Password-free login for Android clients such as China Unicom's wowo mailbox (any Unicom user's pop3 PASSWORD can be obtained)
By accident, I found that wowemail and wowo had no password login, and other apps had not been tested yet.
By accident, we found that the android client has a one-click Login button and does not need to enter a password.
It can be seen that he is verifying whether the mobile phone has a valid SIM card number.
Use xposed + code change software. After modification, I can pass the verification. I feel that it is relatively simple.
For example, you can log on to 18577777777and 18566666666.
And I can also receive emails sent to my mailbox. There are also historical emails.
If this is a common mailbox attack, most of the password retrieval functions can be used.
Captured pop3 passwords
This is the result of changing the mobile phone number to log on to luvo.
This is my email address.
This is the email content in 18577777777. Including my test email
This is an account Property
Number 18566666666
This is my original mobile phone information ). Iccid imsi does not move. You only need to change the mobile phone number.
Solution:
You are more professional ,.