Derpitron / Discord-OTP-Forcer

Selenium based discord OTP forcer
GNU Affero General Public License v3.0
45 stars 13 forks source link

A few questions #23

Closed Teeterama closed 1 year ago

Teeterama commented 1 year ago

.Do I launch the code from git cause if so the stuff im putting in .env isn't staying and if I use the thing in the folder it doesnt really automate whatsoever if its supposed to. I also don't get a captcha. And the token says it is invalid even when I just get it. Also am I supposed to move the download out of the downloads folder onto my desktop cause I have done that. Also do I need to know the old password? Is that what the problem is, Cause if so...this really sucks for me

Derpitron commented 1 year ago

Sorry, I don't understand what you're trying to say at all. Please type your issue out in a clear way I can understand.

What is your issue? Are you not able to install or use the program? Does it not work for you?

Teeterama commented 1 year ago

I dont think I have one anymore sorry. I forgot to get rid of the <.>

Teeterama commented 1 year ago

Out of curiosity how long did it take for you to get the correct code?

LuXeZs commented 1 year ago

It's hard to give an estimate as it boils down to luck, you could get it in the first few or it might take weeks or months, I have only been running it during testing of new features so I haven't got the correct code yet.

Teeterama commented 1 year ago

Oh...........

Teeterama commented 1 year ago

So do you actually know if it is possible

LuXeZs commented 1 year ago

This is a brute forcer so it should work but it will take time, This is mainly a last resort to try get accounts back.

If you use backup codes you'd have 2.82 trillion codes to get through but it has the advantage the codes not changing.

Teeterama commented 1 year ago

Do you know any non last resorts?

Teeterama commented 1 year ago

If you use backup codes you'd have 2.82 trillion codes to get through but it has the advantage the codes not changing.

Wait the regular code changes!?!

LuXeZs commented 1 year ago

I'm not 100% as I'm new to this but I believe it does as it would timeout meaning it would send a new code. @Derpitron maybe have more info but they're busy.

Derpitron commented 1 year ago

Wait the regular code changes!?!

This program works by trying hundreds of different codes as fast as possible.

But the problem is that the Discord 2FA OTPs change every 30 seconds: this is a security feature so that people aren't able to easily brute force codes to hack into people's accounts.

While it is a good security feature, it makes legitimate people (like you I hope)'s time harder by making it less likely to get the correct code. Even if you got the correct code for 30 seconds ago, it wouldn't work.

There isn't any other way unfortunately.