EvilZone

Hacking and Security => Hacking and Security => : Deque January 26, 2013, 06:04:47 AM

: [Question] gmail - read mails with application specific password
: Deque January 26, 2013, 06:04:47 AM
Hello guys,

I have a little question. For gmail you can use the 2-step-authentification, which is explained here: https://support.google.com/mail/bin/answer.py?hl=en&answer=1173270

I dissected a stealer and extracted gmail account and pass from it. The password is an application specific password, which means I can't log in with it at gmail.

I would like to log in to the gmail account, at least to read the mails.
Which possibilities to you see to go on with this information?

Regards
Deque
: Re: [Question] gmail - read mails with application specific password
: parad0x January 26, 2013, 07:35:41 AM
Upto what I understood,you can login to those applications which requires you rgmail account and do not verify if the password is correct or not.You can try to login in any application which will retrieve all your emails from your account.
: Re: [Question] gmail - read mails with application specific password
: Deque January 26, 2013, 07:45:32 AM
Upto what I understood,you can login to those applications which requires you rgmail account and do not verify if the password is correct or not.You can try to login in any application which will retrieve all your emails from your account.

I tried with thunderbird, but it says the user-password-combination is not valid.

Edit: Could it be that only one application is able to use this combination?
I don't think that the stealer is outdated. It seems relatively fresh, only one AV on Virustotal marks it as infected.
: Re: [Question] gmail - read mails with application specific password
: Daemon January 26, 2013, 08:26:41 AM
Try it with outlook, and all the otger mahor mail client. I didnt read ot very thoroughly but worst case scenario youll need access to their specific computer to read their mail client on said comouter.
At least thats what i got from it

Sorry for spelling, tequila+phone == bad combination