Member-only story

How did I hack Godaddy 2-step Authentication of my own account

In this blog, I describe step by step how I could hack my Godaddy account’s 2-step authentication and take the control back from the hacker as well as sharing my analyzation about Godaddy’s Security Level

Lê Yên Thanh
6 min readOct 8, 2018

Couple of days ago, one of the Godaddy account that I am managing got hacked :( The reason is simple: Password is too weak and no 2-step authentication is turned on. The hacker got in the account and turned on the 2-step authentication (without changing the password) so I can not login or even reset my password (they also ask for 2-step authentication code when I try to reset password from the email request).

First action I take is locking the bank card linked to the account. Then next action is to call for support from GoDaddy but they said they couldn’t help if we don’t have the 2-step authentication code. So I was thinking if I can hack the account back myself without asking for “Daddy’s help anymore :)

Now the purpose for this hack is clear: Find a way to turn off the 2-step authentication of the hacked account.

Start analyzing Godaddy’s Security Level

--

--

Responses (4)