI-PEX40064 sata controller || Corsair CX500m || NZXT Source 210.

Link to comment
Share on other sites

Link to post
Share on other sites

2 hours ago, ARikozuM said:

My mother has a iPhone 7 with TouchID... She didn't want to set a passcode nor use TouchID as it "would take too long". 

 

And before you ask: My mother wouldn't listen to me even if I were her pets' veterinarian. 

I only have a pass-code thing because I haven't worked out how to turn it off on android.  For years I never had a code or swipe pattern.  If I lose my phone the only thing people will find out that they might not have already known is that I occasionally send my wife dirty txt's.

Grammar and spelling is not indicative of intelligence/knowledge.  Not having the same opinion does not always mean lack of understanding.  

Link to comment
Share on other sites

Link to post
Share on other sites

32 minutes ago, Septimus said:

DrMacintosh countdown bet anyone?

inb4 "Apple's resources are spread thin because of all the things they did this year" applelogetic excuse 

One day I will be able to play Monster Hunter Frontier in French/Italian/English on my PC, it's just a matter of time... 4 5 6 7 8 9 years later: It's finally coming!!!

Phones: iPhone 4S/SE | LG V10 | Lumia 920 | Samsung S24 Ultra

Laptops: Macbook Pro 15" (mid-2012) | Compaq Presario V6000

Other: Steam Deck

<>EVs are bad, they kill the planet and remove freedoms too some/<>

Link to comment
Share on other sites

Link to post
Share on other sites

20 minutes ago, mr moose said:

I only have a pass-code thing because I haven't worked out how to turn it off on android.  For years I never had a code or swipe pattern.  If I lose my phone the only thing people will find out that they might not have already known is that I occasionally send my wife dirty txt's.

You should be able to just set "none" as a type of pin in the list that offers password, pin, swipe pattern, etc.

That is, unless you have encryption turned on.  I would assume it needs some sort of code to use that, and it's on by default now so keep that in mind.

Solve your own audio issues  |  First Steps with RPi 3  |  Humidity & Condensation  |  Sleep & Hibernation  |  Overclocking RAM  |  Making Backups  |  Displays  |  4K / 8K / 16K / etc.  |  Do I need 80+ Platinum?

If you can read this you're using the wrong theme.  You can change it at the bottom.

Link to comment
Share on other sites

Link to post
Share on other sites

1 minute ago, Ryan_Vickers said:

You should be able to just set "none" as a type of pin in the list that offers password, pin, swipe pattern, etc.

That is, unless you have encryption turned on.  I would assume it needs some sort of code to use that, and it's on by default now so keep that in mind.

cheers.

Grammar and spelling is not indicative of intelligence/knowledge.  Not having the same opinion does not always mean lack of understanding.  

Link to comment
Share on other sites

Link to post
Share on other sites

Best security around!  Who would ever seriously guess that a password was no password at all...

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now


×