Abstract
Totp is an open-source Cybersecurity & Ethical Hacking project. Support Two Factor Authentication (2FA) in your application with ease. The TOTP is what we typically use for verification codes. This can be used for 2FA (two-factor authentication), but also used for email verification, password reset, etc. It is built using JavaScript. The complete source code is publicly available on GitHub under the MIT License, making it a useful reference for students building a Cybersecurity & Ethical Hacking mini project or final-year project.
1. Introduction
The TOTP is what we typically use for verification codes. This can be used for 2FA (two-factor authentication), but also used for email verification, password reset, etc.
[![Build Status][build-badge]][build] [![MIT License][license-badge]][license] [![Code of Conduct][coc-badge]][coc]
The primary motivation was to support a more secure algorithm than SHA-1 (though Google Authenticator only supports SHA-1, longer-lived OTPs should use a more secure algorithm). The maintainer has not actively responded to issues or pull requests in years.
2. Objective
Support Two Factor Authentication (2FA) in your application with ease.
This project demonstrates how JavaScript can be applied to a real-world Cybersecurity & Ethical Hacking problem.
4. Technology Stack
5. System Requirements
General requirements for this technology stack — check the README for exact versions.
- Node.js (LTS) and npm
- A modern web browser
- VS Code or any code editor
- Git (to clone the repository)
6. Installation & Setup
git clone https://github.com/epicweb-dev/totp.git
cd totp- generateTOTP - This generates the OTP and returns the config used to
- verifyTOTP - This verifies the OTP against the config used to generate it.
- getTOTPAuthUri - This generates a URI that can be used to add the OTP to an
import { generateTOTP, verifyTOTP } from '@epic-web/totp'
const { otp, secret, period, digits, algorithm, charSet } = await generateTOTP({
charSet: 'ABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789', // custom character set
})
// Remember to save the charSet to your database as well.
// To verify
const isValid = await verifyTOTP({
otp,
secret,
period,
digits,
algorithm,
charSet,
})Full setup instructions are in the project README.
7. Future Enhancements
Suggested extensions you can add to make this your own project.
- Add logging and alert notifications (email / Telegram)
- Write a threat model document for the tool
- Package it with Docker for safe lab testing
8. Viva / Review Questions
Common questions examiners ask for projects in this domain.
- Which threat or attack does this project defend against?
- What detection or protection technique is used and what are its limits?
- How are false positives and false negatives handled?
- Which cryptographic algorithms or security standards are involved?
- What legal and ethical rules apply when testing a tool like this?
9. Source Code & License
This project is developed by epicweb-dev and published on GitHub under the MIT License. Please follow the license terms and credit the original author when you use or modify this code.
Want to build this as your internship project?
Work on a Cybersecurity & Ethical Hacking project like this with mentor guidance, weekly reviews and an internship certificate from Training Trains, Erode — online or offline.
Apply for Cybersecurity & Ethical Hacking Internship