Credential Access
- Category
- Privilege Escalation
- Confidence
- 70% confidence
- Finding
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
- Content
grant_type=urn:ietf:params:oauth:grant-type:device_code&device_code=<device_code>
text `authorization_pending` → keep waiting. `slow_down` → wait longer. `access_denied` → they said no; stop. `expired_token` → start again from step 1. 4. Success gives `access_token` (30 days), `refresh_token` (rotates on every use) and maybe `client_id`. Save them where only you can read them, at `~/.config/andco/credentials.json` (mode 600): ```json {"base": "https://andco.ethanflow.com", "access_token": "…", "refresh_token": "…", "client_id": "…", "expires_at": "<ISO time>"}
