![]() Open Spotlight on the Mac by hitting Command+Spacebar (or clicking the Spotlight icon in the upper right corner of the menubar) and type in “Directory Utility” and hit return to launch the app.Using Directory Utility to Lock Down Root Directory Utility is perhaps easier for most users since it is accomplished entirely from the graphical interface on the Mac, whereas the command line approach is text based and generally considered more complex. There are two approaches to preventing root login without a password on a MacOS High Sierra machine, you can use Directory Utility or the command line. How to Prevent Root Login Without a Password in MacOS High Sierra All you have to do is set a root password on the impacted Mac. Sounds bad, right? It is, but there’s a fairly easy workaround that will prevent this security bug from being a problem. Mac users impacted by the security bug include anyone running macOS High Sierra 10.13, 10.13.1, or 10.13.2 betas who have not previously enabled the root account or changed a root user account password on the Mac before, which is the vast majority of Mac users running High Sierra. Any of these scenarios then allow full access to the MacOS High Sierra machine without ever using a password.Ī root user account provides the highest level of system access possible on a MacOS or any unix based operating system, root grants all capabilities of administrative user accounts on the machine in addition to unrestricted access to any system level components or files. The password-less root login can occur directly with a physical machine at the general user login screen seen on boot, from the System Preferences panels which typically require authentication, or even over VNC and Remote Login if those latter two remote access features are enabled. What is the root login bug, and why does it matter?įor some quick background, the security hole allows a person to enter ‘root’ as a username and then immediately login as root to the Mac, without a password. If you are running macOS High Sierra, download the update as soon as possible to your Mac. Important Update: Apple has released Security Update 2017-001 for macOS High Sierra to fix the root login bug, download it now. ![]() This is an urgent security problem, and while a software update should arrive to resolve the problem soon, this article will detail how to protect your Mac from this security hole. ![]()
0 Comments
Leave a Reply. |
Details
AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |