Home
Posted By: Virtual1 high sierra, everyone's root! - 11/28/17 08:39 PM
https://www.macrumors.com/2017/11/28/macos-high-sierra-bug-admin-access/

and this is why I don't do "bleeding edge"
Posted By: jchuzi Re: high sierra, everyone's root! - 11/28/17 11:57 PM
Apple says fix incoming for macOS High Sierra root access bug
Posted By: pbGuy Re: high sierra, everyone's root! - 11/29/17 12:27 AM
iMore provides instructions on setting the root password, which eliminates the issue.

Link: Setting root Password
Posted By: Pendragon Re: high sierra, everyone's root! - 11/29/17 12:42 PM
Is physical access required or can Remote Access also exploit this vulnerability?
Posted By: pbGuy Re: high sierra, everyone's root! - 11/29/17 01:57 PM
Good question. ...According to the guy, who discovered this issue, physical access is required.

However, Apple details (at the Support Page linked below) that root user is disabled by default; but, if one logs in to one's Mac using an administrator account, one could enable the root user, then log in as the root user to complete a task. ...Again, I'm not sure is this could be done remotely (with administrator login password).

Here's Apple's root PW Instructions

Regardless, setting a root user password (a strong & unique one) would defeat this security issue. (My unique, root PW is a 13 alpha-numeric-character PW I'll never remember; so, I saved it to 1PW.)

I used the "Change root password" method within System Preferences (as iMore detailed wherein they advised keeping "Enable root user" - after setting root password - since subsequently disabling will delete the just-initiated password). Done. cool
Posted By: jchuzi Re: high sierra, everyone's root! - 11/29/17 04:08 PM
Apple just issued this security update for High Sierra. From the language, I'm not positive that it addresses the root user issue, but it sounds as if it might.
Posted By: pbGuy Re: high sierra, everyone's root! - 11/29/17 04:23 PM
I just completed the Security Update (no Restart required), available through Mac Apple Store update. My macOS 10.13.1 build did change to that referenced on the Support page.

Thanks for the link. ...And, I found this sentence ("If you require the root user account on your Mac, you will need to re-enable the root user and change the root user's password after this update.) about the Update, interesting as it implies the update resets the "enable root & its password." ....Hmmm. smirk
Posted By: Virtual1 Re: high sierra, everyone's root! - 11/29/17 05:01 PM
Originally Posted By: Pendragon
Is physical access required or can Remote Access also exploit this vulnerability?

Basically the problem is that before you "enable the root user", he's already there and enabled because he has to be, but can't authenticate by default if his password is blank. except for this one place that someone forgot to lock down in HS.

It does lead me to wonder though, surely they will find the person ultimately responsible for this, I wonder what will happen to them? What is the penalty for a major embarrassment?
Posted By: Virtual1 Apple to review software practices - 11/29/17 06:23 PM
https://www.reuters.com/article/us-apple...g-idUSKBN1DT2TJ
Posted By: MacManiac Re: high sierra, everyone's root! - 11/29/17 06:35 PM
Same positive result for the security update here....however, I'm fairly certain that you meant to say that the build for 13.1 did NOT show up after install.

Mine has NO build associated with the Mac OS X 10.13.1 listed under "About This Mac" under the Apple Menu.....

It DID disable the previously enabled root user....and it DID properly test to validate that the previous root bypass issue was resolved....and I was able to re-enable and disable the root user appropriately with both the Terminal and with the Directory Utility.
Posted By: pbGuy Re: high sierra, everyone's root! - 11/29/17 06:47 PM
Originally Posted By: MacManiac
...Mine has NO build associated with the Mac OS X 10.13.1 listed under "About This Mac" under the Apple Menu.....


In the "About" window, click on the version number; you'll then see the Build added.

Additionally, you could also use the Sys Info app (Utilities), click on Software. You'll also see the System Version with the Build.
Posted By: Pendragon Re: high sierra, everyone's root! - 11/29/17 11:58 PM
Apparently, today's Security Fix causes a problem with File Sharing. See this.

FWIW, I ran the fix and it seems to have worked as divined.
Posted By: tacit Re: high sierra, everyone's root! - 11/30/17 04:37 AM
Originally Posted By: Pendragon
Is physical access required or can Remote Access also exploit this vulnerability?


At first, it appeared that physical access was required. It now appears this is not the case. If a user can be tricked into running a malicious app or shell script, the malicious app or shell script can silently enable the root user and then make any changes whatsoever to the system.

You will still need to trick the user into running malicious code, however.

Posted By: MacManiac Re: high sierra, everyone's root! - 11/30/17 06:24 AM
Thanks for that....I missed the change in how About This Mac delivered info as obviously it no longer shows the build until you click on the version number.
Posted By: jchuzi Re: high sierra, everyone's root! - 11/30/17 10:30 AM
And in a related issue: Apple explains how to fix macOS High Sierra file sharing after security update breaks feature
Posted By: pbGuy Re: high sierra, everyone's root! - 11/30/17 01:57 PM
The update to the SU update is now available. ...Other than correcting the File Sharing issue, the 10.13.1 Build is now 17B1003.
Posted By: Virtual1 found it! - 11/30/17 06:30 PM
and this is where it all began, accidentally, WEEKS AGO:

https://forums.developer.apple.com/thread/79235
Posted By: pbGuy High Sierra - 11/30/17 07:31 PM
My 2¢...

While this coding episode should not have occurred and should be / is an embarrassment to Apple, IMHO, I think those using this episode to voice denigrating comments about High Sierra, are a bit over the mark. (I am not implying any posts in this Thread have done so; but, I have read such shortsighted comments elsewhere.)

Apple deserves a knock for allowing both issues (the High Sierra root vulnerability & the subsequent File Share) to get past code quality control.

Apple reacted quickly to fix both; I think that counts for something. ...Other issues will, no doubt, subsequently arise with macOS (& iOS); I have confidence Apple will be responsive in getting those quickly fixed.

I've been using High Sierra from day one. As my MBP has an SSD, I've using APFS from day one as the upgrade auto converted my drive. ...I've not had any fundamental issues (with Keychain, iCloud, Time Machine, my HS compatible apps, my total system) causing me to even consider rolling back to Sierra. Progress is going forward, not the opposite.

I'm aware some have had certain issues, and FTM is the place to seek help as the active participants are highly knowledgeable & willing to assist. But, again IMHO, I do not believe there are fundamental issues with High Sierra itself, when its installed on a hardware setup that will effectively and efficiently run High Sierra.
Posted By: Virtual1 Re: High Sierra - 11/30/17 08:16 PM
Originally Posted By: pbGuy
Apple deserves a knock for allowing both issues (the High Sierra root vulnerability & the subsequent File Share) to get past code quality control.

And don't forget the file vault storing the password in the hint recently.... there's a reason Apple is calling a meeting with their devs to "discuss recent security".
© FineTunedMac