macOS High Sierra Bug Lets Anyone Gain Root Access Without a Password

If you own a Mac computer and run the latest version of Apple’s operating system, macOS High Sierra, then you need to be extra careful with your computer.

A serious, yet stupid vulnerability has been discovered in macOS High Sierra that allows untrusted users to quickly gain unfettered administrative (or root) control on your Mac without any password or security check, potentially leaving your data at risk.

Discovered by developer Lemi Orhan Ergin on Tuesday, the vulnerability only requires anyone with physical access to the target macOS machine to enter “root” into the username field, leave the password blank, and hit the Enter a few times—and Voila!

In simple words, the flaw allows an unauthorized user that gets physical access on a target computer to immediately gain the highest level of access to the computer, known as “root,” without actually typing any password.

Needless to say, this blindingly easy Mac exploit really scary stuff.

This vulnerability is similar to one Apple patched last month, which affected encrypted volumes using APFS wherein the password hint section was showing the actual password of the user in the plain text.

Here’s How to Login as Root User Without a Password

If you own a Mac and want to try this exploit, follow these steps from admin or guest account:

  • Open System Preferences on the machine.
  • Select Users & Groups.
  • Click the lock icon to make changes.
  • Enter “root” in the username field of a login window.
  • Move the cursor into the Password field and hit enter button there few times, leaving it blank.

With that (after a few tries in some cases) macOS High Sierra logs the unauthorized user in with root privileges, allowing the user to access your Mac as a “superuser” with permission to read and write to system files, including those in other macOS accounts as well.

This flaw can be exploited in several ways, depending on the setup of the targeted Mac. With full-disk encryption disabled, a rogue user can turn on a Mac that’s entirely powered down and log in as root by doing the same trick.

At Mac’s login screen, an untrusted user can also use the root trick to gain access to a Mac that has FileVault turned on to make unauthorized changes to the Mac System Preferences, like disabling FileVault.

All the untrusted user needs to do is click “Other” at the login screen, and then enter “root” again with no password.

However, it is impossible to exploit this vulnerability when a Mac machine is turned on, and the screen is protected with a password.

Ergin publicly contacted Apple Support to ask about the issue he discovered. Apple is reportedly working on a fix.

“We are working on a software update to address this issue. In the meantime, setting a root password prevents unauthorized access to your Mac. To enable the Root User and set a password, please follow the instructions here: https://support.apple.com/en-us/HT204012. If a Root User is already enabled, to ensure a blank password is not set, please follow the instructions from the ‘Change the root password’ section.”

Here’s How to Temporarily Fix the macOS High Sierra Bug

Fortunately, the developer suggested a temporary fix for this issue which is as easy as its exploit.

To fix the vulnerability, you need to enable the root user with a password. Heres how to do that:

  • Open System Preferences and Select Users & Groups
  • Click on the lock icon and Enter your administrator name and password there
  • Click on “Login Options” and select “Join” at the bottom of the screen
  • Select “Open Directory Utility”
  • Click on the lock icon to make changes and type your username and password there
  • Click “Edit” at the top of the menu bar
  • Select “Enable Root User” and set a password for the root user account

This password will prevent the account from being accessed with a blank password.

Just to be on the safer side, you can also disable Guest accounts on your Mac. for this, head on to System Preferences → Users & Groups, select Guest User after entering your admin password, and disable “Allow guests to log in to this computer.”

 

Microsoft Releases Update to Fix 53 Vulnerabilities

Microsoft has released a large batch of security updates as part of its November Patch Tuesday in order to fix a total of 53 new security vulnerabilities in various Windows products, 19 of which rated as critical, 31 important and 3 moderate.

The vulnerabilities impact the Windows OS, Microsoft Office, Microsoft Edge, Internet Explorer, Microsoft Scripting Engine, .NET Core, and more.

At least four of these vulnerabilities that the tech giant has now fixed have public exploits, allowing attackers to exploit them easily. But fortunately, none of the four are being used in the wild, according to Gill Langston at security firm Qualys.

The four vulnerabilities with public exploits identified by Microsoft as CVE-2017-8700 (an information disclosure flaw in ASP.NET Core), CVE-2017-11827 (Microsoft browsers remote code execution), CVE-2017-11848 (Internet Explorer information disclosure) and CVE-2017-11883 (denial of service affecting ASP.NET Core).

Potentially Exploitable Security Vulnerabilities

What’s interesting about this month’s patch Tuesday is that none of the Windows OS patches are rated as Critical. However, Device Guard Security Feature Bypass Vulnerability (CVE-2017-11830) and Privilege Elevation flaw (CVE-2017-11847) are something you should focus on.

Also, according to an analysis of Patch Tuesday fixes by Zero-Day Initiative, CVE-2017-11830 and another flaw identified as CVE-2017-11877 can be exploited to spread malware.

“CVE-2017-11830 patches a Device Guard security feature bypass vulnerability that would allow malware authors to falsely authenticated files,” Zero-Day Initiative said.

“CVE-2017-11877 fixes an Excel security feature bypass vulnerability that fails to enforce macro settings, which are often used by malware developers.”

The tech giant also fixed six remote code execution vulnerabilities exist “in the way the scripting engine handles objects in memory in Microsoft browsers.”

Microsoft identified these vulnerabilities as CVE-2017-11836, CVE-2017-11837, CVE-2017-11838, CVE-2017-11839, CVE-2017-11871, and CVE-2017-11873, which could corrupt memory in such a way that attackers could execute malicious code in the context of the current user.

“In a web-based attack scenario, an attacker could host a specially crafted website that is designed to exploit the vulnerability through Microsoft Edge and then convince a user to view the website,” Microsoft said. “These websites could contain specially crafted content that could exploit the vulnerability.”

17-Year-Old MS Office Flaw Lets Hackers Install Malware

Also, you should be extra careful when opening files in MS Office.

All versions of Microsoft Office released in the past 17 years found vulnerable to remote code execution flaw(CVE-2017-11882) that works against all versions of Windows operating system, including the latest Microsoft Windows 10 Creators Update.

However, due to improper memory operations, the component fails to properly handle objects in the memory, corrupting it in such a way that the attacker could execute malicious code in the context of the logged-in user.

Exploitation of this vulnerability requires opening a specially crafted malicious file with an affected version of Microsoft Office or Microsoft WordPad software, which could allow attackers to remotely install malware on targeted computers.

Adobe Patch Tuesday: Patches 62 Vulnerabilities

Besides fixing vulnerabilities in its various products, Microsoft has also released updates for Adobe Flash Player.

These updates correspond with Adobe Update APSB17-33, which patches 62 CVEs for Acrobat and Reader alone. So, Flash Player users are advised to ensure that they update Adobe across their environment to stay protected.

It should also be noted that last Patch Tuesday, Microsoft quietly released the patch for the dangerous KRACK vulnerability (CVE-2017-13080) in the WPA2 wireless protocol.

Therefore, users are also recommended to make sure that they have patched their systems with the last month’s security patches.

Alternatively, users are strongly advised to apply November security patches as soon as possible in order to keep hackers and cybercriminals away from taking control of their computers.

For installing security updates, just head on to Settings → Update & security → Windows Update → Check for updates, or you can install the updates manually.

The Hacker News

Office 365: A Vehicle for Internal Phishing Attacks

A new threat uses internal accounts to spread phishing attacks, making fraudulent emails even harder to detect.

Cybercriminals go where the users are. Office 365, which has more than 100 million active monthly subscribers, has become a hotspot for compelling and personalized cyberattacks. Users trust emails from coworkers, especially those with the correct corporate email address.

Traditional phishing attempts have red flags: suspicious attachments, bold requests, misspelled words, questionable email addresses. Users know how to react to these. But what happens when attacks are more personalized, with legitimate addresses and reasonable requests?

These have become more popular and tougher to spot, says Asaf Cidon, spearphishing expert at Barracuda. The company recently released a report on a threat he calls Account Compromise. Once they have an employee’s Office 365 account information, threat actors can craft realistic-looking messages and send them from an account their victims trust.

Attackers primarily steal credentials using traditional methods, he continues. Most rely on phishing or spearphishing to send victims to fraudulent websites, where they are prompted to reset their Office 365 credentials. Some buy users’ credentials on the dark web.

“What’s new is what happens after they get access to the accounts,” Cidon says. Threat actors can conduct several types of attacks after they gain a foothold in an organization.

In one common scenario, an attacker sets forwarding rules on an Office 365 account to send emails to an account they control. From there, they can both steal data and monitor the user’s internal and external communication patterns so they can plan future attacks.

Threat actors also impersonate their victims and send emails to other employees with the goal of collecting data. Some send emails with PDF attachments that can only be opened with a username and password. Some send an invoice for payment that requires logging into a web portal, where they have to log in with a corporate email address and password.

Damage could potentially extend outside the organization. Cidon explains a scenario in which an attacker, impersonating an employee, used their access to request a wire transfer from a partner company. The employee in the scenario didn’t even realize the transfer was happening.

“This is an evolution of spearphishing – we’re seeing more and more sophistication,” he says. A couple of years ago, cyberattackers primarily targeted executive employees. These new Office 365 threats are putting all employees at risk.

“With this attack, they’re just trying to get in and once they’re in, a lot of the employees getting targeted are not high-level. It’s not just executive targets,” Cidon continues.

There are red flags that signify a company is targeted in one of these attacks. Oftentimes the IP addresses used to log into corporate accounts come from other countries, he says, and looking at the log can identify geographical anomalies. It also helps to keep track of your email account to see when emails are getting forwarded or sent to unfamiliar addresses.

Cidon advises security leaders to train employees on how to spot phishing attacks to prevent attackers gaining initial access. He also advises adding security layers like multi-factor authentication to Office 365 to lessen the chance of a break-in.

“Traditional email security systems are going to be almost useless in stopping this,” he says, noting how most tools look at the API of the email provider. “Once an attacker is in, they don’t see internal emails … only the external emails coming in.”

DARKReading

Adobe Flash Player to Be Retired in 2020

Adobe Systems’s Flash, a once-ubiquitous technology used to power most of the media content found online, will be retired at the end of 2020, the software company announced Tuesday.

Adobe, along with partners Apple, Microsoft, Alphabet Inc’s Google, Facebook and Mozilla, said support for Flash will ramp down across the Internet in phases over the next three years.

After 2020, Adobe will stop releasing updates for Flash and Web browsers will no longer support it. The companies are encouraging developers to migrate their software onto modern programming standards.

“Few technologies have had such a profound and positive impact in the Internet era,” said Govind Balakrishnan, vice president of product development for Adobe Creative Cloud.

Created more than 20 years ago, Flash was once the preferred software used by developers to create games, video players and applications capable of running on multiple Web browsers. When Adobe acquired Flash in its 2005 purchase of Macromedia, the technology was on more than 98 percent of personal computers connected to the web, Macromedia said at the time.

But Flash’s popularity began to wane after Apple’s decision not to support it on the iPhone.

In a public letter in 2010, late Apple CEO Steve Jobs criticized Flash’s reliability, security and performance. Since then, other technologies like HTML5 have emerged as alternatives to Flash.

In the past year, several Web browsers have begun to require users to enable Flash before running it.

On Google’s Chrome, the most popular Web browser, Flash’s usage has already fallen drastically. In 2014, Flash was used each day by 80 percent of desktop users. That number is now at 17 percent “and continues to decline,” Google said in a blog Tuesday.

“This trend reveals that sites are migrating to open Web technologies, which are faster and more power-efficient than Flash,” Google said. “They’re also more secure.”

Flash, however, remains in use among some online gamers. Adobe said it will work with Facebook as well as Unity Technologies and Epic Games to help developers migrate their games.

Adobe said it does not expect Flash’s sunset to have an impact on its bottom line. “In fact, we think the opportunity for Adobe is greater in a post-Flash world,” Balakrishnan said.

Gadgets 360

Mac Computers Hacked With ‘FruitFly’ Surveillance Malware

American Apple Mac computers have been hacked with FruitFly malware, Forbes reports.

The hack is thought to be for surveillance as hackers were able to jump into the webcams of the affected computers and take screenshots, though the FruitFly malware has the ability to take over the entire computer.

“This didn’t look like cybercrime type behaviour, there were no ads, no keyloggers, or ransomware,” said Patrick Wardle, cybersecurity researcher, via Forbes. “Its features had looked like they were actions that would support interactivity: it had the ability to alert the attacker when users were active on the computer, it could simulate mouse clicks and keyboard events.”

This isn’t the first time that FruitFly is making a hacking appearance. Earlier this year, it was used to target biomedical research centers.

“The only reason I can think of that this malware hasn’t been spotted before now is that it is being used in very tightly targeted attacks, limiting its exposure,” wrote Thomas Reed, MalwareBytes researcher. “Although there is no evidence at this point linking this malware to a specific group, the fact that it’s been seen specifically at biomedical research institutions certainly seems like it could be the result of exactly that kind of espionage.”

FruitFly is difficult to detect. Not much is known about the malware.

Microsoft is preparing to kill off Paint after 32 years

Microsoft has revealed that the graphics editing app is no longer “in active development”, and may be removed from Windows altogether.

Paint was introduced back in 1985, and has featured on every version of Microsoft’s computer operating system.

Though it was never the most capable program, it was easy to use and familiar to millions of people, many of whom used it as their main source of digital fun before going online.

The company has published a support document listing a number of Windows features that are set to be killed off.

“The following features and functionalities in the Windows 10 Fall Creators Update are either removed from the product in the current release (“Removed”) or are not in active development and might be removed in future releases (“Deprecated”),” Microsoft says.

“This list is intended to help customers consider these removals and deprecations for their own planning.”

Paint would be the biggest casualty by far, though it might yet survive, as Microsoft says “the list is subject to change and may not include every deprecated feature or functionality”.

Paint 3D, a modern version of the app, was introduced earlier this year, but Microsoft decided to make it available alongside regular Paint, rather than instead if it.

3D Builder app, Apndatabase.xml, Enhanced Mitigation Experience Toolkit (EMET), Outlook Express, Reader app, Reading List, Screen saver functionality in Themes, Syskey.exe, TCP Offload Engine, Tile Data Layer and Trusted Platform Module (TPM) Owner Password Management will be removed from Windows 10 when the the Fall Creators Update arrives – most likely in September.

Along with Paint, IIS 6 Management Compatibility, IIS Digest Authentication, RSA/AES Encryption for IIS, Sync Your Settings, System Image Backup (SIB) Solution, TLS RC4 Ciphers, Trusted Platform Module (TPM): TPM.msc and TPM Remote Management, Trusted Platform Module (TPM) Remote Management, Windows Hello for Business deployment that uses System Center Configuration Manager and Windows PowerShell 2.0 have also been marked as Deprecated.

independent

This cheap password-stealing malware just added to your security headaches

A new form of credential-stealing malware — complete with slick marketing and support from its authors — is available for as little as $7, providing wannabes with a worryingly easy entry point into the world of cybercrime.

First appearing a month ago, Ovidiy Stealer is regularly updated by its Russian-speaking authors and the malware has hit targets around the world including the UK, the Netherlands, India, and Russia.

Despite its low price of 450-750 Rubles ($7-13), the malware comes with code designed to avoid analysis and detection.

Uncovered by researchers at Proofpoint, the malware is spread via a number of methods, including malicious email attachments, file-hosting websites, and even within software packages.

It comes with functionality to target multiple applications, but buyers are able to purchase a version of the malware which only focuses on a single browser if they so wish.

If the malware is able to find passwords in its targeted applications, it will send them to the gang using it, putting the victim and their organisation at risk of compromise, especially if the same password is used across multiple accounts.

Ovidiy Stealer is openly sold on a domain which boasts support and features — including the ability to view statistics and logs of infected machines — to potential customers. Payment for the malware is taken by RoboKassa, the Russian equivalent of PayPal.

In order to help drive sales in the competitive criminal world of malware, the developers include statistics and detail plans for future releases of Ovidiy Stealer.

ovidiy-stealer-reviews.png
Reviews help Ovidiy Stealer look appealing to potential buyers.Image: Proofpoint

While Ovidiy Stealer isn’t advanced, the marketing and advertising around it, combined with a low price, could make it very attractive to wannabe cybercriminals who might not otherwise have the expertise to get involved.

“Ovidiy Stealer highlights the manner in the cybercrime marketplace drives innovation and new entrants and challenges organizations that must keep pace with the latest threats to their users, their data, and their systems,” said Proofpoint researchers.

While many cybercriminal operations are run by highly sophisticated gangs which do not sell their products to outsiders, there’s a growing market for ‘cybercrime-as-a-service’ schemes which provide low-level criminals with all the tools they need to get started, in return for a cut of the profits.

ZDNet

Hackers use NSA’s leaked EternalBlue exploit to power more malicious payloads

Hackers are expanding the use of EternalBlue, the leaked NSA hacking exploit that was thrust into the spotlight in May with its initial use in the WannaCry ransomware and Adylkuzz cryptocurrencyminer.

Security researchers have now found threat actors exploiting the vulnerability in Microsoft Server Message Block (SMB) protocol to distribute other malicious payloads including Backdoor.Nitol and Trojan Gh0st RAT.

Backdoor.Nitol is a Trojan horse that opens a backdoor on the infected computer. Gh0st RAT is a remote access trojan that has been making the rounds for years to target Windows machines and is capable of giving attackers full access and control of an infected machine. It has also been used in extensive cyber espionage and data stealing campaigns.

According to security firm FireEye, both the well-known payloads have been previously used in cyberattacks targeting the aerospace and defence industry with Gh0st RAT targeting government agencies and activists as well.

“We observed lab machines vulnerable to the SMB exploit were attacked by a threat actor using the EternalBlue exploit to gain shell access to the machine,” FireEye researchers said in blogpost. “The initial exploit technique used at the SMB level is similar to what we have been seen in WannaCry campaigns.

“However, once a machine is successfully infected, this particular attack opens a shell to write instructions into a VBScript file and then executes it to fetch the payload on another server.”

Researchers said the combination of EternalBlue and VBScript has been used to distribute Gh0st RAT in Singapore and Backdoor.Nitol in the South Asia region.

EternalBlue came as part of the cache of alleged NSA hacking tools released by notorious hacking group Shadow Brokers in April.

Security researchers warned that with EternalBlue exploit now released and available for any threat actors to target, it is likely that it will be used in new sophisticated and more frequent cyberattacks.

“The addition of the EternalBlue exploit to Metasploit has made it easy for threat actors to exploit these vulnerabilities,” FireEye said. “In the coming weeks and months, we expect to see more attackers leveraging these vulnerabilities and to spread such infections with different payloads.

“It is critical that Microsoft Windows users patch their machines and update to the latest software versions as soon as possible.”

IBTimes

Samsung releases SoundAssistant app for improved audio experience on Galaxy phones


Samsung has launched a new app to allow Samsung Galaxy owners to customize a wealth of audio settings on their devices.

Known as SoundAssistant, the app offers “150 steps” of volume adjustment, a floating EQ, mono and stereo balancing, as well as the chance to set individual volumes for different apps.

What’s more, SoundAssistant can alter the hardware volume keys so that they default to media volume control rather than call volume. Typically, these keys will automatically switch to control whatever sound is playing at the time, but this can be a little finicky and doesn’t always adjust the desired setting. As a person who usually has their phone on silent, though, having it default to media volume would be far more useful than call volume.

If you own a Galaxy S8 or S8 Plus, SoundAssistant can even allow you to set different outputs for different apps, like using a Bluetooth speaker for Spotify and the phone’s speaker for Clash of Clans.

On paper, the app looks like it could be a useful tool and I expect that many Android users would appreciate the features it offers: here’s hoping Samsung opens it up to non-Galaxy devices sometime (and non-Android 7.0 Nougat devices, as that’s another current restriction).

You can download SoundAssistant via the link below and let us know in the comments what your favorite Android audio customization tool is.

Interconnected smart toys “can be weaponised”

An audience of security experts attending a cybersecurity conference at the World Forum in The Hague (The Netherlands) on Tuesday were shocked when a demonstration done by an 11-year-old “cyber ninja” showed the dismal cyber security standards that are prevailing in technology. He hacked into the Bluetooth devices to manipulate a teddy bear and show how interconnected smart toys “can be weaponised”.

The wonder kid in question is American Reuben Paul, a cyber security expert and white hat hacker who’s currently studying in the sixth standard of a school in Austin, Texas. Techworm had reported about the hacking skills of Reuben way back in 2015 when he warned an audience about the dangers of smartphone hacking while delivering a keynote address as a 9-year-old.

“From airplanes to automobiles, from smartphones to smart homes, anything or any toy can be part of the” Internet of Things (IOT),” Reuben told the crowd. “From terminators to teddy bears, anything or any toy can be weaponised.”

As part of his live demonstration and to prove his point, Reuben deployed his cuddly looking teddy bear ‘Bob’, which connects to the iCloud via Wi-Fi and Bluetooth smart technology to receive and transmit messages.

He then plugged a “Raspberry Pi” – a tiny and low cost computer – into his laptop on stage and started scanning the hall for available Bluetooth devices. To the astonishment of everyone in the hall, Reuben was able to download dozens of numbers including some of top officials.

Then, using the programming language called Python, he went on to hack into his Internet-connected teddy bear via one of the numbers and turned on Bob’s lights and transferred a recorded message from the audience through to the bear.

“Most internet-connected things have a blue-tooth functionality … I basically showed how I could connect to it, and send commands to it, by recording audio and playing the light,” he told AFP explaining his demonstration.

“IOT home appliances, things that can be used in our everyday lives, our cars, lights refrigerators, everything like this that is connected can be used and weaponised to spy on us or harm us.”

For instance, they could be used to steal private information such as passwords, as remote surveillance devices to spy on kids, or to locate a person using GPS.

More terrifyingly, toys could even be programmed to say “meet me at this location and I will pick you up,” Reuben said.

Besides being a cyber-ninja, Reuben is also the youngest American to earn a black belt in Shaolin Kung Fu. With the help from his family, Reuben has set up a non-profit organisation called CyberShaolin whose purpose is to spread awareness about “the dangers of cyber-insecurity”.

Since his talk, Reuben has been receiving congratulatory messages on Twitter from various experts in the infosec community applauding his work.

Reuben’s father, Mano Paul, an IT expert, said that his kid’s cyber skills emerged at the age of six, when he began exploring how software systems worked.

“He has always surprised us. Every moment when we teach him something he’s usually the one who ends up teaching us,” he told the AFP.

Reuben hopes to study cyber-security at either CalTech or MIT universities.

TechWorm