OS X login passwords exposed in cleartext

By
Follow google news

Patch issued.

Apple has issued patches to close OS X flaws that makes user login passwords viewable in clear text to other logged in users.

OS X login passwords exposed in cleartext

The flaws were reported by researcher using the handle Magervalp in April and affected machines running OS X 10.7 - 10.8.4.

Apple has this week released patches for affected versions and recommended all affected users apply it.

The researcher said those managing student labs or public machines should apply the patches immediately.

He said the flaw could be tested by:

Logging into an affected machine with a configuration profile applied as a standard (unprivileged) user either over SSH or with fast user switching enabled, and executing:

$ while true; do ps auxww | grep '[m]dmclient mcx_userlogin'; done

Then logging in with a different user account at the login window and watching the shell's output.

"It's like nails on chalkboard," he wrote in a blog.

Add iTnews as your trusted source

Got a news tip for our journalists? Share it with us anonymously here.

Copyright © SC Magazine, Australia

Tags:

Most Read Articles

Home Affairs orders gov-wide 'legacy' system stocktake within six months

Home Affairs orders gov-wide 'legacy' system stocktake within six months

OpenAI agent accessed "credentials" via Medicare data portal

OpenAI agent accessed "credentials" via Medicare data portal

Cisco says no workaround for exploited SD-WAN Manager flaw

Cisco says no workaround for exploited SD-WAN Manager flaw

NSW National Parks web app accessed by OpenAI agent

NSW National Parks web app accessed by OpenAI agent

Log In

  |  Forgot your password?