mercredi 29 novembre 2017

High Sierra admin login without password

Normally I'd assume that people found this themselves, but this "can" be a big deal for some people. I just found this, and it's a flaw in the current operating system. I believe the filevault is turned on by default, so it might not affect that many people, but something to look out for:

Quote:

The bypass works by putting the word "root" (without the quotes) in the user name field of a login window, moving the cursor into the password field, and then hitting enter button with the password field empty. With that—after a few tries in some cases—the latest version of Apple's operating system logs the user in with root privileges. Ars reporters were able to replicate the behavior multiple times on three Macs. The flaw isn't present on previous macOS versions.
Source


via International Skeptics Forum http://ift.tt/2zP2UT9

Aucun commentaire:

Enregistrer un commentaire