Mac OS X Lion Password Flaw Lets Hackers Make Changes With Ease

Discussion in 'Misc' started by Jim_Higgins, Sep 20, 2011.

  1. Jim_Higgins

    Jim_Higgins Guest

    Jim_Higgins, Sep 20, 2011
  2. The short story is that Directory Service is not protecting the password
    in 10.7:

    dscl localhost -passwd /Search/Users/$USER

    In 10.6, you get a permissions error and a password prompt to complete
    the change. In 10.7, it works with no challenge.
    Kevin McMurtrie, Sep 22, 2011
