Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search

TheBlackAdder

(28,203 posts)
Tue Nov 28, 2017, 11:15 PM Nov 2017

Pro tip: You can log into macOS High Sierra 10.13 as root with no password

.


Security Pro tip: You can log into macOS High Sierra as root with no password
Apple, this is Windows 95 bad – but there is a workaround to kill the bug


Updated A trivial-to-exploit flaw in macOS High Sierra, aka macOS 10.13, allows users to gain admin rights, or log in as root, without a password.

The security bug can be triggered via the authentication dialog box in Apple's operating system, which prompts you for an administrator's username and password when you need to do stuff like configure privacy and network settings.

If you type in "root" as the username, leave the password box blank, hit "enter" and then click on unlock a few times, the prompt disappears and, congrats, you now have admin rights. You can do this from the user login screen.



More at the jump, including the remediation fix:

https://www.theregister.co.uk/2017/11/28/root_access_bypass_macos_high_sierra/

.
5 replies = new reply since forum marked as read
Highlight: NoneDon't highlight anything 5 newestHighlight 5 most recent replies
Pro tip: You can log into macOS High Sierra 10.13 as root with no password (Original Post) TheBlackAdder Nov 2017 OP
Oooops!!! hexola Nov 2017 #1
Qubes OS and Purism OS are looking better every day. TheBlackAdder Nov 2017 #2
Not possible greeny2323 Nov 2017 #3
What's also fake: Apple says it can be done via remote access, screen sharing, command line, malware TheBlackAdder Nov 2017 #4
Maybe better try area51 Nov 2017 #5
Latest Discussions»General Discussion»Pro tip: You can log into...