|
Brought to you by:
Suppliers of:
|
|
|
| |
| Netopia has released Timbuktu Preview for Mac OS X. Timbuktu is remote administration software that runs on both Windows and Macintosh platforms. A security hole has been found in the product that lets a user at the console gain complete access to the system without even having to log into the Mac OS X. |
| |
Credit:
The information has been provided by ed from SecureMac.com.
|
| |
Vulnerable systems:
Timbuktu Preview for Mac OS X
The login screen of a freshly updated Mac OS X with preview version of Timbuktu for Mac OS X contains an icon in the upper left hand portion of the screen; the icon enables access to a menu that contains all of the goodies (open Timbuktu, turn tcp on/off, about, etc). When the menu 'About Timbuktu' is clicked, any user with physical access to the machine can get full control to the apple menu and system preferences without even being logged into OS X.
Having access to the System Preferences without being logged in can allow access to the users' panel where someone could change passwords or any system setting.
Essentially, the attacker will have admin access to the entire system preferences window and the users panel even shows the hidden admin/root user.
Vendor Response:
Netopia was notified of this problem but responded that "the software is sold without warrantee".
|
|
|
|
|