Leeds Duo Pwn

#5 / 3 rate

Leeds Duo Pwn

31 users

2021-09-29

rakagunarto

Extension Information

5 star
100%
4 star
0%
3 star
0%
2 star
0%
1 star
0%

Supported Languages

Permissions

Description

Make Duo think you have a Mac for WebAuthn on adfs.leeds.ac.uk domains

This extension simply enables WebAuthn for non MacOS machines on University of Leeds SSO Duo 2FA. Simply put, it's a user-agent spoofer that only changes your UA on specific domains.

Windows Hello Duo 2FA Instructions:
1. Go to "Sign-in options" in Windows, if you don't have a fingerprint scanner or a Windows Hello camera capable of facial recognition, be sure to enable Windows Hello PIN
2. Next time when logging in to duo, click the menu on the top right instead, and choose "Add a New Device".
3. Select "Touch ID"
4. You should now be greeted with a Windows Hello prompt to authenticate yourself
5. Pwned

Source: https://github.com/raka-gunarto/leeds-duo-pwn