• On TechRepublic: 10 cool USB flash drive tricks
advertisement
June 12, 2003 8:00 AM PDT

Potential Jaguar Cache Cleaner security hole

by CNET staff
  • Font size
  • Print
  • Post a comment

There is an apparent security flaw in the shareware utility Jaguar Cache Cleaner that will expose the administrator password via simple Terminal commands.

While deleting a cache or performing another process in Jaguar Cache Cleaner, you can view the Mac OS X administrator user's password in the Terminal by typing "ps -aux" or via any utility that shows other users' processes (such as Process Wizard). This bug was discovered by VersionTracker feedback poster sjonke.

Exploiting this security hole from the Terminal (using the "ps -aux" command) requires access to any account on the machine, and is open to remote infiltration. Exploiting this hole using a separate application such as Process Viewer merely requires physical access to a machine.

There are several processes, such as the "cron" maintenance routines automatically performed by Mac OS X, that access root user privileges without revealing the administrator password. We are not sure why the developer of Jaguar Cache Cleaner chose the less secure route of enabling the administrator password, thus allowing it to be easily viewed by unauthorized users.

UPDATE: MacFixIt reader Rob Morton notes that this is actually a problem with any AppleScript Studio application:

"It is simply the way the AppleScript command do shell script " password AdminPassword with administrator privileges. Unless Apple changes the way that works, it will be a security risk. It really just means that while the application is running, you should not leave your machine and should not allow shell access to your machine from people you do not trust."

Feedback? Late-breakers@macfixit.com.

Resources

  • sjonke
  • Late-breakers@macfixit.com
  • More from Late-Breakers
  • Recent posts from MacFixIt
    Pixelated or fuzzy icons in Snow Leopard
    Snow Leopard: iChat restricting minimum chat window width
    Hack enables 10.6.2 on Atom processors
    Weekly Utilities Update: WhatSize, CoolBook, VisualRoute, more...
    Overcoming missing Appletalk printer connectivity in Snow Leopard
    Terminal fun: Options for printing folder and subfolder contents
    Aperture How-To: Add a watermark to your photographs
    Snow Leopard: Finder not opening files when double-clicked

    Navigate MacFixIt

    • Help
    • Archives
    • Utilities
    • Forums
    advertisement
    Click Here

    About MacFixIt

    MacFixIt is CNET's troubleshooting resource for all things Mac. The information here helps you navigate the ins-and-outs of Mac ownership with how-tos, troubleshooting information, news, reviews, and more.

    Add this feed to your online news reader

    MacFixIt topics