{"id":28,"date":"2008-03-08T12:31:23","date_gmt":"2008-03-08T19:31:23","guid":{"rendered":"http:\/\/www.brunerd.com\/blog\/2008\/03\/08\/ard-security-awareness-standard-user-can-run-root-commands\/"},"modified":"2008-03-08T14:10:59","modified_gmt":"2008-03-08T21:10:59","slug":"ard-security-awareness-standard-user-can-run-root-commands","status":"publish","type":"post","link":"https:\/\/www.brunerd.com\/blog\/2008\/03\/08\/ard-security-awareness-standard-user-can-run-root-commands\/","title":{"rendered":"ARD Security Awareness (Standard User can run root commands)"},"content":{"rendered":"<p>Did you know a Standard user can run commands as root via ARD?<br \/>\nThis seems really odd doesn&#8217;t it? Why would this be necessary? The thing that gets me is how in Tiger you had to <a href='http:\/\/www.brunerd.com\/blog\/wp-content\/uploads\/2008\/03\/tigerardpane.png' title='Tiger ARD Pref Panel'>explicitly <\/a> grant each user the privileges after starting the ARD service. But in Leopard, when you start the service All Users is the default.<\/p>\n<p>So let&#8217;s take a walkthrough of what I was looking into this Friday evening:<br \/>\nFind a Mac running Leopard<br \/>\nTurn on Remote Management (yes you <strong>do <\/strong>have to be admin to do this)<br \/>\n<a href='http:\/\/www.brunerd.com\/blog\/wp-content\/uploads\/2008\/03\/remotemanagementleo.png' title='Remote Management Pref Pane'>Notice<\/a> the default is for All Users to have access.<br \/>\n<a href='http:\/\/www.brunerd.com\/blog\/wp-content\/uploads\/2008\/03\/testuser.png' title='Test User in Account Pref Pane'>Create<\/a> a Standard user in Leopard<br \/>\nGreat, now go get a machine with ARD on it.<br \/>\n<a href='http:\/\/www.brunerd.com\/blog\/wp-content\/uploads\/2008\/03\/ardinfosheet.png' title='ARD Info Sheet'>Add the computer <\/a>to your ARD list using the standard user&#8217;s credentials<br \/>\nSend it a <a href='http:\/\/www.brunerd.com\/blog\/wp-content\/uploads\/2008\/03\/unixcommand.png' title='Unix Command'>Unix Command<\/a> to run as root (<code>touch \/HaxorWasHere<\/code>, in this case)<br \/>\n<a href='http:\/\/www.brunerd.com\/blog\/wp-content\/uploads\/2008\/03\/newfile.png' title='A new File'>Notice <\/a>the new file owned by root in a place where no standard user can put things.<\/p>\n<p>Interestingly, perhaps because I had done this a number of times, and Leopard got confused after a while, I tried deleting through Finder (while logged in as &#8216;test&#8217; but authenticating as administrator) and got <a href='http:\/\/www.brunerd.com\/blog\/wp-content\/uploads\/2008\/03\/trash.png' title='No trash for you!'>this message<\/a><\/p>\n<p>OK that oddity aside, here&#8217;s another: You don&#8217;t need to have <a href='http:\/\/www.brunerd.com\/blog\/wp-content\/uploads\/2008\/03\/sharing3.png' title='Sharing Panel, Everything Checked'>everything checked<\/a> in ARD&#8217;s preferences to accomplish this, here&#8217;s the <a href='http:\/\/www.brunerd.com\/blog\/wp-content\/uploads\/2008\/03\/minimum.png' title='Minimum Access to allow root execution of Unix command'>bare minimum <\/a>:<\/p>\n<li>Generate reports\n<li>Open and quit applications<\/li>\n<li>Change settings<\/li>\n<li>Delete and replace items<\/li>\n<li>Restart and shut down<\/li>\n<li>Copy items<\/li>\n<p>Page 66 of the ARD manual does go into detail what needs to be turned on to run a Unix command, but why not just have a check box: Run Unix Command? Also, Generate Reports isn&#8217;t listed as one of them, but unless it was checked I got <a href='http:\/\/www.brunerd.com\/blog\/wp-content\/uploads\/2008\/03\/notauth.png' title='Not Authorized'>this<\/a>?<\/p>\n<p>Now I&#8217;m not saying this is an out and out security breach, no, because it requires admin privileges to turn on the service and add the user, but it does show how simply checking a check box as an admin could open your up your Mac to Bad Things\u2122 if a standard user on your family computer has a weak password and someone else has ARD in a dark alley&#8230; well, you know what I mean. This just doesn&#8217;t seem right. Standard users should only be able to do standard user things, even in the magical world of ARD.<\/p>\n<p>See the <a href=\"http:\/\/images.apple.com\/server\/docs\/ARD3.2_AdminGuide.pdf\">ARD manual<\/a> pages 65-68 for Apple&#8217;s wording on the Remote Management Preference pane permissions. See if it seems clear that Standard users given &#8216;administrator&#8217; (ARD administrator in this case) privileges can run as root. Leave a comment and let me know what you think, thanks.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Did you know a Standard user can run commands as root via ARD? This seems really odd doesn&#8217;t it? Why would this be necessary? The thing that gets me is how in Tiger you had to explicitly grant each user the privileges after starting the ARD service. But in Leopard, when you start the service [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4,8],"tags":[],"class_list":["post-28","post","type-post","status-publish","format-standard","hentry","category-os-x","category-security"],"_links":{"self":[{"href":"https:\/\/www.brunerd.com\/blog\/wp-json\/wp\/v2\/posts\/28","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.brunerd.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.brunerd.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.brunerd.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.brunerd.com\/blog\/wp-json\/wp\/v2\/comments?post=28"}],"version-history":[{"count":0,"href":"https:\/\/www.brunerd.com\/blog\/wp-json\/wp\/v2\/posts\/28\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.brunerd.com\/blog\/wp-json\/wp\/v2\/media?parent=28"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.brunerd.com\/blog\/wp-json\/wp\/v2\/categories?post=28"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.brunerd.com\/blog\/wp-json\/wp\/v2\/tags?post=28"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}