Slashdot is powered by your submissions, so send in your scoop

 



Forgot your password?
typodupeerror
×
Security Bug Businesses OS X Operating Systems Apple

Mac OS X Root Escalation Through AppleScript 359

An anonymous reader writes "Half the Mac OS X boxes in the world (confirmed on Mac OS X 10.4 Tiger and 10.5 Leopard) can be rooted through AppleScript: osascript -e 'tell app "ARDAgent" to do shell script "whoami"'; Works for normal users and admins, provided the normal user wasn't switched to via fast user switching. Secure? I think not." On the other hand, since this exploit seems to require physical access to the machine to be rooted, you might have some other security concerns to deal with at that point, like keeping the intruder from raiding your fridge on his way out.
This discussion has been archived. No new comments can be posted.

Mac OS X Root Escalation Through AppleScript

Comments Filter:

"And remember: Evil will always prevail, because Good is dumb." -- Spaceballs

Working...