Apple Open Firmware 4.1.7/4.1.8 - Insecure Password

Author: Macintosh Security
type: local
platform: osx
port: 
date_added: 2001-08-15  
date_updated: 2012-09-10  
verified: 1  
codes: OSVDB-86900  
tags:   
aliases:   
screenshot_url:   
application_url:   

raw file: 21070.txt  
source: https://www.securityfocus.com/bid/3186/info

A user who has set an Open Firmware password on their Apple system believes it to be safe when powered down. There is a tool that any user with access to the Finder can run in order to reveal the Open Firmware password without any decryption.

https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/21070.sit