Click, then enter an administrator name and password. Click Login Options. Click Join (or Edit). Click Open Directory Utility. Click in the Directory Utility window, then enter an administrator name and password. From the menu bar in Directory Utility: Choose Edit Enable Root User, then enter the password that you want to use for the root user. If you desire to change the root password on the mac, you just open up terminal in your logged in account and type: sudo passwd root (enter) this will prompt you to enter a new password for root 2x. A new root password! If you don’t know what to do with the root user, then you probably shouldn’t be attempting to change the password.
Right, this isn’t a good day for Apple.
As first reported on Twitter by Lemi Orhan Ergin, you can bypass just about any security dialog on Mac OSX High Sierra (10.13) by using the root user without a password.
Root Password Mac El Capitan
Open it up, then under one of the menu's it says enable root user, just do that and change the password. I find that using the CLI is easiar though. Just open up a terminal and type in 'sudo /bin/tcsh' then 'passwd root' and enter the root password.
Use the user root and click _Unlock _several times, you’ll eventually bypass the dialog and be granted root privileges. You can try it if you go to the Users & Groups settings screen and click Lock at the bottom.
I’d be very curious to know the technical reasons why this was possible in the first place.
Update: be sure to disable the root user after test
The need to reset or recover your admin password for your account can happen for a variety of reasons - we were once in this position when we messed around with settings on our Mac and then forgot. If you share your Mac with friends or family members and they forgot their password, odds are you'll be able to reset it for them. The key here is that you need access to an Admin user account.
Root Password For Mac Desktop
Turns out, testing this actually creates a root user without a password in the background! Make sure to disable the root user in System Preferences to prevent this from getting any worse than it already is.
For a quick workaround, set a non-default (aka: anything) password on the root user via the terminal.
Once a password has been set, it wont change to an empty value anymore.
Literature suite;Extensive support through Wiki and Forum; and tutorial and documentation in the form of a mind map.The map called Freeplane functions illustrates the main functions of Freeplane. Besides it provides an index with hyperlinks to the tutorial an documentation where you can read more.
Also applicable to Remote Management
If you’ve enabled Remote Management, anyone can log into your Mac using the root user with an empty password.
Woops.
Responsible disclosure?
Default Root Password For Mac
This issue was first reported on Twitter and is now getting widespread traction. This isn’t exactly a good way to disclose security issues, but I’m willing to bet the reporter perhaps didn’t think it would go this far in the media?
There’s an entire KB about reporting security issues to Apple, if someone ever feels the need to report similar security bugs.