3 ms·
Regarding 2fa - For TOTP there is a Linux command line tool called oathtool. For SMS, set up Twilio. For U2F you can emulate a device with an ECDSA library. Fo
by alert0 6y ago
Regarding 2fa - For TOTP there is a Linux command line tool called oathtool. For SMS, set up Twilio. For U2F you can emulate a device with an ECDSA library.
For CSRF you'll want browser automation, like Chrome Headless. Alternatively, you can load a page and extract a token from the DOM in a normal scraper.
>To be honest it feels like vested interests are keeping it that way: professionals want to keep the tools manual so they can charge by the hour;
As a security professional, get out of here with that non-sense. You've run into a challenging problem and still think there is some conspiracy. What we do is highly technical and often customer specific (e.g. automate 2fa due to some weird requirement rather than the customer disabling it for the test account). There is no market in automating a lot of this work, packaging it in a nodejs library for you to use, and writing docs.
- glutamate 6y agoMy "challenging problem" is that I use CSRF tokens, which is a minimal requirement of any non-toy project.
- tlavoie 6y agoI haven't tried it in Zap, but there is definitely a Burp add-on that takes care of this for you. Probably several. Zap is pretty scriptable as well, so there are likely solutions for it also. What have you tried?