Old 06-18-2008, 04:10 PM Offline   #1 (permalink)



 
coolmanhiphop's Avatar
Mr. News Guy
 
Since: Nov 2007
Posts: 109,399
Rank:
Uploads: 0
eCash: $500
Thank Meter: 9973

coolmanhiphop started pushin nickels an dimescoolmanhiphop started pushin nickels an dimescoolmanhiphop started pushin nickels an dimescoolmanhiphop started pushin nickels an dimescoolmanhiphop started pushin nickels an dimescoolmanhiphop started pushin nickels an dimescoolmanhiphop started pushin nickels an dimescoolmanhiphop started pushin nickels an dimescoolmanhiphop started pushin nickels an dimescoolmanhiphop started pushin nickels an dimescoolmanhiphop started pushin nickels an dimes
Rep Power: 2076
Default Mac OS X Root Escalation Through AppleScript

An anonymous reader writes "Half the Mac OS X boxes in the world (confirmed on Mac OS X 10.4 Tiger and 10.5 Leopard) can be rooted through AppleScript: osascript -e 'tell app "ARDAgent" to do shell script "whoami"'; Works for normal users and admins, provided the normal user wasn't switched to via fast user switching. Secure? I think not." On the other hand, since this exploit seems to require physical access to the machine to be rooted, you might have some other security concerns to deal with at that point, like keeping the intruder from raiding your fridge on his way out.
Read more of this story at Slashdot.
</img>


More...
 
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Jan 10 - Israel warns Gaza of escalation Black Caesar Daily News Press 0 01-10-2009 08:24 AM
do u eat pickled lotus root or know someone who does? Eazy EL The Corner 4 09-30-2008 06:42 PM
Use an AppleScript to force a desktop picture change (Macworld.com) coolmanhiphop Feeds 0 08-15-2008 07:47 AM
What Could You Do With a Bogus Root Name Server? coolmanhiphop Feeds 0 06-01-2008 09:30 AM
Kotei = Root To All Of Problems The MVPlaya The Corner 26 10-09-2005 07:05 PM


All times are GMT -8. The time now is 09:05 PM.

Archive:


Powered by vBulletin® Version 3.8.2
Copyright ©2000 - 2019, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.3.2 © 2009, Crawlability, Inc.
Hip Hop Universe 2005-Forever