Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
post hole digger
Mar 21, 2011

Zil posted:

And the initials on the comment on that line of code?

SJobs

Adbot
ADBOT LOVES YOU

Vintersorg
Mar 3, 2004

President of
the Brendan Fraser
Fan Club



Zil posted:

And the initials on the comment on that line of code?

SJobs

lmfao

Salt Fish
Sep 11, 2003

Cybernetic Crumb
I'm laughing at all the twitter plebs that are going to try this, and then forget about it, and now they have a blank root password.

Last Chance
Dec 31, 2004

Salt Fish posted:

I'm laughing at all the twitter plebs that are going to try this, and then forget about it, and now they have a blank root password.

id hope that an update from apple would fix that

RISCy Business
Jun 17, 2015

bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork
Fun Shoe
https://twitter.com/textfiles/status/935305053258125312

:stare:

Bulgogi Hoagie
Jun 1, 2012

We

Salt Fish posted:

I'm laughing at all the twitter plebs that are going to try this, and then forget about it, and now they have a blank root password.

what’s responsible disclosure

LinYutang
Oct 12, 2016

NEOLIBERAL SHITPOSTER

:siren:
VOTE BLUE NO MATTER WHO!!!
:siren:
root bypass happens to the best of us

akadajet
Sep 14, 2003

Bulgogi Hoagie posted:

what’s responsible disclosure

guy could have probably collected a nice bug bounty but instead went the comedy route and we all benefit.

LinYutang
Oct 12, 2016

NEOLIBERAL SHITPOSTER

:siren:
VOTE BLUE NO MATTER WHO!!!
:siren:
time to get grampa to learn how to run `passwd root` on his trump twitter box

Diva Cupcake
Aug 15, 2005

https://twitter.com/Viss/status/935625291749138432

akadajet posted:

guy could have probably collected a nice bug bounty but instead went the comedy route and we all benefit.
i guess apple only has a bug bounty for ios and not macos. and it's invite only.

post hole digger
Mar 21, 2011

akadajet posted:

guy could have probably collected a nice bug bounty but instead went the comedy route and we all benefit.

money cant buy you lols

Schadenboner
Aug 15, 2011

by Shine

Diva Cupcake posted:

i guess apple only has a bug bounty for ios and not macos. and it's invite only.

:lol:

akadajet
Sep 14, 2003

Diva Cupcake posted:

i guess apple only has a bug bounty for ios and not macos. and it's invite only.

lmao

post hole digger
Mar 21, 2011

Diva Cupcake posted:

i guess apple only has a bug bounty for ios and not macos. and it's invite only.

holy loly

post hole digger
Mar 21, 2011

https://twitter.com/pizen/status/935617411016826880

post hole digger
Mar 21, 2011

im overstimulated. i need a sedative.

Bulgogi Hoagie
Jun 1, 2012

We
so does it only work if you bug it out in a system settings menu first so it actually makes the empty root acc

The MUMPSorceress
Jan 6, 2012


^SHTPSTS

Gary’s Answer

All my friends think I'm a square for using hotels instead of air bnb. I can't seem to get through to them that gig economy apps are really just a platform for selecting rape victims en masse.

post hole digger
Mar 21, 2011

Bulgogi Hoagie posted:

so does it only work if you bug it out in a system settings menu first so it actually makes the empty root acc

yes

Perplx
Jun 26, 2004


Best viewed on Orgasma Plasma
Lipstick Apathy
i hope someone gets fired for this

it's just embarrassing

post hole digger
Mar 21, 2011


there are a bunch of stories like this and i dont think i could ever bring myself to use airbnb. too suspect.

Farmer Crack-Ass
Jan 2, 2001

this is me posting irl

Diva Cupcake posted:

i guess apple only has a bug bounty for ios and not macos. and it's invite only.

lmbo if i only had a twitter account i would go shove this in the face of every one of those idiots screeching "RESPONSIBLE DISCLOOOOOSUUUUURE"



also what's the usual payout for a bug bounty anyway and how reliable is it to actually get paid out? b/c i would definitely leave a few hundo on the table to massively embarrass a major corporation

Bulgogi Hoagie
Jun 1, 2012

We
zero effort privilege escalation

The MUMPSorceress
Jan 6, 2012


^SHTPSTS

Gary’s Answer

my bitter bi rival posted:

there are a bunch of stories like this and i dont think i could ever bring myself to use airbnb. too suspect.

right, and it's only the idiots who are being super obvious who are getting caught. there's plenty of ways to hide a camera that arent as conspicuous as GIANT POD ON WALL

Bulgogi Hoagie
Jun 1, 2012

We

Farmer Crack-rear end posted:

lmbo if i only had a twitter account i would go shove this in the face of every one of those idiots screeching "RESPONSIBLE DISCLOOOOOSUUUUURE"



also what's the usual payout for a bug bounty anyway and how reliable is it to actually get paid out? b/c i would definitely leave a few hundo on the table to massively embarrass a major corporation

i mean if you check the security update pages on the apple website seeming randos get CVEs all the time and they probably get paid too

Shifty Pony
Dec 28, 2004

Up ta somethin'


jfc why would you put that root vulnerability into a public tweet?

MALE SHOEGAZE posted:

imagine the sinking feeling the programmer responsible for that bug is feeling right about now

or anyone involved in the response. imagine seeing this whopper pop up on the bug tracker at 7:00 AM PST while most of the main team is probably en route to work.

it would be legitimately interesting to see a timeline of how long this took to get to the response team.

akadajet
Sep 14, 2003

Shifty Pony posted:

jfc why would you put that root vulnerability into a public tweet?

because it's funny and now apple has to clean it up

LinYutang
Oct 12, 2016

NEOLIBERAL SHITPOSTER

:siren:
VOTE BLUE NO MATTER WHO!!!
:siren:

Diva Cupcake posted:

i guess apple only has a bug bounty for ios and not macos. and it's invite only.

???? i checked their bug tracker and you can report osx issues

akadajet
Sep 14, 2003

LinYutang posted:

???? i checked their bug tracker and you can report osx issues

do they offer money though? do I have to pay money to access it?

post hole digger
Mar 21, 2011

anyone know if its possible to pipe input to a mac UAC screen via cli because i can get this to work running 'security authorizationdb write system.preferences.users allow' also

if so, i think that this can be scripted

Trabisnikof
Dec 24, 2005

my bitter bi rival posted:

anyone know if its possible to pipe input to a mac UAC screen via cli because i can get this to work running 'security authorizationdb write system.preferences.users allow' also

if so, i think that this can be scripted

can you do it with applescript?

Truga
May 4, 2014
Lipstick Apathy
whatever autohotkey alternative for mac is :v:

also, boy am i glad rn i have root account set up on all our macs, my users are dumb and one once managed to break ldap preventing anyone from logging in so now all the macs have a local root with a long password, i just hope the sploit doesn't also disable password because lol


vvv: well thank gently caress for that

Truga fucked around with this message at 23:18 on Nov 28, 2017

post hole digger
Mar 21, 2011

it wont disable an existing password if the local root acct is enabled and has one.

Shifty Pony
Dec 28, 2004

Up ta somethin'


akadajet posted:

because it's funny and now apple has to clean it up

definitely don't disagree there. this is hilarious.

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe

Zil posted:

And the initials on the comment on that line of code?

SJobs

'Ere I am, J.H.

flakeloaf posted:

sierra=high,dumb

amazing

fishmech
Jul 16, 2006

by VideoGames
Salad Prong

cis autodrag posted:

All my friends think I'm a square for using hotels instead of air bnb. I can't seem to get through to them that gig economy apps are really just a platform for selecting rape victims en masse.

hh holmes, but with an app

pseudorandom name
May 6, 2007

https://twitter.com/BAKKOOONN/status/935629381560516608

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe

Bulgogi Hoagie posted:

zero effort privilege escalation

:cmon:

effort
less
root

Trabisnikof
Dec 24, 2005


So good

https://twitter.com/InTrumpsAmerica/status/935628409908158464?s=17

Adbot
ADBOT LOVES YOU

Plorkyeran
Mar 22, 2007

To Escape The Shackles Of The Old Forums, We Must Reject The Tribal Negativity He Endorsed

Shifty Pony posted:

jfc why would you put that root vulnerability into a public tweet?

the great part about having security flaws that joe random can find is that joe random has no idea how to report a security flaw and is probably just going to tweet about it

  • Locked thread