L IntegrAuth Lab

← All practicals

P56

Phish a device code — then watch transparency catch it

Start a device sign-in as the attacker, then see the victim screen expose WHERE it actually started.

  1. 1

    On the Device-code phishing lab, act as the attacker: start a request with a suspicious initiator context (e.g. "attacker script, Lagos NG").

    This is exactly what a real device-code phisher does: start a device authorization on THEIR OWN device/script, then get a short user_code to send you.

  2. 2

    Switch to the victim panel, type the code, and read the approval screen before doing anything else.

    A transparent screen shows WHAT is being approved and WHERE it actually started — right there next to your own account. A mismatch with your own device/location is the tell.

  3. 3

    Tap Approve WITHOUT ticking "I started this".

    It's refused (400 confirmation_required) — the explicit self-attestation is REQUIRED to approve, not just a suggestion. A phished victim who blindly taps through gets stopped here.

  4. 4

    Tick the confirmation box and approve for real.

    Approval now requires you to affirmatively assert you started this, right now, on this device — the one claim an attacker phishing you into typing their code can never truthfully make on your behalf.

Do it

Do the steps above on the lab page, then come back and check your progress.

Open the lab →

🩻 X-ray — what actually happened

Your own insert-only audit trail — the real server events, sanitized (never a secret), each linked to the lesson that explains it.