Security vulnerabilities

  • Status Closed
  • Assigned To
    cbay
  • Private
Attached to Project: Security vulnerabilities
Opened by haxor07 - 27.09.2026
Last edited by cbay - 28.09.2026

FS#509 - TOTP Authenticator Accept Expired Code on Alwaysdata

Summary:
Hi Security Team, During testing www.alwaysdata.com, I discovered that the TOTP authenticator implementation accepts expired codes, allowing attackers to bypass authentication. This is a security vulnerability that reduces the effectiveness of the TOTP authentication mechanism.

Description:
TOTP (Time-Based One-Time Password) is a widely used authentication mechanism that generates a new password every 30 seconds. The password is valid for a short period, typically 30 seconds, before a new password is generated. This mechanism is designed to prevent attackers from using previously generated passwords.
During testing, I discovered that the TOTP authenticator implementation accepts expired codes, allowing attackers to bypass authentication. Specifically, I found that the authenticator accepts codes that are more than 45 Seconds old, which is considered a large window of acceptance. This vulnerability reduces the security benefits of TOTP, allowing attackers to reuse expired codes. This can lead to unauthorized access to the system, which can result in data breaches, financial losses, and reputational damage.
Steps To Reproduce

Enable TOTP authentication for the account at AlwaysData with google authenticator.
Log in to the tfa enabled account with correct password.
When it comes to tfa state, save the current totp code from authenticator app.
Wait for the code to expire.
Submit the expired code to the authentication endpoint.
Observe that the authentication is successful despite using an expired code.
Suggest Fix

Reduce the window of acceptance to a more secure value (e.g., 30 seconds).
Implement a more robust TOTP algorithm that rejects expired codes.
Impact

The attacker can bypass the two factor authentication by using expired otp code.

If you need other information let me know.

Waiting for your positive reply.

Thanks
Ahmed

Closed by  cbay
28.09.2026 07:27
Reason for closing:  Duplicate
Additional comments about closing:  

https://security.alwaysda ta.com/task/204

Loading...

Available keyboard shortcuts

Tasklist

Task Details

Task Editing