lundi 4 mai 2015

Email users - Are you bothered that your passwords are being stored in plain text topic


I looked into the databases for Boxer & Gmail and found that they both are storing passwords in plain text. Boxer I found only stored my exchange password(which is my most important) and Gmail was storing all. I would of been fine with any type of password hashing but having them in plain text is completely unacceptable to me, anyone think the same?

Here are some example queries to show your passwords(must be rooted)

Boxer

Code:


su
/system/xbin/sqlite3 /data/data/com.boxer.email/databases/EmailProvider.db "SELECT password FROM HostAuth WHERE protocol IN ('eas')"


Gmail

Code:


su
/system/xbin/sqlite3 /data/data/com.google.android.gm/databases/EmailProvider.db "SELECT password FROM HostAuth WHERE protocol IN ('gEas')"



xda-developers


  1. Hi therе, all the time i used to check blog posts ɦere in thе еarly hоurs in tҺе break of day, as i likе to gain knowledge οf more aand mοre.

    RépondreSupprimer
  2. New and used forklift driving system Forklift training
    course will include the elements about what is
    internal mechanism. s injuries and treatment is done by medical professionals who, absent evidence
    to the contrary, give medical treatment that is fair and reasonable and medically necessary.

    Take care to hire an attorney that is knowledgeable, personable
    experience and makes you feel safe.

    RépondreSupprimer

Remarque : Seul un membre de ce blog est autorisé à enregistrer un commentaire.