Mac OS major security flaw : PSA

Discussion in 'PC Hardware, Software and Displays' started by zed, Nov 29, 2017.

  1. zed

    zed
    Veteran

    Joined:
    Dec 16, 2005
    Messages:
    4,441
    Likes Received:
    628
    Grall likes this.
  2. BRiT

    BRiT (╯°□°)╯
    Moderator Legend Alpha Subscriber

    Joined:
    Feb 7, 2002
    Messages:
    12,498
    Likes Received:
    8,701
    Location:
    Cleveland
    Some info from a Vulnerability Analyst at CERT/CC ...

    The Apple High Sierra root issue is bad. If you have exposed "Screen Sharing", you can allow people into your machine with full GUI access, using no password. Setting the root password appears to prevent this from happening.



    Apple "Remote Management" also has the same exposure. If "Control" is enabled, that gives full interactive remote root access to a system, without requiring a password.

     
    Grall and iroboto like this.
  3. iMacmatician

    Regular

    Joined:
    Jul 24, 2010
    Messages:
    773
    Likes Received:
    200
    Apple has now released a security update to fix this problem.

    This flaw was mentioned on Apple's Developer forums on November 13th 2017.
     
    #3 iMacmatician, Nov 29, 2017
    Last edited: Nov 29, 2017
    Malo and Grall like this.
  4. BRiT

    BRiT (╯°□°)╯
    Moderator Legend Alpha Subscriber

    Joined:
    Feb 7, 2002
    Messages:
    12,498
    Likes Received:
    8,701
    Location:
    Cleveland
  5. Cyan

    Cyan orange
    Legend Veteran

    Joined:
    Apr 24, 2007
    Messages:
    8,572
    Likes Received:
    2,292
    a video on the issue

     
  6. hoom

    Veteran

    Joined:
    Sep 23, 2003
    Messages:
    2,947
    Likes Received:
    495
    Thats like '80s movie level hacking stuff :runaway:
     
Loading...

Share This Page

  • About Us

    Beyond3D has been around for over a decade and prides itself on being the best place on the web for in-depth, technically-driven discussion and analysis of 3D graphics hardware. If you love pixels and transistors, you've come to the right place!

    Beyond3D is proudly published by GPU Tools Ltd.
Loading...