Two Factor Authentication(2FA) Bypass Using Brute-Force Attack

Поділитися
Вставка
  • Опубліковано 3 січ 2025

КОМЕНТАРІ • 63

  • @ahmedabualkass390
    @ahmedabualkass390 Рік тому +5

    The time is right. When the OTP is six digits long, it will not prevent the final cut of the exam in case of selection due to a challenge. If the OTP is not released within 60 seconds, the OTP will expire.

    • @AGHILESFELLAG-q7w
      @AGHILESFELLAG-q7w 2 місяці тому

      So what's the solution can u use multiple laptop to do the task?

  • @bjtaudio
    @bjtaudio Рік тому +3

    That will not work for most sites, as 1 the 4 digit usually 6 digits code keeps changing, often one-time codes and time limited, 2 after several failed attempts the account is locked, 3 often a secure app is used, 4 the system alerts the account holder of a login from a new device. 5 behavior checks, to see if its a automated attack.

    • @tyk953
      @tyk953 2 місяці тому +1

      mersi pentru explicați e,,deci e foarte greu de ocolit codul🎉,se plătește o taxă pentru codul ăla

    • @tyk953
      @tyk953 2 місяці тому

      mersi pentru explicați e,deci e foarte greu de ocolit codul,sau deloc🎉,se plătește o taxă pentru codul ăla

    • @tyk953
      @tyk953 2 місяці тому

      da 50 lei la luna

  • @drewcurry2882
    @drewcurry2882 9 місяців тому +1

    The basic flaw: it assumes the required code does not change. Use an authenticator tool, with 6-digits that change every 30-seconds, with a 3-mistakes-results in a 5-minute cooldown, and you will need a quantum computer to try to break that puppy.

  • @tauruxx1893
    @tauruxx1893 2 роки тому +4

    Can I use that to force the 2fa on a instagram account?

    • @abdulhalim747
      @abdulhalim747 10 місяців тому

      Yes you can anywhere but remember use in legal

    • @tyk953
      @tyk953 2 місяці тому

      mai sus spune că se schimba codul la 30 de sec,proprietarul contului plătește taxă,că se schimba codul 🎉,ori greu ori imposibil😊

  • @charlotte8840
    @charlotte8840 Рік тому +7

    Thanks for the tutorial! Can limiting the max. no. of One-time password (OTP) attempts and/or minimizing the time limit for each OTP entry help to prevent Brute-Force Attack?

  • @ayman2796
    @ayman2796 Рік тому +1

    Good job Bro, What is the solution when the reaction of the website is different like that "attempts of enter the pin are limited in three time then it lock"?

  • @gamegunner9079
    @gamegunner9079 2 роки тому +5

    Very detailed explanation Sir, many thanks

    • @TraceTheCode
      @TraceTheCode  2 роки тому +1

      Thanks and welcome!

    • @gamegunner9079
      @gamegunner9079 2 роки тому

      @@TraceTheCode I tried this sir but it was running for whole night and finally crashed my vm 😂

    • @TraceTheCode
      @TraceTheCode  2 роки тому

      Sorry to hear that! But it shouldn't take more than a few mins!

    • @gamegunner9079
      @gamegunner9079 2 роки тому

      @@TraceTheCode are you using it in VM? Ran it as 1 concurrent connection too but still same,will turbo intruder fasten up the process?

    • @TraceTheCode
      @TraceTheCode  2 роки тому

      yeah, concurrent Request must be 1. Using Turbo Intruder shouldn't make much difference.

  • @Manoj-sy9ky
    @Manoj-sy9ky 2 роки тому +2

    Hi dude.
    My Facebook account Two factor authentication code didn't come.any solution pls

  • @weird9890
    @weird9890 Рік тому

    so 0167 was the code or something else?

  • @shvraj883
    @shvraj883 Рік тому

    How I want see an otp send by server

  • @thumpertorque_
    @thumpertorque_ 2 роки тому

    When you log into someone's account does it change their original password?

  • @obiokoyenelson3760
    @obiokoyenelson3760 Рік тому

    Will the website request a new otp each time the macro is run?

    • @purvashgangolli5968
      @purvashgangolli5968 Рік тому

      I guess no, because after a particular single request from the browser the burp suite will virtually handle the request, so for the code which was sent by the original server for that will automate the task using macro.

  • @khalidzahri1
    @khalidzahri1 2 роки тому

    Could it bypass 2fa ebay ??

  • @roseoliver1955
    @roseoliver1955 Рік тому +1

    Pls I need an answer

  • @thanhnhannguyen1910
    @thanhnhannguyen1910 2 роки тому +2

    could it by pass 2fa paypal bro?

    • @bassxfunky2367
      @bassxfunky2367 2 роки тому +2

      Probably not because the code of 2fa will change afther 1 mins or 2 so i bet u cant find the right code in that time

    • @Ayu_Chandravanshi
      @Ayu_Chandravanshi 2 роки тому +1

      @@bassxfunky2367 but if luck loves you, you can 😂

    • @ahmedabualkass390
      @ahmedabualkass390 Рік тому

      ​@@Ayu_Chandravanshihow ❤

    • @tyk953
      @tyk953 2 місяці тому

      ​@@Ayu_Chandravanshionly but🎉

  • @cypher875
    @cypher875 7 місяців тому

    I got a very less secure app, which allows unlimited OTP tries .. in 5 mins then we just have to resend the otp is it possible to crack it ?

  • @doshamitv5020
    @doshamitv5020 Рік тому +1

    possible to bypass GOOGLE 2FA wiTh this?

  • @csh4992
    @csh4992 2 роки тому +1

    Why can my macro only add one request

    • @TraceTheCode
      @TraceTheCode  2 роки тому +3

      Maybe you forgot to hold the CTRL key while selecting the requests.

  • @nikitabiddle7344
    @nikitabiddle7344 Рік тому

    how to do this with andriod and windows

  • @studiospan6426
    @studiospan6426 Рік тому

    So basically this attack works on requsting a new otp from the server then trying that otp and hope that our combination of generated and payload otp somehow matches . Isn't this , really difficult and completely based on luck i mean yeah we can increase the speed by making our own code in nodejs or some other languages which are very very fast when it comes to webscraping but still the odds are very very high thay we will get the code i am not sure if any website will be willing to pay for this bug . Please correct me if am wrong 🙏

    • @8124K-u4x
      @8124K-u4x 2 місяці тому

      sir are you sure after 1 year

    • @studiospan6426
      @studiospan6426 2 місяці тому

      @@8124K-u4x indeed I was wrong, you will crack the OTP in 3-4 days at max if you find this bug and any company will give you a decent bounty for this bug. Keep learning mate.

    • @studiospan6426
      @studiospan6426 2 місяці тому +1

      @@8124K-u4x yeah I was indeed wrong for a 4-digit code it can be cracked in some hours to a day while a 6-digit code might take some time, but it will eventually be cracked as well and yes any company would pay you a decent bounty for this.

    • @rayanemazar2979
      @rayanemazar2979 4 дні тому

      @@studiospan6426all company’s have good security

  • @allanamalsloveit
    @allanamalsloveit Рік тому +2

    You are amazing, we support you❤️❤️❤️❤️❤️❤️❤️❤️❤️❤️❤️❤️

  • @MafiMartins-cw5tv
    @MafiMartins-cw5tv 9 місяців тому

    Thanks for teaching and giving us the ideal are amazing. I am really happy to be here thanks again 🙏🙌🧐✊

  • @the.jhantoo
    @the.jhantoo Рік тому

    Is Work on My Jio ?

  • @fokshand4950
    @fokshand4950 2 роки тому

    Can you make viedo bypass application not page

  • @thanthtooaung2979
    @thanthtooaung2979 2 роки тому +1

    How can we know the correct one is the first one??

  • @keithbow1779
    @keithbow1779 2 роки тому +3

    Thanks for such a detailed explanation.

  • @RomanticRides
    @RomanticRides 2 роки тому

    I can't understand what's this... How can I by pass a gmil 2fa or what's app code ???

  • @romogomu6726
    @romogomu6726 Рік тому +1

    Thankyou

  • @StanBodnar
    @StanBodnar Рік тому +1

    well done bro

  • @tajadavis
    @tajadavis 2 роки тому +2

    Does this work for Snapchat Accounts?

  • @Violocto
    @Violocto 2 роки тому +1

    Perfect 👍

  • @boomergaming4174
    @boomergaming4174 Рік тому

    Does it work for every 2FA? like Fcebook?

    • @kiiturii
      @kiiturii Рік тому +1

      bruh no lmao, huge companies will have high security especially for 2fa.

    • @ANAS-ty6rn
      @ANAS-ty6rn Рік тому

      what about roblox LMAO @@kiiturii

  • @saikirangoud118
    @saikirangoud118 6 місяців тому

    brilliant

    • @DickmanYT
      @DickmanYT 5 місяців тому

      do u need premium burl for this?