Derpitron / Discord-OTP-Forcer

Selenium based discord OTP forcer
GNU Affero General Public License v3.0
43 stars 12 forks source link

[Feature Request] Input for Backup codes on Disable 2FA Field #5

Closed Nightjar-ish closed 6 months ago

Nightjar-ish commented 1 year ago

I've lost access to my 2fa authenticator due to a phone wipe and I can't find my back-up codes. My password isn't working (nor any of my usuals, typical) however I am still logged in on chrome browser so I can access settings for 2fa, just can't turn it off as you need the codes.

I know approx 0 about any of this stuff, so sorry for what's probably an obvious question, but will this script work since I'm already logged in? I noticed your response to another question re: the password reset screen so wanted to check.

Thanks!

Derpitron commented 1 year ago

Hello! This tool can be used with the Disable 2FA input as well, though currently I don't have the time to make a version for that. However if you have the knowledge then you can try making it yourself

Nightjar-ish commented 1 year ago

Ah okay, thanks. I have zero know-how for any of this so I'll have to try the old fashioned way for now. Thanks anyway!

Derpitron commented 1 year ago

removed a comment for being off topic

Derpitron commented 1 year ago

May be related: #15

LuXeZs commented 6 months ago

Just got around to looking at this, you need to be logged into the account to be able to remove 2FA, So If you know the account's password, then you can accesses the accounts backup codes which can be used to disable 2FA.

Derpitron commented 6 months ago

What about scenarios where the user may be logged in on web browser on a device but doesn't have the password? They'd still have account access in this case. It's worth looking into imo

LuXeZs commented 6 months ago

What about scenarios where the user may be logged in on web browser on a device but doesn't have the password? They'd still have account access in this case. It's worth looking into imo

We'd have to login with the program and unless I'm mistaken we'd have to give a 2FA code for that processes.