The Notebook Review forums were hosted by TechTarget, who shut down them down on January 31, 2022. This static read-only archive was pulled by NBR forum users between January 20 and January 31, 2022, in an effort to make sure that the valuable technical information that had been posted on the forums is preserved. For current discussions, many NBR forum users moved over to NotebookTalk.net after the shutdown.
Problems? See this thread at archive.org.

    Heads Up! Apple OSX (Yosemite/Mavericks/MountainLion) flaw allows full (root) takeover

    Discussion in 'Apple and Mac OS X' started by KernalPanic, Nov 5, 2014.

  1. KernalPanic

    KernalPanic White Knight

    Reputations:
    2,125
    Messages:
    1,934
    Likes Received:
    130
    Trophy Points:
    81
    Heads up people!

    I'd like to point out that this security flaw is not officially confirmed, but the fact Apple has asked the security company to not publish the flaw until Jan 2015 makes it pretty likely to be true.

    If this is true, it is a complete security failure. While panic is not advised, it most certainly should concern any and all 10.8,10.9, and 10.10 users.

    I advise reading
    OS X Yosemite Flaw Leaves Macs Open to Hacker Takeover

    The source above identifies two ways to help slow or mitigate such flaws:

    -Do NOT log in under an administrative account unless you need it. Use a standard user account for browsing the web and reading e-mail.
    (this is wise under any operating system)

    -Encrypt files (Filevault will work) so as not to give an attacker an easy time. This does not stop an attacker, but it does slow them down.


    Note that just because one security group decided to keep it under wraps does NOT mean that others have not discovered this.
    Here's hoping Apple moves quickly on something like this.
     
  2. Jarhead

    Jarhead 恋の♡アカサタナ

    Reputations:
    5,036
    Messages:
    12,168
    Likes Received:
    3,134
    Trophy Points:
    681
    KernalPanic likes this.
  3. saturnotaku

    saturnotaku Notebook Nobel Laureate

    Reputations:
    4,879
    Messages:
    8,926
    Likes Received:
    4,707
    Trophy Points:
    431
    In looking at a few other articles, there seems to be conflicting information as to whether or not this exploit affects Mavericks (10.9). I've got non-admin accounts set up anyway, but it would be nice to have clarification.
     
  4. KernalPanic

    KernalPanic White Knight

    Reputations:
    2,125
    Messages:
    1,934
    Likes Received:
    130
    Trophy Points:
    81
    The first article confirms it works on 10.8, 10.9 and 10.10, so yes.
    It takes slight modifications in the script, but works.