196

16377 readers
2180 users here now

Be sure to follow the rule before you head out.

Rule: You must post before you leave.

^other^ ^rules^

founded 1 year ago
MODERATORS
226
 
 
227
228
 
 
229
 
 
230
 
 

i can post images now >:)

231
403
Rule (lemmy.blahaj.zone)
submitted 1 week ago by [email protected] to c/[email protected]
 
 
232
 
 
233
 
 

(And by popular demand i mean AlligatorBlizzard)

234
 
 

My phone died a few days ago, and the Cisco Duo app overwrote 2FA key backup after connecting my old phone to the internet.
Lemmy has no backup codes, nor can you disable 2FA even while logged in without a valid token.

Anyway, I noticed there's no rate limiting on 2FA attempts.
So following Lemmy API docs I wrote this exceptionally stupid script (look at my foolish way of parallelization and no auto-stop).

I got the JWT token from logged-in Firefox session, using cookies.txt extension to export it.

Anyway, just make sure your password is secure enough, It's obviously (potentially) better than 6 digits, probably with 3 valid combinations at each time (current 30s, past 30s, future 30s windows), if I am guessing how it works right.

My attempt also clearly involved a lot of luck with just 21,830 attempts (less than 5 minutes). But, if you're lucky enough, you may guess it on first attempt, or never if you aren't.

235
 
 
236
 
 
237
 
 

Just looking up some DIY medical procedures and then the unwanted AI goes off the rails.

238
 
 
239
 
 
240
 
 
241
 
 

Didn't realize Wall-E was that forward about its messaging when I was 6 watching it. woah

Also here is a song they made for the company

242
 
 
243
 
 
244
367
Rule (lemmy.blahaj.zone)
submitted 1 week ago by [email protected] to c/[email protected]
 
 
245
289
rule (files.catbox.moe)
submitted 1 week ago by [email protected] to c/[email protected]
 
 
246
 
 
247
 
 
248
368
rule (lemmy.dbzer0.com)
submitted 1 week ago by [email protected] to c/[email protected]
 
 
249
 
 
250
496
wizards rule (lemmy.blahaj.zone)
submitted 1 week ago by [email protected] to c/[email protected]
 
 
view more: ‹ prev next ›