1) The got the code by bruteforcing the login credentials on device.
2) Server-side code is not accessible which is where the LAM runs.