emaail app vulnerability - Windows Phone 8 Development and Hacking

i have usual email in my box, which kill microsoft mail application, when i try to open it.
so, we can abuse this app in some way, for example, run own code, if it overflows stack. What privilegies this application have?
sorry for my english

can you upload email data anywhere?

ultrashot said:
can you upload email data anywhere?
Click to expand...
Click to collapse
it contains my real name.
i may forward it to you for test, pm me. i want to be sure this letter will not be spread over all internet

mailwl said:
it contains my real name.
i may forward it to you for test, pm me. i want to be sure this letter will not be spread over all internet
Click to expand...
Click to collapse
What email service are you using?

Yandex.ru but i am unsure it mean

Ah I see... wonder if its to do with the service or your actual account... Did you send the email data to @ultrashot . We might be able to exploit this..

doesn't hang email app when it is forwarded, unfortunately
build 10328
I will try to send original data

ultrashot said:
doesn't hang email app when it is forwarded, unfortunately
build 10328
I will try to send original data
Click to expand...
Click to collapse
I have an idea: @mailwl
Don't forward it
Setup Outlook
Save message as .eml
(optional) Send it to yourself and test if openning this file breaks e-mail client.
Send this file to ultrashot

Email runs in the COMMSAPPLICATIONS chamber, which is sandboxed but still has pretty good privileges. Getting arbitrary code execution will not be easy even if it's a straightforward exploitable buffer overflow, since WP8 has a lot of exploit mitigations in place, but it should be possible especially since we *can* get ACE in our own chamber easily, which means we can examine certain elements of system state.

edit: remove links

url of picture https://mail.yandex.ru/message_part...&name=avatar-mk-square-830191244-square80.png

the browser eat this link

Hmm... Do you still have a cached version on your device?

wp8 device is not my preffered one (i use sony xperia z in real life). i doesnt understand how email app works. in mail web ui i set this email status for not readed, and it do not appear in email app. i cant even make the video of killing email app while opening the certain email

Hmm....was the crash caused by that image? Does any other email crash the app?

TheInterframe said:
Hmm....was the crash caused by that image? Does any other email crash the app?
Click to expand...
Click to collapse
i think the image is cause. i've got tons similar emails, every opens without any problems.
can anyone create the mail with this broken link inside?

Related

GMail - can send but can't receive

can anyone help? I've setup my gmail account in messaging, and can send to myself and others using messaging (send and receive sends fine), BUT I can't get it to receive! pop and smtp servers are setup ok but when I send and receive I get nothing back. I can logon onto my gmail account and see the email sitting quite happily in my inbox.
any ideas?
Hi, I imagine you already have your issue fixed, but if not, are you allowing pocket outlook to auto config the settings?, I skipped this the first few times when first setting my email up, and it seems I always had something wrong, so I let the auto config do its thing, and it works beautifully with gmail.
well, i've stiil not got it working yet, but i'm going through the auto setup as we "speak". so i'll keep you posted.
MM.
how long does the auto setup normally take? it's been sat at the downloading stage for 30 mins now!
Dont know if youve seen this but theres a new app from google for gmail, its java and i couldnt get it to work but others may have success, anyway you can grab it from http://gmail.com/app (using your mobiles browser)
That app doesn't work with the midlet manager on the TyTn
got the same problem with my gmail and also the same problem with the auto configuration. does anyone have gmail working for both sending and receiving? if so can you post the settings? thanks
And me, I cannot send but receive. I was use defalts setting for gmail. If any one want to set by defalts, you must be online! Can any one resolve my problem?
pop.gmail.com:995
smtp.gmail.com:465
no ssl
no domain
use authentification, outgoing settings same
mine is set to connect and check every 15 minutes, and get headers, and 999kb of body.
I just set up my two gmail addys a day ago, I did a hard reset to fix a few issues, all I do is put in my gmail addy, and password when it asks, and it working in minutes.
I didn't pay special attention to your carriers, but I think I might have had issues when I used medianet [email protected], I pay for the pdaconnect plan now, resco radio wouldn't work on wap either.
I dunno what to tell you for sure, but if any of you use cingular, you might give the [email protected] settings a try, but I wouldn't plan on using them permanently you might get a crazy bill.
I'm sure the other carriers have corresponding settings, and I'm just guessin the problem, but that is the only possible difference in our devices, and I'm not sure about your connection.
edit: I don't think any of you are on cingular, I seen tmobile, but I really don't have any ideas on what all the different carriers offer.
Just make sure in GMail on your c mputer you go to settings, tab forward and pop and set up gmail to forward messages to POP ONLY from now on. If you have a lot of messages in Gmail it will take forever otherwise.
Hope this helps.
rilot said:
That app doesn't work with the midlet manager on the TyTn
Click to expand...
Click to collapse
Actually found a way to get it to work
http://msmobiles.com/news.php/5729.html
Gonna try sky mobile jar using this technique too.
msmobiles.com says that the latest version (6.1) of the IBM J9 JVM for CLDC runs Gmail just fine. Have anyone tried it?
Yes it works, anyone know of a good link to d/l the jar file for sky by mobile
UPDATE
Tried doing sky by mobile app using this method can enter login details but cannot click or use the login key on screen so same as manually installing the jar using default midlet app, very annoying so close yet so far.
rilot said:
That app doesn't work with the midlet manager on the TyTn
Click to expand...
Click to collapse
try this http://www.cjmillisock.com/2006/11/how-to-get-gmail-mobile-for-your-t.html
shahril said:
try this http://www.cjmillisock.com/2006/11/how-to-get-gmail-mobile-for-your-t.html
Click to expand...
Click to collapse
TyTN already does have Java VM installed.
rilot said:
That app doesn't work with the midlet manager on the TyTn
Click to expand...
Click to collapse
Correct, I just installed it for nothing.
joedoe said:
TyTN already does have Java VM installed.
Click to expand...
Click to collapse
Then why mine wasn't able to run Gmailapp until I have installed a Java VM?
szlevi said:
Then why mine wasn't able to run Gmailapp until I have installed a Java VM?
Click to expand...
Click to collapse
You haven't install a Java VM but one more Java VM, which runs Java applications in a different way.
joedoe said:
You haven't install a Java VM but one more Java VM, which runs Java applications in a different way.
Click to expand...
Click to collapse
Possibly but it still doesn't answer the question: why was my TyTn unable to run any Java with its shipping OS?

gmail drive for windows mobile?

It is known that gmail account can be simulated as a new drive on your PC by an application called "GMail Drive shell extension". http://www.viksoe.dk/code/gmail.htm
For Symbian there is also a program "GSpaceMobile" which can do that job. https://www.ibomobi.com/home/gspacemobile_free
So I wonder if there is such a tool for WM system which can simulate a gmail account as a network disk or some guy is willing to develop one ?
Thanks.
Bump.
This is actually a really good idea.
sounds like a neat idea, I might try to see what this would take.
Bump.
With bated breath and whisp'ring humbleness I wait for those more skilled than I take on this task.
Seems like a great idea.
Sounds like a Really useful thing to have please have a go someone
Wow! This does sound very interesting.....
i had the same idea!
but it is forbidden in the term of use of gmail...
My account has been locked
If we detect abnormal usage that may indicate that your account has been compromised, we may temporarily disable access. It will take between one minute and 24 hours for access to be reinstated, depending on the behavior detected by our system.
Unusual account activity includes, but is not limited to:
1. Receiving, deleting, or downloading large amounts of mail via POP or IMAP in a short period of time. If you're getting the error message, 'Lockdown in Sector 4,' you should be able to access Gmail again after waiting 24 hours.
2. Sending a large number of undeliverable messages (messages that bounce back).
3. Using file-sharing or file-storage software, browser extensions, or third party software that automatically logs in to your account.
4. Leaving multiple instances of Gmail open.
5. Browser-related issues. Please note that if you find your browser continually reloading while attempting to access your Inbox, it's probably a browser issue, and it may be necessary to clear your browser's cache and cookies.
If you feel that you have been using your Gmail address according to the Gmail Terms of Use, please contact us.
idsk said:
i had the same idea!
Click to expand...
Click to collapse
If you have the skill to code a gmail drive, how about this much simpler idea- an app which automatically e-mails your pictures to a g-mail account, and another app on your desktop which automatically downloads the pictures to your desktop and deletes them.
The advantage of using gmail in the middle is that the process becomes asynchronous - your pc does not have to be on to work and neither does your phone have to be contactable for your pc to download the photos.
Surur
idsk said:
i had the same idea!
.....
3. Using file-sharing or file-storage software, browser extensions, or third party software that automatically logs in to your account.
.....
Click to expand...
Click to collapse
Doesn't that include pretty much any and all automated checking, such as push mail polling and thunderbird (imap / pop) clients ?
That's pretty restrictive wording.. much like the snafu with the Chrome release, where they stated "anything you enter via forms in the browser online is now copyright google" - they had to fix that after a large public outcry.
surur said:
If you have the skill to code a gmail drive, how about this much simpler idea- an app which automatically e-mails your pictures to a g-mail account, and another app on your desktop which automatically downloads the pictures to your desktop and deletes them.
The advantage of using gmail in the middle is that the process becomes asynchronous - your pc does not have to be on to work and neither does your phone have to be contactable for your pc to download the photos.
Surur
Click to expand...
Click to collapse
Check out PocketPicasa which does just that. Well it gets them as far as Google anyway, then use Picasa 3 on the desktop to retrieve them.
deedee said:
Check out PocketPicasa which does just that. Well it gets them as far as Google anyway, then use Picasa 3 on the desktop to retrieve them.
Click to expand...
Click to collapse
Picassa is a heavy client, and from my checking does not do automated downloads. I would not want to have it running in the background on my desktop all the time.
Actually I have already found a VBA script for outlook that will automatically save picture attachments from an e-mail folder to my desktop, so all I really need is the windows mobile side to automatically e-mail the pictures (although a special purpose dedicated pair would be even better)
Surur
Great idea, bump.
and...
idsk said:
i had the same idea!
but it is forbidden in the term of use of gmail...
My account has been locked
If we detect abnormal usage that may indicate that your account has been compromised, we may temporarily disable access. It will take between one minute and 24 hours for access to be reinstated, depending on the behavior detected by our system.
Unusual account activity includes, but is not limited to:
1. Receiving, deleting, or downloading large amounts of mail via POP or IMAP in a short period of time. If you're getting the error message, 'Lockdown in Sector 4,' you should be able to access Gmail again after waiting 24 hours.
2. Sending a large number of undeliverable messages (messages that bounce back).
3. Using file-sharing or file-storage software, browser extensions, or third party software that automatically logs in to your account.
4. Leaving multiple instances of Gmail open.
5. Browser-related issues. Please note that if you find your browser continually reloading while attempting to access your Inbox, it's probably a browser issue, and it may be necessary to clear your browser's cache and cookies.
If you feel that you have been using your Gmail address according to the Gmail Terms of Use, please contact us.
Click to expand...
Click to collapse
That hardly seems like a problem. Create a second account to use with your cell. If they lock it then its a lot less troubling. Besides, they don't monitor this kind of stuff. I've been using the same concept on my pc for a long time. Being able to have a network hdd on my phone and pc would be supurb!
bumping for the greatness of the idea
Doesn't anyone with developing skills see a use for this?
I have scoured everywhere for a wm solution to gmail drive. gonna keep watch on this, hopefully someone makes it happen.
The Idea is widespread
The idea's popped up in other places as well:
http://forum.xda-developers.com/showthread.php?t=433913
Also, I am recalling that I looked into this concept years back using Xdrive by AOL. From what I remember they released an experimental mobile version but have since shut it down. Maybe we can find a way to tap into either of these valuable resources.
I can't think of a solution for Gmail but I have been using Microsofts Live Mesh on my computers and mobile. It syncs up between your desktops and you can also access it thru the mobile browser. I don't think there is a dedicated mobile app though.
It's still a tech preview, but it should work for what you are describing.
Windows Live Mesh
skyegalen said:
It's still a tech preview, but it should work for what you are describing.
Windows Live Mesh
Click to expand...
Click to collapse
"Not yet available for mobile."
The words: "Soon to be available" + the words: "Microsoft" in the same sentence = uncontrollable laughter then disinterest.
...sorry, can't help it.

IDEA: Easy way to have a native GMAIL app on Windows Mobile...

I had an epiphany today, I want to share this idea, perhaps someone here has the knowledge to pull it off, unfortunately, I am not a C programmer:
Gmail already has built in RSS feeds. Every Gmail account hass RSS feeds for every label at https://mail.google.com/mail/feed/atom/LABEL/ (This also works for Apps at https://mail.google.com/a/DOMAIN.TLD/feed/atom/LABEL/ ).
The only requirement is that the feed reader support authentication.
Now lets bring pRSSreader into the equation (http://code.google.com/p/prssr/)
Supports SSL, Yes!
Supports Authntication, YES!
Source Code Available! GPL!
So to start: A competent developer begin with the pRSSreader code, change the UI a bit so that it will revolve around inputing gmail accounts and it will be able to read our mail)
The next step is to add a simple SMTP component that will send outgoing mail through the GMAIL smtp.
What do the smart people here think?
I'm not critisizing your idea by any means, but why not using the mobile JAVA app done by google?
It works flawlessly with JBED or JEODEK for WM. The functionality is also great. Of course, it's not native WM app, but it's still worth a while.
fbifbi said:
I'm not critisizing your idea by any means, but why not using the mobile JAVA app done by google?
It works flawlessly with JBED or JEODEK for WM. The functionality is also great. Of course, it's not native WM app, but it's still worth a while.
Click to expand...
Click to collapse
URL for this mate?
fbifbi said:
I'm not critisizing your idea by any means, but why not using the mobile JAVA app done by google?
It works flawlessly with JBED or JEODEK for WM. The functionality is also great. Of course, it's not native WM app, but it's still worth a while.
Click to expand...
Click to collapse
The JAVA app is great... except that the text font (including menu and everything) is too tiny and small on my Diamond. Otherwise it's great app...
Wiggz said:
URL for this mate?
Click to expand...
Click to collapse
Go to m.gmail.com on your phone, and then download it. It should automatically recognize that you have a windows mobile phone and offer you the JAVA version to download.
fbifbi said:
Of course, it's not native WM app, but it's still worth a while.
Click to expand...
Click to collapse
^^ that was the point of ethanpil's suggestion.
@ethanpil, I think it's a good idea, the only hole I see is that it's mostly for people who actually use the labels now, yes?
wait....maybe i'm not understanding u guys properly...u dont wanna use the mail program that it came with?? i have a diamond and i synced it to my outlook which has gmail..so when i'm on WIFI it vibrates when i get a gMail.....
so what is it that Java program do that this one doesn't??
Why not use Emoze? That has true push and works great with Gmail. Gmail also has a Exchange server for your calender and contacts.
sinara said:
The JAVA app is great... except that the text font (including menu and everything) is too tiny and small on my Diamond. Otherwise it's great app...
Click to expand...
Click to collapse
sinara, look for VGA hacked JBED (here on XDA) - it solves problems with small fonts on our devices.
sinara said:
The JAVA app is great... except that the text font (including menu and everything) is too tiny and small on my Diamond. Otherwise it's great app...
Click to expand...
Click to collapse
You can fix the font sizes with simple regedits.
Why do ppl want this?? Outlook can link to IMAP from google natively. Which All wm6 phones have...so why does anyone care about an external app that windows can do by default. I'm not discounting it or anything I'm just really confused on this issue
xcom923 said:
Why do ppl want this?? Outlook can link to IMAP from google natively. Which All wm6 phones have...so why does anyone care about an external app that windows can do by default. I'm not discounting it or anything I'm just really confused on this issue
Click to expand...
Click to collapse
I am with you here, gmail with imap is the way to go. If your device automagically finds gmail settings, just misspell gmail when entering your email addy, then fix it after you have unchecked to automatically find settings.
I believe the reason for doing this is to get away from the built-in (WM) applications which for the most part suck. Not to mention that the emails are stored in a database and not in individual files (as in Qmail). Even if it was stored in a database, the database should be easily manipulated to allow for quick backup and recovery operations (SQLite?). Not to mention that such an application can implement great features like imap-idle and connecting over 1x/gprs to save battery life (and privates).
Just my two cents.
The reason is as many have guessed above:
1) The Java version sucks for WM users: its not native, and a few times alerady if I exited hastily by hitting the X instead of through the menus then my DB was corrupted and I had to reinstall the app
2) Something native will be able to take advantage of all of the features of WM and run in the background better.
3) The native apps also suck.
4) Push IMAP and activesync take horrendous battery power
Anyway, I have been using NewsBreak to read my gmail by RSS and it works great, updates once per hour, and runs real fast in background and I get notification of new emails and I only downlod the labels I need... Its just a pain to then login to gmail app to reply...
I have a small application (in VB.NET) that I am working on but in this moment it is "work in progress". I am able to connect to GMail over SSL in POP3, SMTP and IMAP.
In this moment I am trying out POP3 but I have some problems when downloading larger attachments from GMail (out-of-memory exceptions) which I have to sort out.
I guess I could make a native application for GMail - however the first beta version would not support attachments (at least larger attachmnets - let's say more than 200KB - until I have sorted out the problem mentioned above).
In order to produce a first version, I still would need some days but if there's interest, I could give it a shot.
Rgds,
Tilleke
------------------------------------
Add spellchecking to your applications.
See: http://forum.xda-developers.com/showthread.php?t=495728
this would def worth a shot since it's a bunch of shareware ideas taken into an all in one freeware app to add to our collection of greatly developed freeware. i'd rather use a custom made freeware app that will always add features rather than waste memory with certain shareware programs just to have all the bells and whistles scattered across the cluttered memory
boog321 said:
I am with you here, gmail with imap is the way to go. If your device automagically finds gmail settings, just misspell gmail when entering your email addy, then fix it after you have unchecked to automatically find settings.
Click to expand...
Click to collapse
I've been doing that since my 8525.. I can't believe that anyone would rather 'fight' with a 3rd party app.. I can see the argument for push, but if you really need up to date inbox, just get a scheduler to set your 'active' hours so you get faster updates when you need it. Typically I get emails at the same time though.

copy and paste on the n1 email

im trying to use copy and paste when opening an email and i cant see any options to do this, i know you can select text normally and after a bit of googling it looks like this isnt possible, surely not is there not an app available to do this ?
treble4 said:
im trying to use copy and paste when opening an email and i cant see any options to do this, i know you can select text normally and after a bit of googling it looks like this isnt possible, surely not is there not an app available to do this ?
Click to expand...
Click to collapse
Not possible unless you use Gmail in the browser.
Possibly in FroYo when they separate Google Apps from Android.
you've found one of the huge gaping bugs with the gmail app, it does not support copy and paste yet. everywhere else in the OS it seems to work, but not the gmail app.
so there is no way then say if i get an email with a phone number in it i can click on the number and call it, or copy and paste in any mail program on the n1?
treble4 said:
so there is no way then say if i get an email with a phone number in it i can click on the number and call it, or copy and paste in any mail program on the n1?
Click to expand...
Click to collapse
intall k9 mail from the market. iirc it does copy/paste, and VERY nicely does multiple accounts.
it's not as polished as Mail or Gmail apps are stock on the phone, but it's pretty darn good.
treble4 said:
so there is no way then say if i get an email with a phone number in it i can click on the number and call it, or copy and paste in any mail program on the n1?
Click to expand...
Click to collapse
I think if you have a phone number in an email, it becomes clickable automatically.
Paul22000 said:
I think if you have a phone number in an email, it becomes clickable automatically.
Click to expand...
Click to collapse
it doesnt for me
evidently on the desire mail app you can copy and paste and click numbers
Sent from my Nexus One using the XDA mobile application powered by Tapatalk

[Q] help for new chat project

hello xda
i am a new developer [Student] i need to submit my app for my project at school
so what i want to ask is
i want to develop a app that allows a person to chat like is i give one coustmer a no. [say 678567] and he shares it with other person so they can chat share files
its same as how i think whats app works
can someone please guide me to the right direction i am keen to develope this app and get good grades ^_^
thank you
thedeadlycoder said:
hello xda
i am a new developer [Student] i need to submit my app for my project at school
so what i want to ask is
i want to develop a app that allows a person to chat like is i give one coustmer a no. [say 678567] and he shares it with other person so they can chat share files
its same as how i think whats app works
can someone please guide me to the right direction i am keen to develope this app and get good grades ^_^
thank you
Click to expand...
Click to collapse
If i get you, you want something like whatsapp...
As far as i know, you will need different things:
A backend Server to manage and store users and manage files sended.
A client side with is the chat. If you doing it in Android, Java the process could be like this:
client get a list of friends, then stores in local files. To send a message, firstly can use push messages like GCM to send a message, if receiver is online with the conversation openned, it tries to stablish a socket connection to send messages each other. If no, then it uses the push GCM.
More or less like that....of course there are much more things to do and take care of.
hope i helped you a little with this info!
forgin said:
If i get you, you want something like whatsapp...
As far as i know, you will need different things:
A backend Server to manage and store users and manage files sended.
A client side with is the chat. If you doing it in Android, Java the process could be like this:
client get a list of friends, then stores in local files. To send a message, firstly can use push messages like GCM to send a message, if receiver is online with the conversation openned, it tries to stablish a socket connection to send messages each other. If no, then it uses the push GCM.
More or less like that....of course there are much more things to do and take care of.
hope i helped you a little with this info!
Click to expand...
Click to collapse
ya!! thats what i want , seems tougher for a amature android programmer
so here what i have
i have a server at school which we are allowed to use
i have created a basic layout of the app(on a white board )
since i do not have that much expirence with apps ( till now i have made calculator and simple sudoku ) the problem is i don't know how can i make the app to contact with the servver complete noob in this thing
and
thanks for making me understand the working now i can tell my teacher how the app works
thedeadlycoder said:
ya!! thats what i want , seems tougher for a amature android programmer
so here what i have
i have a server at school which we are allowed to use
i have created a basic layout of the app(on a white board )
since i do not have that much expirence with apps ( till now i have made calculator and simple sudoku ) the problem is i don't know how can i make the app to contact with the servver complete noob in this thing
and
thanks for making me understand the working now i can tell my teacher how the app works
Click to expand...
Click to collapse
You can use backends like Google Cloud Messaging or Parse, they're well documented and easy to use, just go through their documentation,
swapnilraj said:
You can use backends like Google Cloud Messaging or Parse, they're well documented and easy to use, just go through their documentation,
Click to expand...
Click to collapse
thanks for the reply actually i researched a little and found the GCM is not a good choice for IM as sometimes messages are not delivered so as for parse i have no experience with that and i found something that i need to have some connection between my android app to server (running php and mysql database)
the point where i am stuck is that
How to connect the app to server ??
and how to give a user his personal pin or username so he can share with others to chat ??
thanks
thedeadlycoder said:
thanks for the reply actually i researched a little and found the GCM is not a good choice for IM as sometimes messages are not delivered so as for parse i have no experience with that and i found something that i need to have some connection between my android app to server (running php and mysql database)
the point where i am stuck is that
How to connect the app to server ??
and how to give a user his personal pin or username so he can share with others to chat ??
thanks
Click to expand...
Click to collapse
http://forum.xda-developers.com/showthread.php?t=2325799
it was just 3 post under yours
And just make that every user have an unique nickname and use it has a primary key.

Categories

Resources