ITPRO

Printed from www.itpro.co.uk

Register to receive our regular email newsletter at http://www.itpro.co.uk/reg/register.

The newsletter contains links to our latest IT news, product reviews, features and how-to guides, plus special offers and competitions.

Skip to navigation

    Mac OS X Lion password-changing flaw uncovered

Changing passwords looks awfully simple for anyone who has acquired access to a Mac OS X Lion machine.

By Tom Brewster, 26 May 2012 at 05:34

Password

A flaw in Apple’s new OS lets those with access to a Mac running Lion change passwords without knowing the user’s login details, a researcher has claimed.

In previous versions of the Apple OS, users wanting to change passwords had to enter their login information before making alterations.

Why crack hashes when you can just change the password directly?

Now that step is not needed, thanks to insecure permissions in the Mac OS X Lion’s local directory service, researcher Patrick Dunstan said, writing on the Defense in Depth blog.

“Why crack hashes when you can just change the password directly?” Dunstan said. “It appears Directory Services in Lion no longer requires authentication when requesting a password change for the current user.”

Dunstan also claimed it was possible to access other users’ password hashes and therefore steal their login information.

In previous versions of Mac OS X, only those with root access were allowed to view so-called shadow files, which contain hashes and salts used to encrypt passwords.

Although non-root users cannot access the shadow file directly, they can still gain access to information in it by extracting data from the directory services on the OS. All that needs to be done is type in the right command into Terminal to get that information, the researcher claimed.

“The interesting thing about this? Root privileges are not required,” Dunstan added. “All users on the system, regardless of privilege, have the ability to access the ShadowHashData attribute from any other user's profile.”

A brute force attack could be used to crack passwords once the hash and salt are acquired.

Comments on the blog showed some claiming to have exploited the flaw successfully, whilst others were unable to do so.

At the time of publication, Apple had not responded to a request for comment on the alleged vulnerability.

Email to a friend

Print this page

< Previous   Unified Threat Management : News

Be the first to comment on this article

You need to Login or Register to comment.

    You may also like...

 Sponsored Links

advertisement

    You may also like...

    Latest Unified Threat Management Analysis & Insight

computer security

Business of IT: Building a business case for security

Security can be both the unseen hero and the weakest link in an organisation, so how do you make the case to spend enough to protect your organisation's most vital assets? Stephen Pritchard investigates...

Read more

 

    Latest Unified Threat Management Reviews

Netgear ProSecure UTM150

Rating: 5

Netgear is better known for its network routers and switches than its security appliances. Karl Wright takes a look under the hood of the ProSecure UTM150 to see if the new unified threat management appliance is right for you.

Read more

 
advertisement

    Register for IT PRO

You'll get exclusive member benefits including free whitepapers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.

Sponsored Links
Advertisement