Welcome to the MacNN Forums.

If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

You are here: MacNN Forums > Software - Troubleshooting and Discussion > Mac OS X > Possible HUGE security flaw in OSX!!

Possible HUGE security flaw in OSX!!
Thread Tools
Mac Enthusiast
Join Date: Sep 2003
Status: Offline
Reply With Quote
Dec 17, 2004, 06:00 AM
 
I am finding a strange security flaw in OSX. Test your machine. Running 10.3.6 on 3 powerbooks here. One is an Aluminum 15 inch, 2 are Titanium 15 inch. Both Titaniums had this security flaw, but my personal one the Aluminum does not. I dont see why it would matter the hardware but test your machines to verify.

Ok here's the glitch. In order for you to succceed thru an OS X password challenge box, all you have to do is type the correct password as the begining of your entry.

Example: Your password is HAPPYDAYS32 If you enter HAPPYDAYS325544485689 as your password, it succeeds. or HAPPYDAYS322 or HAPPYDAYS32BA

So If my brother's password used to be HAPPYDAYS34 and last week he changed it to HAPPYDAYS, I can still log in without him telling me that he changed his password.

Does Apple know about this? Does it make sense that 2 out of 3 powerbooks that I've tried have this flaw? Does it matter the hardware revision or is it just a common glitch?


After testing it last night, i upgraded to 10.3.7 as I expected the test still fails on my AL15 but it always failed, I will urge my brother to upgrade to 10.3.7 and test again, please post your experiences.
| MBA Student | MacAddict | CarAddict | PhotoNut | Dork | PhishHead |
     
Mac Elite
Join Date: Jun 2003
Location: Newport News, VA USA
Status: Offline
Reply With Quote
Dec 17, 2004, 06:20 AM
 
I'm assuming the Titaniums were upgraded from Jaguar at some point. Jaguar and earlier versions of OS X used a different password scheme that only recognized the first 8 characters of a password.

Try changing the passwords on the problem machines and see if you get the same results...

edit: See this posting over at macosxhints.com:
http://www.macosxhints.com/article.p...41206090221302
     
Bruck  (op)
Mac Enthusiast
Join Date: Sep 2003
Status: Offline
Reply With Quote
Dec 17, 2004, 07:34 AM
 
Thanks!!! That link explained the issue, both machines had been upgraded to jag, while my AL15 had been installed from scratch.
(Last edited by Bruck; Dec 17, 2004 at 07:39 AM. )
| MBA Student | MacAddict | CarAddict | PhotoNut | Dork | PhishHead |
     
Mac Elite
Join Date: Nov 2001
Status: Offline
Reply With Quote
Dec 17, 2004, 08:48 AM
 
Originally posted by Bruck:
Thanks!!! That link explained the issue, both machines had been upgraded to jag, while my AL15 had been installed from scratch.
This is standard UNIX. If you use a crypt password (which is the least secure password type), it only uses the first 8 characters of the password.

This is not a HUGE security flaw in OS X -- it's the way crypt passwords work. OS X server has additional options for passwords, but c'mon do you REALLY need a 27 character password? No.
     
Grizzled Veteran
Join Date: Feb 2001
Location: Pittsburgh
Status: Offline
Reply With Quote
Dec 17, 2004, 10:09 AM
 
Originally posted by CatOne:
This is standard UNIX.
Sort of. Many *nix had this problem at one point but it has been mostly resolved in newer versions on most platforms.

There are various backends for user authentification. Fresh installs of 10.3 do not exhibit this insecurity. Also fixed are the non-shadowed password problems.
     
   
Thread Tools
Forum Links
Forum Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Top
Privacy Policy
All times are GMT -5. The time now is 11:13 AM.
All contents of these forums © 1995-2011 MacNN. All rights reserved.
Branding + Design: www.gesamtbild.com
vBulletin v.3.8.7 © 2000-2011, Jelsoft Enterprises Ltd., Content Relevant URLs by vBSEO 3.3.2