[Warning] the "official" Windows messenger app is leaking your email and password - Android Software/Hacking General [Developers Only]

[Warning] the "official" Windows messenger app is leaking your email and password
Hello all!
I have seen that between 10 and 50 millions people are using the Windows Messenger app by Miyowa on Android.
Just to let you know, this app is leaking your email adress and username in clear text in logcat.
I created in 3 minutes a demo application that "steal" these credentials (and they are not stored in the app, that's just a demo, but if a was a bad guy, I could send that to my own server ;-)
https://play.google.com/store/apps/details?id=com.WazaBe.WindowsCredentials
One the app installed, just play a little bit with Messenger and open my app, it will display these credentials.
So the only advice I could give: uninstall immediatly Windows Live messenger!
{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}

All I can say is WOW!!!
Sent from my SPH-D710 using xda premium

profete162 said:
Hello all!
I have seen that between 10 and 50 millions people are using the Windows Messenger app by Miyowa on Android.
Just to let you know, this app is leaking your email adress and username in clear text in logcat.
I created in 3 minutes a demo application that "steal" these credentials (and they are not stored in the app, that's just a demo, but if a was a bad guy, I could send that to my own server ;-)
https://play.google.com/store/apps/details?id=com.WazaBe.WindowsCredentials
One the app installed, just play a little bit with Messenger and open my app, it will display these credentials.
So the only advice I could give: uninstall immediatly Windows Live messenger!
Click to expand...
Click to collapse
i dont use miyowa msn but some time i use MSN Messenger: Mercury
is some to miyowa? or are diferant thank you

profete162 said:
Hello all!
I have seen that between 10 and 50 millions people are using the Windows Messenger app by Miyowa on Android.
Just to let you know, this app is leaking your email adress and username in clear text in logcat.
Click to expand...
Click to collapse
Uninstalled, thank you for sharing!
That's a serious leak, have you contacted the developer also? Hopefully they fix that soon.

Yes, they seem to have taken my warning seriously.
App has been updated and promised a fix (v2,0,88)
I have currently no time to test it but I guess they did it!

Related

can a Chrome browser plugin steal my Google password?

i am looking for a way to schedule sending emails with my Gmail account. i came across Boomerang for Gmail which does exactly what i need it to. it installs as a plugin for Chrome browser and once installed, when i compose a new email in Gmail account, right next to the "send" button, there is now a new Boomerang send button.
what i need to know is if plugins like these can steal passwords. i know i should have thought about that before i installed it but it didn't occurred to me until after the fact. thanks for letting me know!
if permissions include access to cookies it can
Sent from my GT-I9100 using XDA App
They can easily steal your password if they're active when you type it in, but not after that.
Sent from my GT-P1000 using Tapatalk
As far as I am aware, unless they have some sort of keylogger, they cannot get your password, per-se.
However, (As also mentioned above), if they have access to cookies, they can login in your name. Additionally, some sites have the ability to hook in with google, and get "access" to your account if you approve it.
{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}
i got that prompt to allow or deny access as well.
DarthCaniac said:
As far as I am aware, unless they have some sort of keylogger, they cannot get your password, per-se.
However, (As also mentioned above), if they have access to cookies, they can login in your name. Additionally, some sites have the ability to hook in with google, and get "access" to your account if you approve it.
Click to expand...
Click to collapse
I could quite easily write a Chrome extension that popped up a window with your username and password in it, but it would have to capture them at a login screen, and not with a keylogger.
An extension has access to every control on every page that it is running.
Chrome would tell you, when you installed the extension, that it could access your google username and password though, so it could never do anything without you first allowing it to. Saying that though, there's a lot of people that just click 'Okay' without knowing what they're clicking!

[APP][2.2+] Etext (SMS to Email and Back)

Hello all,
I just released a free application/service that forwards your SMS messages to e-mail addresses you define, and also sends responses back when you reply to the received e-mails (coming from your own number). Etext uses Google's Cloud 2 Device Messaging (C2DM) to notify your phone without polling every x minutes, hence the Android 2.2 requirement. It's designed so that it can actually replace the default SMS application's notifications, and to be able to reply to incoming messages from any device that's able to receive e-mail, no matter where you are.
The application is brand new on the market, so it would be great if the XDA community could give it a try. Screenshots and a more thorough description can be found on the Android Market (or should I say Google Play). Below is a link, and a QR code that you can scan on your device. If you have any questions or suggestions you can always post here or e-mail me!
{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}
Hey!
Did a quick test this and it works well Will do more tests soon.
Was wondering what the real purpose is. I mean ... wouldn't SMS be more reachable than emails given that for email a net connection is necessary, while it is not necessary for SMS?
I'll be using this to have a record of my messages in my mail and occasionally to save a wee bit on my message bills!
Paparasee said:
Hey!
Was wondering what the real purpose is. I mean ... wouldn't SMS be more reachable than emails given that for email a net connection is necessary, while it is not necessary for SMS?
Click to expand...
Click to collapse
It bugged me that I couldn't receive SMS messages or reply to them when I was using my tablet (or any other device for that matter). That's basically why I started working on the application. It worked pretty well for myself, so I decided to implement C2DM and release it on the market. A plus is that I can now search for a name on GMail and get the text messages as well.

[FREE APP] My Mixtapez 250k users :)

My Mixtapez
Requirements:
Android 2.2+
Overview:
Stream or Download Official Mixtapes on your Android Device. We have more than 250k users and we just released our app to the Google Play Store. Hopefully we can see the same amount of success that we have from Getjar, Slideme, Amazon App store and Etc. Heres a couple of screenshots and our url to the market.
{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}
Download Here APK: URL: http://www.mediafire.com/?spbp8v1qgqckz9v
Android Marketplace
If anyone has any feedback regarding my application it would be much appreciated
Fricken Awesomeness. Thanks.
MoPhoACTV Initiative
Why do you need to give phone number unless this is a Phone number farming app ?
Sent from my GT-I9000 using xda premium
I think I just found a replacement for my Datpiff app. Btw, I absolutely love the icon too. Thanks Dev.
MoPhoACTV Initiative
scull2011 we are keeping the info because in the future we are are going to be a subscription based app kinda like pandora. We are going to recognize your app by phone number and email. Any more questions just ask.
moonzbabysh said:
I think I just found a replacement for my Datpiff app. Btw, I absolutely love the icon too. Thanks Dev.
MoPhoACTV Initiative
Click to expand...
Click to collapse
thanks we love the logo we just changed it. heres the old one
Great selection of mix tapes .
I don't really like having to give you my phone number, but I did it. You might want to rethink that requirement. It's gonna turn some people off. An email address should be enough for an account. It is with Pandora, Dropbox, Evernote, etc.
...and please, please, please. Make the app work in landscape, for tablet users.
i appreciate all the feedback, this is the first time i really put my app on any forums and i really want to thank everyone for all the suggestions. im going to try and remove the phone number on the next update.

[Q] Photo from email

how to download a photo that is embedded in an email ?!
i couldn't....
What's your email client?
That is, what are you reading email with?
michaelkenward said:
What's your email client?
That is, what are you reading email with?
Click to expand...
Click to collapse
the standard clint.
Fahad00 said:
the standard clint.
Click to expand...
Click to collapse
Which is? The one on the phone? What's that? (I have couple of "standard clients" on my android phone.)
Can you forward the message to an email account that you can access on a PC?
Is there an email accnt that can't be accessed through pc? If you are using the stock mail client. Once you open it. There will be a save option beside it after.
{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}
Sent from my HUAWEI MT7-TL10
yes the stock email clint.
the photo i want is in the email as background not as an attachment like you mentioned. so there is no save option.
i tried using the outlook app but it seems complicated.
michaelkenward said:
What's your email client?
That is, what are you reading email with?
Click to expand...
Click to collapse
that is stupid question .. on android phones u only can hav gmail for play store so that is standard
Simona Simmy said:
that is stupid question .. on android phones u only can hav gmail for play store so that is standard
Click to expand...
Click to collapse
You seem to have missed the point of the Android environment. I have various options on my devices. One of them is Mailwasher. I can even use my browser.
And that is just the tip of the iceberg. Try these:
K-9 Mail – Android Apps on Google Play
myMail—Free Email Application – Android Apps on Google Play
All Email Providers – Android Apps on Google Play
I could go on – there's a heap of them, a dozen or more – but don't want to rub salt into the wounds.
---------- Post added at 10:16 PM ---------- Previous post was at 10:09 PM ----------
Fahad00 said:
the photo i want is in the email as background not as an attachment like you mentioned. so there is no save option.
Click to expand...
Click to collapse
That makes life more complicated.
But email is email. It isn't locked to the device you use. (Ignore Simona Simmy. They clearly don't have a clue. What does the play store have anything to do with your email?)
Can you forward the message to a PC account that might have a bit more capability?
Or is that what you meant by the Outlook app?
I can get at all of my email accounts on my Android devices and on my PC. So, if I get an email through gmail, I can also access it from my PC, first with my browser, then with any other email client I like.

[APP] NordVPN is looking for Android beta testers! Free premium accounts!

{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}
Hello community!
my name is Chris and I work at NordVPN. Currently, we are in the developing phase of our native Android app and are looking for smart guys to break it. Oh, I mean test it In the beta testing phase we are giving three-month subscriptions to anyone signed-up. And there's almost nothing for you to do, just download our beta app and use it. If you find a bug, you can report it (if you want). Or if you want an awesome feature or have a great idea - post it to us and we'll certainly do it!
Subscription page is here: https://nordvpn.com/blog/looking-for-android-app-beta-testers/
Just enter your email and we'll activate your subscription as soon as Beta testing rolls out. And it should go live today or tomorrow
If you have any questions, just ask here or email us via website :good:
P.S. subscriptions are active on any device with no restrictions
Thank you, I'll try it out?
Thanks, will give it a go.
link ?>
manhar2108 said:
link ?>
Click to expand...
Click to collapse
It's in the description :
https://nordvpn.com/blog/looking-for-android-app-beta-testers/
Regards.
Hi,
Having a bit of trouble with the beta app, it will not accept my password, "this password is incorrect" every time.
The username and password is correct, both the windows, mac and android openvpn clients all log in ok.
The username and password log into my account on the website, there is plenty of time remaining on my subscription.
I have changed the password on my account several times, all other clients work with the new passwords.
I have talked to support chat on the website and logged in to the beta client with a test account they provided, this worked perfectly.
I have rebooted, reinstalled and updated the client, no change.
I am running android 5.1.1 (rooted stock rom) on an xperia z2
Any suggestions?
I am having the same password issues. I can log in easily in win 8.1. I can log onto the Nord VPN web site. I cannot log in using the Android app -"password not correct." I have tried two separate Android 5 devices. I have tried changing passwords, deleting and reinstalling the app, rebooting the devices, - no joy. I can't login on the Android app despite being able to log in to the Nord VPN website with the same credentials on the same Android device.
I am supposed to be beta testing this app. Difficult to do when I can't launch it.
I'm also having the issue of not being able to sign in due to the password not being recognised. Running Android 4.4.2 on Samsung Galaxy S3.
Thank you. I'll try it out. I'm into its service but couldn't buy it yet. This is a great chance.
Just so everybody knows, they vpn solution is really slow and they 30 day money back policy is a scam.
NordVPN Premium Account or Nord VPN Crack? Which One Is Best
Many People want to access nordvpn for free but its not possible, We have reviewed the NordVPN app and also organized a giveaway for NordVPN Premium Account so do please check out. hamachix.com
Edit: thanks for updating 4 year old topic.

Categories

Resources