<?xml version="1.0" encoding="UTF-8"?> <rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:wfw="http://wellformedweb.org/CommentAPI/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
> <channel><title>ByteChip &#187; google password recovery</title> <atom:link href="http://www.bytechip.com/tag/google-password-recovery/feed/" rel="self" type="application/rss+xml" /><link>http://www.bytechip.com</link> <description>Technology Blog with updated news about Mobiles, Gadgets, Laptops, Windows, Linux, Tutorial, Internet, Web</description> <lastBuildDate>Mon, 23 Jan 2012 19:48:23 +0000</lastBuildDate> <language>en</language> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=3.3.1</generator> <item><title>Find your friends gmail password</title><link>http://www.bytechip.com/2009/10/log-into-friends-gmail-account-without-knowing-his-password/</link> <comments>http://www.bytechip.com/2009/10/log-into-friends-gmail-account-without-knowing-his-password/#comments</comments> <pubDate>Mon, 12 Oct 2009 09:41:51 +0000</pubDate> <dc:creator>Ramkumar</dc:creator> <category><![CDATA[Windows]]></category> <category><![CDATA[crack]]></category> <category><![CDATA[gmail hack]]></category> <category><![CDATA[gmail password hack]]></category> <category><![CDATA[google password recovery]]></category> <category><![CDATA[gtalk hack]]></category> <category><![CDATA[gtalk password]]></category> <category><![CDATA[gtalk password hack]]></category> <category><![CDATA[gtalk password recovery]]></category> <category><![CDATA[hack]]></category> <category><![CDATA[password]]></category> <category><![CDATA[step by step gtalk password]]></category> <category><![CDATA[step by step guide gmail password]]></category> <guid
isPermaLink="false">http://www.bytechip.com/?p=275</guid> <description><![CDATA[Gtalk stores its account information in the Windows Registry, that too in text format. Everything in it except the password in unencrypted. With this flaw we can login into a friends’ gmail account without knowing their password.]]></description> <content:encoded><![CDATA[<p><!--[if gte mso 10]> <mce:style><!<br
/> /* Style Definitions */<br
/> table.MsoNormalTable<br
/> {mso-style-name:"Table Normal";<br
/> mso-tstyle-rowband-size:0;<br
/> mso-tstyle-colband-size:0;<br
/> mso-style-noshow:yes;<br
/> mso-style-parent:"";<br
/> mso-padding-alt:0in 5.4pt 0in 5.4pt;<br
/> mso-para-margin:0in;<br
/> mso-para-margin-bottom:.0001pt;<br
/> mso-pagination:widow-orphan;<br
/> font-size:10.0pt;<br
/> font-family:"Times New Roman";<br
/> mso-ansi-language:#0400;<br
/> mso-fareast-language:#0400;<br
/> mso-bidi-language:#0400;}<br
/> --> <!--[endif]--></p><p
class="MsoNormal">I have quoted in one of my old article ( <a
href="../?p=241">http://www.bytechip.com/?p=241</a> ) that gtalk has a serious security issue, which has not been rectified till now. Using this flaw we can login into a friends’ gmail account without knowing their password.</p><p
class="MsoNormal">Gtalk stores its account information in the Windows Registry, that too in text format. Everything in it except the password in unencrypted.</p><p
class="MsoNormal">I wonder how Google considers this as a safety measure. Though we cannot view the password directly from Windows registry, we can use the encrypted password to login to gtalk or gmail, even without knowing the actual password.</p><p
class="MsoNormal">Here is the step by step guide to get an encrypted password from another computer and use it to login in your computer.</p><p
class="MsoNormal"><strong>Note: </strong>You need to have access to the other computer to get the encrypted text, however if you are good in programming, you can use your skills in making a bot which can retrieve the encrypted passwords and mail to your inbox. Also you can access their encrypted password, if the user has chosen to remember his password atleast once during sign in.</p><p
class="MsoNormal"><strong><span> </span>In friend’s System</strong></p><ol
style="margin-top: 0in;" type="1"><li
class="MsoNormal"><span> </span>Open “<strong>Run</strong>” windows, this can be done by      clicking on “Start menu” or pressing “Window Key + R”.</li><li
class="MsoNormal">Type      “regedit” and Click on “OK”</li></ol><div
id="attachment_278" class="wp-caption alignnone" style="width: 357px"><img
class="size-full wp-image-278" title="Run" src="http://www.bytechip.com/wp-content/uploads/2009/10/corel003.jpg" alt="corel003 Find your friends gmail password" width="347" height="186" /><p
class="wp-caption-text">Run window</p></div><ol
style="margin-top: 0in;" type="1"><li
class="MsoNormal">This      will open the Windows Registry Editor.</li><li
class="MsoNormal">Select      the Hive <strong>HKEY_CURRENT_USER</strong>.</li></ol><p><img
class="alignnone size-full wp-image-288" title="corel015" src="http://www.bytechip.com/wp-content/uploads/2009/10/corel015.jpg" alt="corel015 Find your friends gmail password" width="474" height="349" /></p><ol
style="margin-top: 0in;" type="1"><li
class="MsoNormal">Then      under that select <strong>HKEY_CURRENT_USER -&gt; Software -&gt; Google -&gt;      Google Talk -&gt; Accounts</strong></li><li
class="MsoNormal">This      will list the accounts he that person the logged in with his computer.</li><li
class="MsoNormal">Open the      account you want to get password, in my case I have selected <a
href="mailto:rkdperil@gmail.com">rkdperil@gmail.com</a></li><li
class="MsoNormal">In the      right panel you can see the Field “<strong>pw</strong>” , this contains the encrypted      password of that gmail account.</li></ol><div
id="attachment_289" class="wp-caption alignnone" style="width: 484px"><img
class="size-full wp-image-289" title="corel016" src="http://www.bytechip.com/wp-content/uploads/2009/10/corel016.jpg" alt="corel016 Find your friends gmail password" width="474" height="349" /><p
class="wp-caption-text">Copy the string in &quot;pw&quot; field</p></div><ol
style="margin-top: 0in;" type="1"><li
class="MsoNormal">This      encrypted password is independent of the computer used.</li><li
class="MsoNormal">So      this password can be copied to some other computer and we can login      through this.</li></ol><p
class="MsoNormal"><strong>In Your System</strong></p><ol
style="margin-top: 0in;" type="1"><li
class="MsoNormal">Open      Gtalk, in the login form , type your friend’s id and some temporary      password and select “ Remember Password“</li><li
class="MsoNormal">Click      on Sign in button, the login will fail.</li><li
class="MsoNormal">Now      open your Windows Registry and goto the gtalk account information folder      (HKEY_CURRENT_USER -&gt; Software -&gt; Google -&gt; Google Talk -&gt;      Accounts)</li><li
class="MsoNormal"><span> </span>Locate your friend’s email id there,      select it. You double click the “pw” field can see some random value.</li><li
class="MsoNormal"><span> </span>Now replace it with the encrypted      password you got from your friend’s computer and paste it here.</li><li
class="MsoNormal">Download a gTalk password recovery software, there are lots of such tool available.</li><li
class="MsoNormal">Run the recovery program and it will successfully decrypt you friend&#8217;s password.</li><li
class="MsoNormal">That’s      it. You are done.</li></ol><p
class="MsoNormal"><strong>Hope you make the most out of this within Google solves this vulnerability.</strong></p><p
class="MsoNormal"> ]]></content:encoded> <wfw:commentRss>http://www.bytechip.com/2009/10/log-into-friends-gmail-account-without-knowing-his-password/feed/</wfw:commentRss> <slash:comments>23</slash:comments> </item> </channel> </rss>
