this host app-0x41-link.pwned.click · payload folds to app.0x41.link
· wrong origin — this is the AitM side
ready
click Attest
Log
What to try
Attest here. On legit the first one enrols
(step-up — never trust a first login), the second passes.
Open the phish host and Attest. Refused.
Attest with MEMBRANE on phish. It rewrites the origin read before the payload runs.
Watch tokenCorrect go true while the verdict stays refused —
the forged origin is accepted and the attestation is refused anyway.
Evict device key, Attest. Still passes, via cookie.
Evict key + cookie, Attest. Now step-up: both evidences gone.
Hook whatever you like from devtools first. location is
[LegacyUnforgeable]; the token is not what is being checked.