ISC StormCast for Wednesday, November 29th 2017
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 29 November 2017
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Wednesday, November 29th, 2017 edition of the Santernut Storm Center's |
| 0:06.6 | Stormcast. My name is Johannes Ulrich, and the time, recording from Augusta, Georgia. |
| 0:12.0 | Today, we got an amazingly simple exploit in OS10 that will get you root access. |
| 0:20.2 | Turns out that OS10 does ship without a route password being set for the operating system. |
| 0:27.6 | At first, site this may not be a big problem because the route account is disabled, so you cannot |
| 0:33.6 | actually directly log in using route. However, you can still use root credentials to |
| 0:40.3 | authenticate yourself as an administrator when you're adjusting system preferences. |
| 0:47.3 | So for example, if you are going to the system preference dialogue, then you're trying to unlock one of the options. |
| 0:57.0 | Typically, you get a pop-up box, it's pre-populated with your current username as a username, |
| 1:03.0 | and you enter your own password. |
| 1:06.0 | But as an alternative, you can also just enter root as a username, leave the password empty, |
| 1:13.6 | and then in my experience click the unlock key twice. First time won't work, but second time |
| 1:19.4 | you click it, it will work and will give you access to change these security preferences. |
| 1:26.5 | I tried it with a couple of the preferences and it worked like a charm. |
| 1:30.6 | Now, I haven't tested all and every single one of them. The quick fix here is to actually set a password |
| 1:37.2 | for route. Now, this is done pretty easily. Just use pseudo password, where password is abbreviated, P-A-S-S-W-D, and enter a new password. |
| 1:49.7 | Take a good password here, of course, because once you do actually set a password, the route account |
| 1:55.8 | becomes enabled and can be used to log in. |
| 2:00.4 | Apple stated that they are working on a fix for this issue and does recommend that for now |
| 2:07.4 | you should be changing your password. Now I will add a link to the respective page at Apple's |
| 2:15.8 | support website to the show notes. |
| 2:19.8 | One of the more scary up-and-coming technologies that you may have heard of is the use of |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

