2FA / MFA bypass
SkillCommunicationDefeat a second authentication factor, OTP/TOTP, SMS, push, or backup codes. Load when login has a 2FA/MFA step and you want to reach the account without the factor, on "2FA bypass", "OTP brute", "MFA", or during account-takeover work. Signals: an OTP/verification screen after password, a "verify your device" step, `/verify`, `/2fa`, `otp`/`code` parameters.
Instructions available. Your AI can read the instructions. Execution depends on the setup they require.
Account requirements not reviewed. Check the skill instructions before use; ahel provides instructions and does not run this skill.
Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.
Then ask your AI: use the 2FA / MFA bypass skill
What this skill tells your AI
The instructions your AI receives, as published by noorqureshi/sploitagent in skills/web/web-mfa-bypass/SKILL.md and read by ahel’s review.
When it applies
Authentication has a second step after the password. MFA is only as strong as its enforcement — the common flaws are in the flow, not the crypto, and each is worth a quick check before assuming the factor is solid.
Why it works
The second factor is usually bolted onto a stateful flow, and the server often trusts the client to follow it. Skip the step, replay a state, or brute a short code with no rate limit, and the factor never actually gates access.
Method — work the checklist
- Missing server-side enforcement: complete step 1, then request a post-auth endpoint directly (forced browsing) or reuse the step-1 session — if it works, 2FA is cosmetic.
- No rate limit on the code: brute the 6-digit OTP (Turbo Intruder); watch for missing lockout, or a lockout you can reset by re-triggering send. Also test code reuse and non-expiry.
- Response/flag manipulation: flip
"mfa_required":true→false,verified:false→true, or a 200/302 the client trusts to advance. - Flow/logic: change the account/email between step 1 and 2 (bind your factor to their session), downgrade to a factor you control, or use password-reset to skip MFA entirely.
- Backup/remember: weak/guessable backup codes, a "remember this device" cookie that's static or forgeable, or OAuth/SSO paths that skip MFA.
Gotchas
- Account lockout can burn the test account — throttle and use your own accounts.
- Distinguish "reached the OTP screen" from "reached the account" — only the latter is the bypass.
- Some apps enforce MFA at sensitive actions, not login — test the step-up too.
Verify success
You reach the authenticated account (or perform the MFA-gated action) without presenting a valid second factor, reproducibly from a clean session with test accounts.
References
PortSwigger 2FA bypass labs; OWASP Authentication Testing (OTP/MFA); OWASP ASVS auth requirements.
Signals
- GitHub stars
- 20
- Forks
- 7
- Last commit
- Sep 2026
Advanced
- Item type
- skill
- Key
web-mfa-bypass- Source
- github.com/noorqureshi/sploitagent
github.com/noorqureshi/sploitagent
Related picks
Skill · andrewnggirl
The pick for Cryptocrypto-tools
Skill · lingbol088-spec
The pick for Cryptoowasp-security
Skill · davila7
The pick for Web (OWASP)owasp-web
Skill · nahid-sparktales
The pick for Web (OWASP)slack-gif-creator
Skill · anthropics
More in Communicationerror-handling
Skill · affaan-m
More in Communication