Home User CP Donate Chat Register Today!  
  Get New posts Faq / Help?
   


Go Back   Hackint0sh > Welcome! > Forum News and Events.

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 08-14-2006, 02:01 AM
aRt's Avatar
aRt
Status: Offline
Administrator I AM GOD! :D
 
Join Date: Apr 2006
Location: brasil
Posts: 92
Rep Power: 10
aRt is on a distinguished road
Exclamation MAC SECURITY ISSUE! all passwords in cleartext !! :D

3.9 Clear Text Passwords in Swap File
Apple’s Security Framework does not use mlock() or equivalent to prevent passwords to be
swapped to disk. Therefore it is likely, that user passwords and other passwords from the
Keychain will be written to the swap file in clear text. You can verify this on your own Mac by
typing:
sudo strings /var/vm/swapfile0 |grep -A 4 -i longname

longname
Sart
password
XXXXX... (xxxxx... means password in clear text)
shell
--
longname
ogin.done
XTUM
password
XXXXX...
--
longname
XTUM
password
XXXXX...
XTUM

Last edited by aRt; 08-14-2006 at 02:03 AM.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #2 (permalink)  
Old 08-14-2006, 02:32 AM
bofors's Avatar
bofors
Status: Offline
Member
 
Join Date: May 2006
Posts: 78
Rep Power: 7
bofors is on a distinguished road
Default

Enabling "secure virtual memory" in SystemPreferences->Security should deal with this.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #3 (permalink)  
Old 08-14-2006, 03:43 PM
Crazor
Status: Offline
Junior Member
 
Join Date: Aug 2006
Posts: 8
Rep Power: 0
Crazor is on a distinguished road
Default

There is a reason why only root has access to the swapfile. This problem exists on any platform, I think, as long as the swapfile is not encrypted.
Probably system passwords can be prevented from being swapped out, but any application which holds passwords is prone to be swapped out anyway.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
Sponsored links Remove advertisements
Advertisement
Advertisement

Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
MacRumors: Apple Addresses Security Issue in Safari 3.1.2 for Windows hackint0sh Latest Headlines 0 06-20-2008 01:20 AM
MacNN: Security Update fixes Aperture 2.0 print issue hackint0sh Latest Headlines 0 03-27-2008 12:10 AM
[Negative Black] Possible methods of fixing this goddamn issue... Salmon-Face General 10 03-24-2008 12:21 AM
WiFi hotspot security (lack of) and VPN on the iPhone nematodirus General 1 12-17-2007 08:08 PM
Xtreme OS X Security bofors Using Leopard 56 04-07-2007 02:21 PM



All times are GMT +2. The time now is 03:26 AM.



Powered by vBulletin® Version 3.8.2
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.3.2 Ad Management by RedTyger
follow us on Twitter!

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105