Security Hole in Mac OS X
Embarrassing security hole in Apple‘s new operating system Mac OS X Lion: Because Apple schluderte access protection, attackers can be all too easily give access to a foreign system. It can protect the system simple. A security hole in Mac OS X 10.7 makes it easy to attackers, to gain access to other Apple computers, reported a U.S. blogger. As long as you can at least log in as a guest on a computer with Apple‘s current operating system, you can change passwords for other user accounts as you wish – and to be crowned as the administrator of the computer itself.
Security expert Patrick Dunstan has discovered the gap – and is apparently even more flabbergasted about how Apple was able to see this error: “Looks as if the revision of the authentication scheme in OS X Lion is an important step was overlooked,” writes he in his blog. Accordingly, even lay people exploit the vulnerability by entering a simple command in the Terminal program in Mac OS X. The gap is expected to play for many private-Apple users, however, hardly a role: She’s just nasty, if the attacker already has access to an account. A simple laptop thief could instead just remove the hard drive and work with coarser funds through their database.
Rather, companies should take care: one penetrates one malware into the corporate network, they can gain through this vulnerability theoretically unlimited access rights to the company’s Macs, ransacked files or install additional malicious code.
But there are also simple protection mechanisms, explains Cnet.com : Who the automatic login disabled on his Mac, passwords for the sleep and screensaver-state enabled, guest accounts off and other users removes admin rights in the account management, puts attackers significant obstacles in the way of computer power.
recently discovered security hole in an operating system (1)
