Okay guys, the Rixstep POC was updated with new instructions. He also now has a tidbit about MasterPasswordHint, which I stumbled on while going through the plist on my own machin…
Quote:
Originally Posted by alphasubzero949
Just like Paranoid Android.
Exactly.
This kind of hand-holding for people who are vulnerable to social engineering is not neede…
Quote:
Originally Posted by alphasubzero949
Okay guys, the Rixstep POC was updated with new instructions. He also now has a tidbit about MasterPasswordHint, which I stumbled on…
Okay, here's why the POC will not work through the Finder.
If you duplicate com.apple.loginwindow.plist through the Finder, you get a binary plist file (indicated by bplist00). A…
Just tried it, still no rooted.txt in my /Users/Shared.
Moving the com.apple.loginwindow.plist file to /var/root/Library/Preferences, though, does create the rooted.txt, even if t…
Quote:
Originally Posted by alphasubzero949
It seems that if you're running 10.4.0 or 10.4.1, you're 'safe' (notwithstanding the widget exploit).
To which widget exploit are…
Quote:
Originally Posted by CharlesS
Just tried it, still no rooted.txt in my /Users/Shared.
Moving the com.apple.loginwindow.plist file to /var/root/Library/Preferences, thoug…
Now Alpha, you just described three complex steps required for this vulnerability. Could a malicious application really secretly do all of those things? Apple can only lock things …
Quote:
Originally Posted by Big Mac
Now Alpha, you just described three complex steps required for this vulnerability. Could a malicious application really secretly do all of th…
Quote:
Originally Posted by alphasubzero949
This is how I made it work on my system, although I used Xfile instead of the Finder. The key is that the substituted plist be in XM…
Quote:
Originally Posted by Hal Itosis
Would you believe Apple Security Update 2006-002v1.1?
It's the same update as before, it just fixes a few bugs in the original upd…
Quote:
Originally Posted by Hal Itosis
Would you believe Apple Security Update 2006-002v1.1?
I'm officially confused.® What does this v1.1 due/fix/break?
Quote:
Originally Posted by rickey939
I'm officially confused.® What does this v1.1 due/fix/break?
Presumably corrects bugs in update 2006-002. It fixes nothing new. Othe…
Go here:
http://www.macromedia.com/support/fl...downloads.html
And scroll down until you see:
Macromedia Flash Player 7 - Standalone Players (Projectors) for Macintosh
Download th…
Quote:
Originally Posted by Rumor
I can't get this game to work. Any ideas? In the forums it said to use the stand alone Flash Player 7 but I can't find it.
The following…
I've been reading around on how to make use of the FPT capabilities built into OSX. I'm kind of clueless, on this area. I would like to be able to remotely log into my mac at hom…
I use Interarchy to pick up stuff from my desktop system that I "forgot" to take with me to work on my MacBook Pro. A single-user licence is only $39 and it's really easy to use, a…
Do you need a static IP for this? I tried to set up my airport with a static IP (I read instruction on portforward.com) but, Comcast won't give me the IP for the DNS server (I thi…