nilsstreedain / duo-bypass

🔓 Cisco DUO Mobile App OTP Bypass
https://duo-bypass.nilsstreedain.com
GNU General Public License v3.0
12 stars 1 forks source link
bypass cisco duo duo-mobile duo-security google-authenticator hack hotp otp workaround

duo-bypass

duo-bypass is a tool allowing you to use any valid two factor authentication app (that supports HOTP) in place of Cisco's proprietary proprietary DUO software.

Is it secure?

Absolutely, DUO uses the same HOTP standards as every other 2FA app in the security space. They just encapsulate that standard in their own software to lock you down to their app. This tool tells DUO that you are the DUO app allowing you to activate a 2FA key in whatever app you choose. Alternatively, if you are uncomfortable placing your DUO credentials in a web interface, there is a script-based version of the tool.

Why not just use DUO?

There are many reasons you may want to avoid using the DUO app from usability to ideological. I've listed a few below:

How to setup duo-bypass (web version):

  1. Navigate you your organization's DUO Security Portal.
  2. Login with your current DUO 2FA method.
  3. In the Security Portal, select + Add another device. image
  4. Select Tablet. image
  5. Select Android. image
  6. Select I have DUO Mobile installed. image
  7. Right click on the provided QR code and copy the image URL. image
  8. Navigate to the duo-bypass tool.
  9. Paste the image URL into the duo-bypass tool and select bypass.
  10. Scan the QR code into your chossen 2FA application. If the app does not support a QR code, copy the key below the QR code into your app.
  11. Generate/test your first bypass code and you're done! (You can also now rename the device in DUO if you would like)