Extract OTP Secrets

Extract one time password (OTP) secrets from QR codes exported by two-factor authentication (2FA) apps such as "Google Authenticator". The exported QR codes from authentication apps can be captured by camera, read from images, or read from text files. The secrets can be exported to JSON or CSV, or printed as QR codes to console.

Cybersecurity & Ethical HackingPythonGPL-3.0

Abstract

Extract OTP Secrets is an open-source Cybersecurity & Ethical Hacking project. Extract one time password (OTP) secrets from QR codes exported by two-factor authentication (2FA) apps such as "Google Authenticator". The exported QR codes from authentication apps can be captured by camera, read from images, or read from text files. The secrets can be exported to JSON or CSV, or printed as QR codes to console. It is built using Python. Key capabilities include: Free and open source; Supports Google Authenticator exports (and compatible apps like Aegis Authenticator); Captures the the QR codes directly from the camera using different QR code libraries (based on OpenCV). The complete source code is publicly available on GitHub under the GNU General Public License v3.0, making it a useful reference for students building a Cybersecurity & Ethical Hacking mini project or final-year project.

1. Introduction

The secrets can be exported to JSON or CSV, or printed as QR codes to console or saved as PNG.

Everything is just packed in one executable. No installation needed, neither Python nor any dependencies have to be installed. Easy and convenient

There is a delay after starting the executable since the files have internally to be unpacked.

2. Objective

Extract one time password (OTP) secrets from QR codes exported by two-factor authentication (2FA) apps such as "Google Authenticator". The exported QR codes from authentication apps can be captured by camera, read from images, or read from text files. The secrets can be exported to JSON or CSV, or printed as QR codes to console.

This project demonstrates how Python can be applied to a real-world Cybersecurity & Ethical Hacking problem.

3. Key Features / Modules

  • Free and open source
  • Supports Google Authenticator exports (and compatible apps like Aegis Authenticator)
  • Captures the the QR codes directly from the camera using different QR code libraries (based on OpenCV)
  • ZBAR: pyzbar - fast and reliable, good for images and video capture (default and recommended) if [libzbar is installed]
  • QREADER: QReader if [libzbar is installed]
  • QREADER_DEEP: QReader - very slow in GUI if [libzbar is installed]
  • CV2: QRCodeDetector
  • CV2_WECHAT: WeChatQRCode
  • Program usable as pure GUI application without any command line switches ( since v2.2)
  • Save otp secrets as csv file ( since v2.2)

4. Technology Stack

Python

5. System Requirements

General requirements for this technology stack — check the README for exact versions.

  • Python 3.8 or later
  • pip / virtualenv for dependencies
  • VS Code, PyCharm or Jupyter Notebook
  • Git (to clone the repository)

6. Installation & Setup

git clone https://github.com/scito/extract_otp_secrets.git
cd extract_otp_secrets
  1. Open VSCode command palette (Ctrl-Shift-P)
  2. Type command "Python: Configure Tests"
  3. Choose unittest or pytest. (pytest is recommended, both are supported)
  4. Set ". Root" directory
git clone https://github.com/scito/extract_otp_secrets.git
cd extract_otp_secrets
pip install -U -r requirements.txt

python src/extract_otp_secrets.py example_export.txt

Full setup instructions are in the project README.

7. Future Enhancements

Suggested extensions you can add to make this your own project.

  • Add logging and alert notifications (email / Telegram)
  • Write a threat model document for the tool
  • Package it with Docker for safe lab testing

8. Viva / Review Questions

Common questions examiners ask for projects in this domain.

  1. Which threat or attack does this project defend against?
  2. What detection or protection technique is used and what are its limits?
  3. How are false positives and false negatives handled?
  4. Which cryptographic algorithms or security standards are involved?
  5. What legal and ethical rules apply when testing a tool like this?

9. Source Code & License

This project is developed by scito and published on GitHub under the GNU General Public License v3.0. Please follow the license terms and credit the original author when you use or modify this code.

Want to build this as your internship project?

Work on a Cybersecurity & Ethical Hacking project like this with mentor guidance, weekly reviews and an internship certificate from Training Trains, Erode — online or offline.

Apply for Cybersecurity & Ethical Hacking Internship