Abstract
2fauth is an open-source Cybersecurity & Ethical Hacking project. A Web app to manage your Two-Factor Authentication (2FA) accounts and generate their security codes. 2FAuth Demo Credentials (login - password) : demo@2fauth.app - demo. It is built using PHP. Key capabilities include: Manage your 2FA accounts and organize them using Groups; Scan and decode any QR code to add account in no time; Add custom account without QR code thanks to an advanced form. The complete source code is publicly available on GitHub under the GNU Affero General Public License v3.0, making it a useful reference for students building a Cybersecurity & Ethical Hacking mini project or final-year project.
1. Introduction
2FAuth Demo Credentials (login - password) : demo@2fauth.app - demo
2FAuth is a web based self-hosted alternative to One Time Passcode (OTP) generators like Google Authenticator, designed for both mobile and desktop.
2FAuth is currently fully localized in English and French. See Contributing if you want to help on adding more languages.
2. Objective
A Web app to manage your Two-Factor Authentication (2FA) accounts and generate their security codes
This project demonstrates how PHP can be applied to a real-world Cybersecurity & Ethical Hacking problem.
3. Key Features / Modules
- Manage your 2FA accounts and organize them using Groups
- Scan and decode any QR code to add account in no time
- Add custom account without QR code thanks to an advanced form
- Edit accounts, even the imported ones
- Generate TOTP and HOTP security codes and Steam Guard codes
4. Technology Stack
5. System Requirements
General requirements for this technology stack — check the README for exact versions.
- PHP 7.4+ with a web server (XAMPP / WAMP / LAMP)
- MySQL / MariaDB
- phpMyAdmin (optional)
- Git (to clone the repository)
6. Installation & Setup
git clone https://github.com/Bubka/2FAuth.git
cd 2FAuth- Self-hosted server
- Docker (cli)
- Docker (compose)
Full setup instructions are in the project README.
7. Future Enhancements
Suggested extensions you can add to make this your own project.
- Add logging and alert notifications (email / Telegram)
- Write a threat model document for the tool
- Package it with Docker for safe lab testing
8. Viva / Review Questions
Common questions examiners ask for projects in this domain.
- Which threat or attack does this project defend against?
- What detection or protection technique is used and what are its limits?
- How are false positives and false negatives handled?
- Which cryptographic algorithms or security standards are involved?
- What legal and ethical rules apply when testing a tool like this?
9. Source Code & License
This project is developed by Bubka and published on GitHub under the GNU Affero General Public License v3.0. Please follow the license terms and credit the original author when you use or modify this code.
Want to build this as your internship project?
Work on a Cybersecurity & Ethical Hacking project like this with mentor guidance, weekly reviews and an internship certificate from Training Trains, Erode — online or offline.
Apply for Cybersecurity & Ethical Hacking Internship