OS X Lion security flaw allows anyone to change your password
Highly rated gadgets
-
10.0
Nikon Z 7
-
8.5
Xiaomi Mi A2
-
10.0
FujiFilm X-T3
-
8.0
BlackBerry Motion
-
9.0
Sony WH-1000XM3
-
9.1
Apple iPhone XS
-
9.0
FujiFilm XF10
-
9.1
Apple iPhone XS Max
-
9.0
Panasonic LUMIX LX100 II
Security blog Defense in Depth has found a glaring security flaw in OS X Lion that enables hackers to change the password of any user on a machine running Lion. “[While] non-root users are unable to access the shadow files directly, Lion actually provides non-root users the ability to still view password hash data,” Patrick Dunstan from Defense in Depth explained in a recent blog post. The result is that anyone could use a simple Python script, created by Dunstan himself, to discover a user’s password. It gets worse. Reportedly, OS X Lion does not require its users to enter a password to change the login credentials of the current user. That means typing the command: “dscl localhost -passwd ... »read more
More at: www.bgr.com Add additional source
Filed in: Operating SystemsAppleMac OS X 10.7