Forum Home
Press F1
 
Thread ID: 116587 2011-03-10 22:01:00 OSX 10.6 exploit? Deimos (5715) Press F1
Post ID Timestamp Content User
1185088 2011-03-10 22:01:00 Does anyone know of an exploit in OSX that would allow a non admin user to delete the local accounts on the machine? Deimos (5715)
1185089 2011-03-10 22:21:00 Yes; a local privilege escalation exploit could easily achieve this.

:pf1mobmini:
Erayd (23)
1185090 2011-03-10 22:43:00 OK, I'm trying to find out how a student could do this without knowing it, such as a virus or something, I'm scanning his hard drive for viruses... Deimos (5715)
1185091 2011-03-11 01:09:00 Unlikely that it's a virus - I would be looking at either the student, or a semi-technical friend of that student, or a sysadmin who did something stupid.

Can you provide a bit more context?

:pf1mobmini:
Erayd (23)
1185092 2011-03-11 01:43:00 I look after a school campus with a lot of macs, I use Apple Remote Desktop to look after them, I noticed that a few machines occasionally came up with "Access denied" I eventually traced it back to one particular student (he was the only person who had logged in to all of the effected computers)

We have an active directory back end, all students have an account in AD which the lab machines authenticate off, student accounts only have user level permissions.

There is no firmware password, so potentially anyone with the appropriate knowledge could reset the admin password but it has not been a problem thus far.

The problem with this particular student is, machines that he has used have had the local user accounts deleted (we have 2 local accounts on the machines, one for just in case the network is down, and the other is the admin account).

I have his hard drive at the moment and I'm scanning it for viruses, I suspect that he is full of crap though (that it is happening without his knowledge).
Deimos (5715)
1185093 2011-03-11 03:07:00 Sophos (for mac) turned up nothing. Deimos (5715)
1185094 2011-03-11 03:16:00 At rutherford there was one student who used to reinstall windows xp on some computers, and also got into the server using linux and changed the school's intranet splashpage to a paint penis, then a smiley face because the server wasn't password protected.

It was hilarious, I watched it happening (f5 f5 f5) and then had a word with him afterwards.
Can't say I condone what he did, but the admin was just such an ass.

But yeah it does happen, students with knowledge either get bored and do it for no reason too, so I'm guessing you're right in that he's being a douche and is either bored or is feeling the restrictions.
8ftmetalhaed (14526)
1185095 2011-03-11 04:15:00 Safari was hacked on 10.6, @ Pwn2Own the other day. So, anything is possible Speedy Gonzales (78)
1185096 2011-03-11 06:53:00 by deleting a few xml files you can easily get into the accounts pref pane even if it is locked. I'll try to break into an admin account and post the results. icow (15313)
1185097 2011-03-11 07:09:00 I was able to create a new admin account without touching the original admin account. this would allow you to have full access to the other accounts and then delete your old account/original admin account. icow (15313)
1 2