Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

How to bypass the CAPTCHA, please? #268

Open
brunocek opened this issue Dec 15, 2023 · 4 comments
Open

How to bypass the CAPTCHA, please? #268

brunocek opened this issue Dec 15, 2023 · 4 comments

Comments

@brunocek
Copy link

Hello.

Am I the first one to get this, please? Any hints?

On w3m I used once a way to hijack the cookie from firefox-esr, might this be the way now?

2023/12/15 01:12:24 << POST /api/auth
2023/12/15 01:12:24 &protonmail.authResp{resp:protonmail.resp{Code:9001, RawAPIError:(*protonmail.RawAPIError)(0xc00039c100)}, Auth:protonmail.Auth{ExpiresAt:time.Date(1, time.January, 1, 0, 0, 0, 0, time.UTC), Scope:"", UID:"", AccessToken:"", RefreshToken:"", UserID:"", EventID:"", PasswordMode:0, TwoFactor:struct { Enabled int; U2F interface {}; TOTP int }{Enabled:0, U2F:interface {}(nil), TOTP:0}}, ExpiresIn:0, TokenType:"", ServerProof:""}
2023/12/15 01:12:24 request failed: POST https://mail.proton.me/api/auth: [9001] For security reasons, please complete CAPTCHA. If you can't pass it, please try updating your app or contact us here: https://proton.me/support/abuse
2023/12/15 01:12:24 [9001] For security reasons, please complete CAPTCHA. If you can't pass it, please try updating your app or contact us here: https://proton.me/support/abuse
@vkstack
Copy link

vkstack commented Dec 17, 2023

This requires directly solving the captcha. You can't bypass it.

@wonderfulShrineMaidenOfParadise
Copy link
Contributor

wonderfulShrineMaidenOfParadise commented Mar 8, 2024

It could be authentication failures, which triggered CAPTCHA.
Try to remove the account in your client(s) for days, wait for the cool down of CAPTCHA, then hydroxide auth again.
You can also try another account when waiting for the cool down.

@h3xagonal
Copy link

Not sure if this relates to the experience of hydroxide users but when my account is non-accessed for an extended period of time logging in the onion web-interface prompts a CAPTCHA challenge on occasion. So perhaps hydroxide is victim to a similar mechanism to deter brute-force.

@kontell
Copy link

kontell commented Jun 14, 2024

I login to Proton using a web browser from the same IP address as hydroxide and that fixes it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

5 participants