April 23, 2024
Lion Passwords Can Be Changed By Any Local User

Lion Passwords Can Be Changed By Any Local User

Posted September 20, 2011 at 2:13am by iClarified
Defence in Depth has discovered a security risk in Mac OS X Lion that lets local users change the passwords of any account, reports CNET.

The site explains that OS X user passwords and encrypted and stored in "shadow files" which are placed in secure locations on your hard drive. Security permissions only allow the owner and administrators to access these files.

Unfortunately, recent discoveries have shown that in OS X Lion this security structure is not intact, and any user on the system can modify the passwords of other local accounts quite easily. The problem at hand appears to be because of a permissions oversight that allows all users search access to the system's directory services.


Recommended Steps Until Apple Releases Fix:
1. Disable automatic log-in
2. Enable sleep and screensaver passwords
3. Disable Guest accounts
4. Parental Controls
5. Manage users on the system

Read More [via CNET] [via


Lion Passwords Can Be Changed By Any Local User
Add Comment
Would you like to be notified when someone replies or adds a new comment?
Yes (All Threads)
Yes (This Thread Only)
No
iClarified Icon
Notifications
Would you like to be notified when we post a new Apple news article or tutorial?
Yes
No
Comments (6)
You must login or register to add a comment...
Lm
Lm - September 20, 2011 at 12:56pm
Shocking!! Thats why i dont use mac os.
Andrew
Andrew - September 20, 2011 at 4:13am
Sadly I reflect Apple OS being labeled 99% virus free and no need for firewalls or defrag utilities... But the Window users were right. The only reason that was the case was but it made no sense to hack such a small community. But as Apple continues to market to the masses and make it everybody friendly... Norton's Symantec will be needed for Mac as well as PCs running Windows.
Saeq
Saeq - September 20, 2011 at 10:28am
Do you work for Norton?
CASEACE79
CASEACE79 - September 20, 2011 at 12:09pm
Norton sucks. Even AVG free has better virus protection. Norton is a joke.
Andrew
Andrew - September 20, 2011 at 3:55pm
No fanboy ... Where's chum chum? I work for myself. I'm a studio engineer... I own and operate myself.
DacksMac
DacksMac - September 21, 2011 at 1:03am
Fortunately for Mac users Apple makes and creates FREE updates to kill off possible virus attacks. To bad Windows doesn't offer the same free handout :(
Recent. Read the latest Apple News.
RECENT
Tutorials. Help is here.
TUTORIALS
Where to Download macOS Monterey
Where to Download macOS Ventura
AppleTV Firmware Download Locations
Where To Download iPad Firmware Files From
Where To Download iPhone Firmware Files From
Deals. Save on Apple devices and accessories.
DEALS