Author Topic: [Question] gmail - read mails with application specific password  (Read 1432 times)

0 Members and 1 Guest are viewing this topic.

Offline Deque

  • P.I.N.N.
  • Global Moderator
  • Overlord
  • *
  • Posts: 1203
  • Cookies: 518
  • Programmer, Malware Analyst
    • View Profile
Hello guys,

I have a little question. For gmail you can use the 2-step-authentification, which is explained here: https://support.google.com/mail/bin/answer.py?hl=en&answer=1173270

I dissected a stealer and extracted gmail account and pass from it. The password is an application specific password, which means I can't log in with it at gmail.

I would like to log in to the gmail account, at least to read the mails.
Which possibilities to you see to go on with this information?

Regards
Deque

Offline parad0x

  • VIP
  • Royal Highness
  • *
  • Posts: 638
  • Cookies: 118
    • View Profile
Re: [Question] gmail - read mails with application specific password
« Reply #1 on: January 26, 2013, 07:35:41 am »
Upto what I understood,you can login to those applications which requires you rgmail account and do not verify if the password is correct or not.You can try to login in any application which will retrieve all your emails from your account.

Offline Deque

  • P.I.N.N.
  • Global Moderator
  • Overlord
  • *
  • Posts: 1203
  • Cookies: 518
  • Programmer, Malware Analyst
    • View Profile
Re: [Question] gmail - read mails with application specific password
« Reply #2 on: January 26, 2013, 07:45:32 am »
Upto what I understood,you can login to those applications which requires you rgmail account and do not verify if the password is correct or not.You can try to login in any application which will retrieve all your emails from your account.

I tried with thunderbird, but it says the user-password-combination is not valid.

Edit: Could it be that only one application is able to use this combination?
I don't think that the stealer is outdated. It seems relatively fresh, only one AV on Virustotal marks it as infected.
« Last Edit: January 26, 2013, 07:56:36 am by Deque »

Offline Daemon

  • VIP
  • Baron
  • *
  • Posts: 845
  • Cookies: 153
  • A wise man fears a gentle mans anger
    • View Profile
Re: [Question] gmail - read mails with application specific password
« Reply #3 on: January 26, 2013, 08:26:41 am »
Try it with outlook, and all the otger mahor mail client. I didnt read ot very thoroughly but worst case scenario youll need access to their specific computer to read their mail client on said comouter.
At least thats what i got from it

Sorry for spelling, tequila+phone == bad combination
This lifestyle is strictly DIY or GTFO - lucid

Because sexploits are for h0edays - noncetonic


Xires burns the souls of HF skids as a power supply