Magento2 Module Disabletwofactorauth

The DisableTwoFactorAuth module provides the ability to disable two-factor authentication.

Cybersecurity & Ethical HackingPHPMIT

Abstract

Magento2 Module Disabletwofactorauth is an open-source Cybersecurity & Ethical Hacking project. The DisableTwoFactorAuth module provides the ability to disable two-factor authentication. Provides the ability to disable two-factor authentication. It is built using PHP. The complete source code is publicly available on GitHub under the MIT License, making it a useful reference for students building a Cybersecurity & Ethical Hacking mini project or final-year project.

1. Introduction

Provides the ability to disable two-factor authentication.

With the release of Magento 2.4, two-factor authentication (also known as 2FA) became enabled by default, with no ability to disable it in either the admin or console. However, there are situations which may require 2FA to be disabled or temporarily turned off, such as within development or testing environments.

This module automatically disables 2FA while in developer mode (since version 2.0.0), and adds the missing toggle to turn 2FA on or off from the admin for other environments. It does this by hooking into the core code in a very seamless manner, just as would be done if this toggle existed in the core code. Installing this module should not open any security holes, as it just works off of a simple config toggle which, if not present, falls back to the default functionality.

2. Objective

The DisableTwoFactorAuth module provides the ability to disable two-factor authentication.

This project demonstrates how PHP can be applied to a real-world Cybersecurity & Ethical Hacking problem.

4. Technology Stack

PHP

5. System Requirements

General requirements for this technology stack — check the README for exact versions.

  • PHP 7.4+ with a web server (XAMPP / WAMP / LAMP)
  • MySQL / MariaDB
  • phpMyAdmin (optional)
  • Git (to clone the repository)

6. Installation & Setup

git clone https://github.com/markshust/magento2-module-disabletwofactorauth.git
cd magento2-module-disabletwofactorauth
composer require --dev markshust/magento2-module-disabletwofactorauth
bin/magento module:enable MarkShust_DisableTwoFactorAuth
bin/magento setup:upgrade

Full setup instructions are in the project README.

7. Future Enhancements

Suggested extensions you can add to make this your own project.

  • Add logging and alert notifications (email / Telegram)
  • Write a threat model document for the tool
  • Package it with Docker for safe lab testing

8. Viva / Review Questions

Common questions examiners ask for projects in this domain.

  1. Which threat or attack does this project defend against?
  2. What detection or protection technique is used and what are its limits?
  3. How are false positives and false negatives handled?
  4. Which cryptographic algorithms or security standards are involved?
  5. What legal and ethical rules apply when testing a tool like this?

9. Source Code & License

This project is developed by markshust and published on GitHub under the MIT License. Please follow the license terms and credit the original author when you use or modify this code.

Want to build this as your internship project?

Work on a Cybersecurity & Ethical Hacking project like this with mentor guidance, weekly reviews and an internship certificate from Training Trains, Erode — online or offline.

Apply for Cybersecurity & Ethical Hacking Internship