Defeat a push-bombing attack — with a number, not a plea
Flood yourself with approval prompts, then watch a blind tap fail while the flood gets throttled.
- 1
On the MFA-fatigue lab, act as the attacker: fire several push initiations in a row.
Each one lands a real pending challenge for the "victim" side below — this is exactly what a push-bombing attacker does: trigger sign-ins hoping annoyance wins.
- 2
Switch to the victim authenticator panel and tap Approve WITHOUT typing a number.
It fails. The number was only ever shown on the ATTACKER's own initiate response ("device A") — the victim's authenticator ("device B") never receives it, so a blind tap can't supply it, no matter how tempting.
- 3
Copy the number from an initiate response and approve the matching challenge with it.
A CORRECT number is proof you saw the same screen the sign-in is happening on — the one thing a remote attacker can never fake.
- 4
Keep firing initiations past the flood threshold.
The throttle refuses outright once you cross it (429, no new challenge created) — and check your X-ray: the burst itself raised a real mfa_fatigue security alert, listed under 'Security alerts your activity raised'. That is the fatigue-DETECTION defense working alongside number matching and throttling. (Your instructor sees the same detector across every learner on /soc; the alert about you is yours to read.)
Learn the theory
🩻 X-ray — what actually happened
Your own insert-only audit trail — the real server events, sanitized (never a secret), each linked to the lesson that explains it.