..." /> vowe dot net :: OS X Lion security flaw allows anyone to change your password

OS X Lion security flaw allows anyone to change your password

by Volker Weber

Security blog Defense in Depth has found a glaring security flaw in OS X Lion that enables hackers to change the password of any user on a machine running Lion.

More >

Comments

CNet and BGR seem to quote the original article partly wrong, as heise.de states in http://www.heise.de/newsticker/meldung/Mac-OS-X-Lion-macht-es-Passwortknackern-unnoetig-leicht-1345451.html

You can only change the password of the user executing the command, not the one of passwords from other users. If you try to change the password of another user via dscl it prompts for the other users password after asking for the new password. Try it yourself.

Christian Gut, 2011-09-20

Guter Hinweis, danke!

Volker Weber, 2011-09-20

Lion is increasingly being referred to as 'Apple's Vista' - security issues, memory leaks, incompatibilities and slowdowns aplenty. Which is a very apposite comparison, and ought to be of concern to Apple.

Nick Daisley, 2011-09-22

Recent comments

Jan Fuellemann on ANC Schalter für Beats Studio 3 in iOS 13 at 17:10
Volker Weber on Recording video on iPhone with Buetooth headset at 00:01
Gregory Engels on Recording video on iPhone with Buetooth headset at 22:41
Martin Hiegl on Cryptodamages: Monetary value estimates of the air pollution and human health impacts of cryptocurrency mining at 17:45
Markus Dierker on Recording video on iPhone with Buetooth headset at 08:25
Volker Weber on Cryptodamages: Monetary value estimates of the air pollution and human health impacts of cryptocurrency mining at 22:48
Maximilian von Hulewicz on Cryptodamages: Monetary value estimates of the air pollution and human health impacts of cryptocurrency mining at 08:09
Andreas Weinreich on Withings ECG :: Erste Eindrücke at 21:30
Andy Mell on Very fast October update for Galaxy S10 at 18:56
Volker Weber on Withings ECG :: Erste Eindrücke at 16:53
Bernd Fellerhoff on Withings ECG :: Erste Eindrücke at 15:23
Stanislaus Landeis on iCloud Drive file sharing delayed until spring 2020 at 12:55
Volker Weber on AirPlay 2 richtig verwenden at 11:52
Matthias Welling on AirPlay 2 richtig verwenden at 09:30
Volker Weber on AirPlay 2 richtig verwenden at 23:10
Steve Smillie on Very fast October update for Galaxy S10 at 21:58
Ragnar Schierholz on AirPlay 2 richtig verwenden at 21:34
Ragnar Schierholz on Withings ECG :: Erste Eindrücke at 18:05
Peter Meuser on Endlich habe ich Samsung DeX kapiert at 17:00
Torsten Pinkert on Very fast October update for Galaxy S10 at 16:45
Christian Tillmanns on Cryptodamages: Monetary value estimates of the air pollution and human health impacts of cryptocurrency mining at 16:17
Armin Auth on Lenovo Chromebook C340-11 #stuffthatworks at 11:49
Maximilian von Hulewicz on Cryptodamages: Monetary value estimates of the air pollution and human health impacts of cryptocurrency mining at 10:06
Markus Mews on Lenovo Chromebook C340-11 #stuffthatworks at 09:27
Christian Tillmanns on Cryptodamages: Monetary value estimates of the air pollution and human health impacts of cryptocurrency mining at 07:44

Ceci n'est pas un blog

I explain difficult concepts in simple ways. For free, and for money. Clue procurement and bullshit detection.

vowe

Contact
Publications
Stuff that works
Amazon Wish List
Frequently Asked Questions

rss feed  twitter  amazon

Local time is 19:42

visitors.gif

buy me coffee

Paypal vowe