TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

How to Bypass 2FA with an HTTP Header

8 点作者 agrinman大约 6 年前

2 条评论

lucb1e大约 6 年前
Summary: 2FA token was only some digits, so can be brute forced. But they implemented rate limiting, based on IP. Unfortunately the application accepted the X-Forwarded-For header as if it were the real IP and by randomizing that header, you can do as many requests as you want.
评论 #19783202 未加载
jonnismash大约 6 年前
Misleading title, a better title would be: How I bypassed 2FA Rate-limits with an HTTP Header.