Jump to content

Huge root access bug in High Sierra


Recommended Posts

A new flaw was discovered in High Sierra a few hours ago.

It's a devastating bug enabling access to catastrophic vulnerabilities.

Basically anyone can login as root with a blank password.

 

Here's Apple's statement

 

“We are working on a software update to address this issue. In the meantime, setting a root password prevents unauthorized access to your Mac. To enable the Root User and set a password, please follow the instructions here. If a Root User is already enabled, to ensure a blank password is not set, please follow the instructions from the ‘Change the root password’ section.”

 

Here's a quick rundown of how to create a password:

 

Change the root password via System Preferences

 

  1. Choose Apple menu () > System Preferences, then click Users & Groups (or Accounts).
  2. Click the lock icon, then enter an administrator name and password.
  3. Click Login Options.
  4. Click Join (or Edit).
  5. Click Open Directory Utility.
  6. Click the lock icon in the Directory Utility window, then enter an administrator name and password.
  7. From the menu bar in Directory Utility, choose Edit > Change Root Password…
  8. Enter a root password when prompted.

 

 

Or, if you prefer using the Terminal

 

  1. Open the Terminal and type:
    sudo passwd -u root


  2. Enter and confirm a new root user password.

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.

Guest
Reply to this topic...

×   Pasted as rich text.   Restore formatting

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...