Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
post hole digger
Mar 21, 2011


jesus loving christ

Adbot
ADBOT LOVES YOU

post hole digger
Mar 21, 2011

i just tried this and it definitely works laffo

McGlockenshire
Dec 16, 2005

GOLLOCKS!

https://twitter.com/snd_wagenseil/status/935603174093787136

Bhodi
Dec 9, 2007

Oh, it's just a cat.
Pillbug
how do you gently caress that up, how

Bulgogi Hoagie
Jun 1, 2012

We
if this works remotely (and it probably does) i’m screaming

Pardot
Jul 25, 2001




I can't get the root thing to work :smith: . I thought at first cause i'm just on sierra, but people are saying they can do it on older versions so idk

post hole digger
Mar 21, 2011

it uhhhh works from the login screen too if its set up to allow u/p fields instead of clicking the user.

Diva Cupcake
Aug 15, 2005

lol worked for me as well.

this is amazing.

McGlockenshire
Dec 16, 2005

GOLLOCKS!
if it's not working for you, see if you already have a root account, as the trick seems to be the creation of a new one

geonetix
Mar 6, 2011



lol high Sierra is a loving hug riddled poo poo os

post hole digger
Mar 21, 2011

Bulgogi Hoagie posted:

if this works remotely (and it probably does) i’m screaming

i cant seem to get it to work for remote login via ssh. messing with remote management now.

post hole digger
Mar 21, 2011

every once in a while i think about things like the packet of death thing in windows 95 or AIMbot exploits and think "man i wish computers were easily exploitable like they were when i was a kid" because everything like fuzzing and diassembly and bytecode analysis is way over my head, so the kid in me is glad to know that everything is still impossibly insecure garbage that can be broken trivially by anyone willing to poke at it long enough.

Farmer Crack-Ass
Jan 2, 2001

this is me posting irl

geonetix posted:

lol high Sierra is a loving hug riddled poo poo os

wanna get some of those hugs

geonetix
Mar 6, 2011


best typo

Ulf
Jul 15, 2001

FOUR COLORS
ONE LOVE
Nap Ghost
https://twitter.com/kateconger/status/935546501421395968

https://twitter.com/kateconger/status/935555868128452608

just read the whole thread

flakeloaf
Feb 26, 2003

Still better than android clock

sierra=high,dumb

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

flakeloaf posted:

sierra=high,dumb

holy poo poo 5

Grassy Knowles
Apr 4, 2003

"The original Terminator was a gritty fucking AMAZING piece of sci-fi. Gritty fucking rock-hard MURDER!"

this is fantastic

Meat Beat Agent
Aug 5, 2007

felonious assault with a sproinging boner

flakeloaf posted:

sierra=high,dumb

dpkg chopra
Jun 9, 2007

Fast Food Fight

Grimey Drawer
MacOS If You're Using This You Must Be High Sierra

post hole digger
Mar 21, 2011

HOLY FUCKIN poo poo IT WORKS WITH SCREEN SHARING TOO

Farmer Crack-Ass
Jan 2, 2001

this is me posting irl
rip in piss

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

High Sierra/root thing doesn't work on my system but my account for web/email is user with no sudo rights so whatever its doing can only happen from an account that can already elevate. I wonder if the people doing it with a text logon dialog already have an admin user logged in vs a clean boot with no active user sessions.

AggressivelyStupid
Jan 9, 2012

stebe...

Wiggly Wayne DDS
Sep 11, 2010



BangersInMyKnickers posted:

High Sierra/root thing doesn't work on my system but my account for web/email is user with no sudo rights so whatever its doing can only happen from an account that can already elevate. I wonder if the people doing it with a text logon dialog already have an admin user logged in vs a clean boot with no active user sessions.
there's reports of it working from a clean boot. current idea is that changing/setting your root password is what mitigates it

post hole digger
Mar 21, 2011

BangersInMyKnickers posted:

High Sierra/root thing doesn't work on my system but my account for web/email is user with no sudo rights so whatever its doing can only happen from an account that can already elevate. I wonder if the people doing it with a text logon dialog already have an admin user logged in vs a clean boot with no active user sessions.

i can do it without an active user session (eg log in as admin-level user, log out, log in as root) but havent done it with a clean boot because id have to turn off filevault and :effort:

Diva Cupcake
Aug 15, 2005

my bitter bi rival posted:

i can do it without an active user session (eg log in as admin-level user, log out, log in as root) but havent done it with a clean boot because id have to turn off filevault and :effort:
speaking of which, you can use it to disable filevault.

https://twitter.com/jonp__/status/935607120208199682

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

Oh, I bet being bound to AD is stopping it. Auths to root are probably sent to the DC instead of handled locally. Microsoft saves the day again

post hole digger
Mar 21, 2011

BangersInMyKnickers posted:

Oh, I bet being bound to AD is stopping it. Auths to root are probably sent to the DC instead of handled locally. Microsoft saves the day again

our macs are bound to AD and thats not the case here.

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

well then I have no idea but clearly I am better at security than the normal Mac user

post hole digger
Mar 21, 2011

is it possible the root user is enabled/has a password set already? we don't do that here and that is apparently the mitigation for this

Tunicate
May 15, 2012

my bitter bi rival posted:

every once in a while i think about things like the packet of death thing in windows 95 or AIMbot exploits and think "man i wish computers were easily exploitable like they were when i was a kid" because everything like fuzzing and diassembly and bytecode analysis is way over my head, so the kid in me is glad to know that everything is still impossibly insecure garbage that can be broken trivially by anyone willing to poke at it long enough.

yeah this is some classic era poo poo

username 'field' password 'service'

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

my bitter bi rival posted:

is it possible the root user is enabled/has a password set already? we don't do that here and that is apparently the mitigation for this

yep, that was it. it support nerds enabled root, hid it, and gave it a different displayname

akadajet
Sep 14, 2003

I thought the mac thing was a hoax until I tried it. Took about 20 times but lmao.

CKyle
Jan 15, 2008
I think it only works for logins if you reproduce it from the Users & Groups first. the first time you succeed it makes a root account with blank password that didn't exist before

so don't reproduce or if you must, change your root password immediately

DONT THREAD ON ME
Oct 1, 2002

by Nyc_Tattoo
Floss Finder
imagine the sinking feeling the programmer responsible for that bug is feeling right about now

post hole digger
Mar 21, 2011

CKyle posted:

I think it only works for logins if you reproduce it from the Users & Groups first. the first time you succeed it makes a root account with blank password that didn't exist before

so don't reproduce or if you must, change your root password immediately

I had that thought too and believe it. fortunately we only have a handful of high Sierra macs around so I couldn't try to reproduce it on another device.

Zil
Jun 4, 2011

Satanically Summoned Citrus


MALE SHOEGAZE posted:

imagine the sinking feeling the programmer responsible for that bug is feeling right about now

And the initials on the comment on that line of code?

SJobs

CKyle
Jan 15, 2008

my bitter bi rival posted:

I had that thought too and believe it. fortunately we only have a handful of high Sierra macs around so I couldn't try to reproduce it on another device.

I did a little dance with disabling root, trying to log in as root, failing, reproducing the bug in prefs, succeeding at logging in as root. looks like some macrumors people figured out the same thing

Adbot
ADBOT LOVES YOU

mrmcd
Feb 22, 2003

Pictured: The only good cop (a fictional one).

Zil posted:

And the initials on the comment on that line of code?

SJobs

  • Locked thread