Hotline Hacked Vol. 13
TL;DRA listener faked his college grades using Microsoft FrontPage and the university's free web hosting to fool his strict Asian parents. Another caller detailed years of school network pranks using batch scripts and a remote access trojan…
Schools out for summer. Another collection of computer confessions and strange tales of technology.
Transcript
Machine-generated transcript; may contain errors.
Speaker 1: Thank you for calling Hotline Hacked. Share your strange tale of technology, true hack, or computer confession. After the beep.
Speaker 2: Hi, Jordan and Scott. You can call me Lamb and Rice. I absolutely love the show. Most of my family does, in fact. My five year old daughter often asked me to put the podcast on while driving her to school. I'm not sure whether I should be proud or scared about that fact, but I digress. My story is from my college days about twenty years ago. I was privileged enough to have a family that supported me in my education, and I am forever grateful for that. I used to party really hard and forget to go to class at times, leading to either f's or w withdraw grades for the semester. My parents are traditional Asian parents and very strict when it comes to education. Knowing I couldn't show them my terrible report card, I devised an evil plan. My university at the time gave out web space for all of its students so we could host any content we wanted. I downloaded the HTML for the university's grade portal and was able to alter it using Microsoft FrontPage to change my grades. I made sure to make my grades very average, b's and c's, to make it look more realistic and ease any suspicion. I uploaded the altered HTML to my personal web space and drafted a fake email to myself indicating that grades had been released and could be viewed on the student portal. It had the university watermark and everything. I was very proud of my work. When I logged in to show my dad my grades for the semester, he was disappointed that I didn't do better, but I was elated that it actually worked. It's funny thinking back at the story because if I had put in the amount of effort into my studies versus forging a report card, I would have done pretty well. I now work as a data engineer and have been in the field for about fifteen years, so I write it off as practical experience. I just hope now that my five year old doesn't devise a similar evil plan when she grows up and goes to college. If she does, however, I hope she'll come to me for help.
Speaker 3: Yeah. It's funny because the first thing I thought of was, like, man, just spend so much of your time and utility, like, forging these grades. If you just, like, done it, put in the same amount of effort in a class, I'm sure you would have done fine. And I love that they acknowledge that thing.
Speaker 4: Yeah. It feels like this was just extracurricular study at a certain point. Like, this could have been an assignment. Hey. Use the free web space that we give you to, do a mocked up version of the grades website. Also, welcome to hotline hack. It's the Colin show where you can share your strange tale of technology, true hack or computer confession, brought to you by push security. If you want to share your story with us, go to hotlandhack.com. Lamb and rice. I really like this one. Thank you for sharing both the story and the show with your whole family. Sorry about the last episode. That would have been a not one to share. This is a this is a good one. This one, I never quite forged grades, but this kind of mild, getting in between the teacher and the parent type computer hijink was definitely, definitely my thing when I was younger too.
Speaker 3: I the, I love that his daughter loves the show, and it makes me regret some of the more recent feedback about how we get a little bit more loose lipped with, inappropriate language. And Yeah.
Speaker 4: Maybe We could tighten that up. Maybe we could
Speaker 3: tighten that up for you.
Speaker 4: I definitely don't think of there as being kids listening Yeah. As evidenced by many of the stories. But but you know what? It's a good thing to know. And so if we're if we're gonna get salty, we could give warnings. That's really, really valid. Okay. So Microsoft FrontPage, that seems to be the sort of, like, technical heart of this little this little hijink. Do you are you familiar with that one, Scott?
Speaker 3: Microsoft FrontPage was just one of those products that Microsoft put out as, like, a primitive WYSIWYG, you know, what you see is what you get web editor that kinda came out in early web days being like, here, you can use this to build basic websites without having to know how to write the code.
Speaker 4: Sure. Squarespace space before Squarespace type thing.
Speaker 3: Yeah. OG Squarespace.
Speaker 4: Oh, g Squarespace. It's cool that I mean, he he works as a a data engineer now. So, presumably, he was studying something to do with tech in university. I guess that's a big assumption. He could have gone on to study it. Mhmm. But I find it cool that this university gave out web space to everybody so that they could host whatever content they wanted. I is that common?
Speaker 3: Yeah. I think it was pretty common back in the day. Like, you had your own personal directory. I think that to me is what's at the heart of the heart of the con, we'll call it. Sure. Because because that allowed him to host, like, essentially, a created grades portal on a web like, on the university's URL. So it it would be more believable than if it was like, yeah. My grades are just over here on, like, geocities.com. Sure. It was like, no. It was like, you had to go to the university site, and then it showed the grades. And the parents would be like, okay. This looks legit. I'm sure you pointed that out too. Like, look. Look. Look. Look.
Speaker 4: Yeah. Nothing like clamoring to point out how real something looks to make people think that it's real. Oh, yeah. There was multiple steps to this too because they not only mocked up the website. So it wasn't like, hey, come in and look at my grades already loaded up onto the browser in full screen mode. So you can't see the URL, like, fakes the website and then took the time to consider, okay. My family the family supports lamb and rice. They maybe have a sense that they're not on on a, you know, a road towards a straight a semester. They're partying. They sometimes don't make it to class. In order for this to be realistic, you're gonna wanna rock some b's and c's in that bad boy. They thought ahead. They didn't forge too high. They they forged right where they ought to be, right in that middle pocket to to be a little more realistic and ease some suspicion. They draft the fake email. It was a very thoughtful version of one of these. Mhmm.
Speaker 3: They didn't go full Icarus, didn't fly to the sun with straight a pluses.
Speaker 4: Magna cum laude. They're gonna be the valedictorian of our school and be like, I know this kid's not not going down that path right now. This is a rose.
Speaker 3: I'd be intrigued to know how he faked the email or whether he just, like, drafted up an email to, like, structure that looked like it and sent it from some random email and the parents just assumed it was right. Or if if he actually, like, used some kind of bypass to, you know, use an open SMTP server to make it look like it came from the university, but small details. I'm sure most parents, especially well, if if he's been an engineer for fifteen years, I assume he's around my age. I don't think his parents are probably, you know, hyper technically competent. So Or
Speaker 4: Or or the parent standing over his shoulder, watch this whole thing unfold, nodded, said, okay. Better better grades next time, but glad to see you past everything and walked out of the door, shut the door behind them and went. That was total bullshit. That was all made up. Salty language. I gotta work on that. Yep. That was totally made up.
Speaker 2: But you know what?
Speaker 4: It took a lot of work. It was pretty technically sophisticated. Maybe this kid should go into data engineering.
Speaker 3: Maybe. Maybe. May maybe that was part of his path of discovery. Maybe he was just, like, intro sciences and was like, you know what? I actually quite enjoyed
Speaker 4: that Yeah. Sure.
Speaker 3: That, like, project special project I took on at the end of the semester to, like, confuse and lie to my parents.
Speaker 4: Lamb and Rice was also majoring in English, but this forgery sent them down a much more useful path. I like you know what? That's I'm retconning this whole thing. That's what I think happened here.
Speaker 3: I was gonna say I'm pretty sure you have an English degree. So I I
Speaker 4: I that's why I'm allowed to make that joke.
Speaker 3: That's true. That's true. Oh, man. I also the one other thing that stood out, like, when I was picking this, I only listened to the first few seconds, is how, like, how thankful and grateful they were to their parents for paying for their education. I just love that sentiment. Yeah. Totally respect. No.
Speaker 4: That was big.
Speaker 3: You don't take it for granted. It's not an expectation. I I appreciate and respect that. So when I heard that, I just immediately, like, grabbed this story.
Speaker 4: Yeah. Appreciative. Thank you for calling in. Thank you for the good story at Lamb and Rice. I really dug that one.
Speaker 2: Time listener to hotline act now. Thought it's about time that I call in, tell my story about grade seven to my grade 12 graduation. It started off
Speaker 3: Man, we're just getting an endless amount of people hacking their like, it seems like school related hacks.
Speaker 4: School's out for summer. It's the start of summer now ish. We're getting there. Is this gonna be a whole school centric episode? We're gonna find out together.
Speaker 2: Off with me, I'm injecting cheats into my Xvars schemes, like Call of Duty World at War, Black Ops two, having, like, a modded Xbox. And from that, it it introduced me and show them that you can modify software or make
Speaker 3: The AI apparently didn't do a great job with all the words in this one, so please bear with us.
Speaker 2: Make computers do things that they aren't supposed to do. And being a kid in grade six or seven at this time, you can see how this opened a whole world of possibilities for me. So I remember back
Speaker 3: So he was modding his Xbox and injecting cheats into the Xbox games, grade six. That's what, like, 11 to 12 years old?
Speaker 4: That's pretty good. I don't think I knew someone that had a modded Xbox, and I did know someone that had a modded Xbox until we were into, like, junior high. And I'm sure as heck that he didn't mod it himself. He bought it at the Super Flea Market as you did in the
Speaker 2: time. Then I'd go on YouTube, and I'd search up things like how to hack or how to remotely control a computer. And from that, I was introduced to tools like shutdown dot e x c on Windows or the command prompt or how you could change the color to green in c m b dot e x c and look like you're adding in the matrix. Around this time, I was walking through my school, and I seen someone in the computer lounge or the computer area, with the green terminal open. And he was also one of my classmates. So I approached him, and I'm like, hey. That's so cool. I also do this, and I could also shut down computers. Going forward, we bounced ideas off each other or learned how to batch script together. At one point, we made a script that we distributed to students in our class, which was just like a command line interface, like a batch script, that you can enter a computer name, and it would remotely shut it down. And since all the computers had stickers on them with their name, it was quite easy to identify a target to shut down. And another payload that we had would be a PowerShell script, which would do a text to speech voice saying, insert your finger here, and then it would rapidly open and close the the disk tray to the computer and a bunch of stupid things that you'd expect grade seven students to get off to.
Speaker 3: It's kinda nice that they found each other in this wild world. You know?
Speaker 4: Yeah. It's kinda sweet. I was just walking down the hallway and sees a green terminal open and goes, hey. I do that too. I'll shut down the computers with the computer and then make the disc tray open and shut open and shut and put your finger in it and maybe chop it off like a cigar cutter. It's good stuff.
Speaker 3: I I will say, though, like, when I'm in public and, like, we all have Macs now. Like, there's so many of them. Right? Like, everybody has a Unix computer, so it's not the same. But whenever I walk by and I'm, like, in a public setting and I see somebody with a terminal open, like, ripping in the terminal, I'm like, oh, like, that's a friendly person. Sure. You know, like, it is like a it's like it's like a sticker on a laptop identifies, like, what part of a subculture you are. But if you have a terminal open in a in on a computer, it's like, I know exactly what kind of person you are.
Speaker 4: I see you. I see you over there with that green terminal with with the code tumbling down at, like, the matrix. I love it.
Speaker 3: Shockingly not what they look like, but yes. I'm familiar. I know.
Speaker 2: I know. Cutting forward to about grade 10 of this story, every single student in the school has, a username and password along with the kindergarten students. But as they are kindergarten students, they they all have a shared account with a very memorable username and password of the username a z and the password 123. With this, I guess when they were configuring the account, they didn't really consider kindergarten students in their threat model, and they forgot to enable a lot of security features. Like, at this point, they they block the ability for students to remotely shut down computers. But if you're a kindergarten student, you can easily get past that because there's no restrictions on your account. Along with this, every single computer on the school network came preinstalled with a Samba server. And lucky for us, the kindergarten account credentials also worked on the server, which would let us remotely access or upload files to any computer on the school network as long as you knew the host name to it. We had a piece of software at this time called Trollrat, which was a remote access Trojan. It lets you remotely access computers and, as the name implies, troll them. So you can open up a rickroll, or you can make the screen looks like it's melting or broken, or blue screen of death, the computer. So my friend had the genius idea to upload this to our computer science teacher's computer. And most of the time, the students were very settled with it, like blue screening the computer if they wanted to get out of doing something or if they just wanted, like, a a laugh. But they weren't blatant with popping up messages or opening up websites to my knowledge. I do remember at one point in class, the IT teacher was giving a lecture, and he got a pop up saying trollrat.exe has stopped responding. And with a puzzled look on his face, I believe after that class, he went to the IP department and mentioned how he believes his computer is compromised.
Speaker 3: I I will say it's a strong strong choice to go after the computer science teacher. You're gonna
Speaker 4: wanna go ahead and target a gym teacher, a social studies teacher. You're going after the one person that's gonna know what's going on here.
Speaker 3: Exactly. Exactly.
Speaker 2: Given the security measures that the school has implemented, the best solution that the IP team has found to resolve this malware was to put a script on his desktop of the computer, and you can click it, and it will just kill the task of trollrat.exe.
Speaker 3: That is not the solution.
Speaker 4: That doesn't sound like it would be the solution. Oh, there's something there's some kinda compromise on your computer. We'll just get the turn off the compromise button installed right quick.
Speaker 3: Yeah. And every time you it gets run and you notice that it's being run, you can just turn it off. No big deal.
Speaker 4: So you can't you can't get it off of my computer? And they're, like, driving away in the time it
Speaker 2: took for you to say that. So since we had remote access to every computer in the school, if he decided to kill the rat, we were able to just log back into his computer, run the file again, and then we'd have control again. So their solution was not very well thought out, but I think it goes to reflect how the security was at this point.
Speaker 3: It also shows the complete deficiency of actual security pro like, protocol. Like, hey. There's malware on my computer. It's very, like, mundane as far as malware goes. Okay. We're just gonna put a script on the desktop to kill it. And we're also not gonna look at the other 600 computers in the school and see if it's on there.
Speaker 4: Yeah. There's no question asked about, like, oh, how do you think it got onto my computer? Because that might lead you down the road of going, oh, this is on all of the computers on our network.
Speaker 3: Also, we didn't wanna look through the log files and see what user account put it into the network. Oh my god. It's a kindergarten student's account, and we haven't put any access controls on the kindergarten students. We I was
Speaker 4: gonna I was gonna ask about that that where it's like all the kindergarten kids have the same username and password. And for some reason, this kindergarten username and password combo gives you the access to put files on any device on the entire network.
Speaker 3: It's it's what it sounds like.
Speaker 4: This calm sci teacher and IT department like, I wonder if I was wrong. And meanwhile, the the gym teacher is off in the distance hacking into mainframes, running botnets and stuff. Like like, maybe maybe the talent hasn't been organized quite properly at this school.
Speaker 2: There's a bunch of other stories that I have, like times when we'd remotely authenticate into a student's computer, and we'd turn up the volume to a 100% and play a really embarrassing song in front of everyone. Watching them scramble to turn down the volume or figure out where the audio is coming from. But it all came crashing down when, my friend was using a tool called Canon Able on a school laptop. He was using the future for a man in the middle attack, which basically lets him intercept every single HTTP request in the school network or the school district's network, so upwards of 50 schools. This allowed him to view if you were to log in on a website, it would show him the username and password which you entered into that form. And given that he's doing this all from the school laptop and all of the computers in the school board, dozens of computers are connecting to this tiny school computer, it got overloaded, and it wasn't able to handle all the traffic going towards it, which caused an outage across the entire school board for about the hour that he was doing the man in the middle attack. This raised alarms with the IP department, and they got our forensics team and did some investigation into the source of this. They were able to track down the school computer which it came from and either check security footage or maybe event logs to see who was using the computer at the time. And they did catch my friend. He got a two week suspension for this, and everyone's password in the school board got changed. They upgraded their security. They changed password on administrative accounts. I ended up getting away without any punishment. It did scare me quite straight. Now I've graduated with a degree in computer science. I work in a cybersecurity field on the defensive side. I am very remorseful for a lot of the things I've done at the younger age, but it did teach me a lot. And I'm able to apply a lot of the skills that I learned from black hat hacking on a blue team side of things. But, yeah, that's basically it for mister a. Thanks for listening.
Speaker 3: So you so you sit down at the library computer, and you start a district wide man in the middle attack where you're routing all HTTP traffic through your computer, scrubbing all of these names, passwords, and a private data. Mhmm.
Speaker 4: Thus crashing the entire school board's or school district's computer network because you were trying to run it through, presumably, like, a little Chromebook or something.
Speaker 3: Which causes them to walk away from the IT guy who put the kill troll rats script down and actually go get some competent analysts to come in and figure out what's going on. So so you
Speaker 4: know the the trope in in films and television where there's, like, a the the small town sheriff and then the you know, like a terrible murder happens and they have to call in like the very scary FBI people that pull up in like the black Land Rover helicopter or something and there's this real sense of Oh, no, I was the grown up a minute ago and now the grown ups are here. And it's very disorienting. I'm imagining that's what it was like for this IT department at this specific school, when they suddenly get a call from the very serious IT department at the school board level, or the district or whatever it was called, saying, like, hey, there seems to be a device on your network that's crashed the entire area. We are gonna be showing up. See you soon. I imagine that was a real moment of panic. A real sheriff's waiting for the FBI kind of moment.
Speaker 3: That is a great analogy. I'm sure it very much was. It's like it turns out he used a kindergarten kid's login credentials and was scraping all of the web traffic for confidential information from probably the library computer terminal.
Speaker 4: It's like he was it turns out this person was using a kindergarten's login credentials, and the IT department at the school had to go credential. Credential. There's only one. Oh, and it has access to be able to upload files to the entire, school's network.
Speaker 3: Yeah. Yeah. It's been given, like, god rights on the Samba shares. Samba being, like, Windows file transfer protocol and also commonly used in UNIX and other things.
Speaker 4: Troll rat. I like this one. This is this is both a good story of a person that had a scared straight moment, which I know I've had in my life, and they're useful. I think they're a useful moment to have in your personal history.
Speaker 3: Mhmm.
Speaker 4: Who went on to graduate with a degree in computer science, remorseful for the for the black hat activities of his youth. But I I think really at its heart, it is a it's a workplace comedy about an IT department in over its head in a situation that shouldn't have been above anyone's head.
Speaker 3: Should we write the, the script? Like, do a pilot script for this TV show?
Speaker 4: Yeah. I'd I'd watch.
Speaker 3: I'd watch.
Speaker 4: That one's really good.
Speaker 3: That is good. I do yeah. Classic tales all this time. Feels remorse, goes to university, becomes a blue teamer.
Speaker 4: Totally.
Speaker 3: He's literally on the other side. Kudos to you. Good for you. I'm sure like, that's the thing. It's, like, when you get these kind of interests, how do you explore them? Like if you're a 13 year old or even younger, like I think I started writing code like when I was like seven, eight, it's like you get the itch and there's no way to scratch it without maybe breaking a few policies and laws. And it's like that becomes a real thing. It's like, how do you develop these skills and get interested in these topics? Like, if I decide I really like baseball, like, there's so many ways for me to go out and play baseball and progress in that field. But this is definitely a field of, like, self discovery that can sometimes come at the cost of others. Sure.
Speaker 4: You can tell that, I think the phrase, like, to turn off another person's computer was uttered a couple times in the call. You can tell that that was something that initially caught their imagination.
Speaker 3: Oh, of course.
Speaker 4: Like, you're telling me, I'm over here on my device, and I can turn that device on and off. That probably seemed like the superpower that opened the floodgates to realizing that, like, you can you can do a lot more than turn the other computer off. There's basically nothing you can't do. You can operate it as though you are sitting behind it,
Speaker 3: up
Speaker 4: to and including troll rat, rick rolling, opening up the, the CD tray, which is very nostalgic when you described it. It's like a picture sitting in a in a, you know, school computer room with those big old beige. There were always beige towers with the CD tray.
Speaker 3: Mhmm.
Speaker 4: Yeah. You realize you got a little bit of a superpower on your hands there.
Speaker 3: Well, it's it's funny. Like, I I don't remember the timeline there, but, like, he goes from shutdown.exe to yeah. And then we built a remote access Trojan.
Speaker 4: Big escalation. Yeah. So running a metal man on the middle attack on the school district.
Speaker 3: What was that? Exactly. You you could see the progression as it goes from, like, yeah, we figured out how to, like, you know, pop make a pop up or, like, crash somebody's computer to, like, next thing you know, it's like, okay. I got remote access trojans on every computer in the school district. Yeah. Next step. It's like, yeah. We're running a man in the middle attacks scraping web traffic for confidential data, unencrypted data. And it's like, okay. Like, this is a three year progression.
Speaker 4: I bet that school district level it person was so relieved when they discovered it was a tenth grader using the kindergarten account, and not just a really scary kindergarten or doing this. They probably breathed a big sigh of relief of like, oh, we had a real, a real Terminator situation on our hands here. Like we're gonna have to stop this kid. We're gonna have to intervene here because this child is alarming by tenth grade, you haven't figured out how to do that impressive, Good foreshadowing, but not scary. A five year old doing any of this, spooky.
Speaker 3: I wish he'd I wish he'd told us what happened to his friend, the one that did get busted if he was scared straight and put back on the rails. I'll say a two week suspension. Yeah. Pretty pretty reasonable outcome for him.
Speaker 4: Yeah. Two that two weeks is interesting. I'm trying to not to dox myself, but I think I only ever got a one week suspension. Yeah. Same. The damage, it was it was somewhat tech related, but it wasn't this kind of tech related. It wasn't district wide, though. It was localized to my school and involved power breakers. But Okay. It was just for one week, and it didn't affect anybody outside of, you know, that immediate vicinity. So Yeah. Scales.
Speaker 3: I I get But yeah.
Speaker 4: See how they got there.
Speaker 3: Most I ever got was a week two. The but, like, you're essentially committing cybercrime.
Speaker 4: Yeah. Vandalism. At well, fairly large. Yeah.
Speaker 3: I don't a big man in the middle attack taking, scraping confidential data for what is probably thousands of users. Sure. Like, that's That's not That's real. I feel like a two week suspension is like like, if I'm him, I'm happy about that. I'm happy I'm only getting two weeks for that. I'm I'm glad the FBI didn't actually show up.
Speaker 4: I would hope they have better things to do. Because at at that point, it's really just a question of, like, okay. So you got a dud IT guy. Sorry. Yes. This this child this literal child shouldn't have done this, but I'm pretty sure there's bigger fish to fry just in this school to address this problem. I'm also I'm just thinking. The sheer number of like, I love how many calls we get about, like, youthful school various school aged hijinks on this show. Mhmm. School IT people might be the front lines in a way that I didn't really realize they were before we started doing this call in show. Like, when that whole school district went down for an hour, I bet there was no mystery about what had happened. It was that there was a student somewhere who had gotten up to some some stuff. Because otherwise, like, shy of a ransomware attack trying to go after the school district, what's the more likely explanation? That some external state level actor is trying to take down, maybe scraping the credentials, but, man, students seems like a likely explanation.
Speaker 3: Yeah. I don't know. I feel like in when it comes to troubleshooting IT headaches, I feel like you start with, like, the obvious. Like, is it did anything die? Did a network switch go down? Is there a disconnection? It's like, there's something going on. The ability to have the network data to be like, no. It's actually all of like, there is thousands of gigabytes of throughput going to this, like, library computer in this, like, in this district school.
Speaker 4: The disc tray frantically opened and shut it.
Speaker 3: I think we're way past the disc tray.
Speaker 4: No. No. No. This was a separate instance. It was just the pressure on the system. I know that's not how computers
Speaker 3: work at all. But in in reality, like and this is the thing is, like, you know, if if you're really good like, say you're a seven year old prodigy at, like, basketball. People identify you. You start to get put into, like, development programs. You know, there's there's schools that have entire sports programs in them where you do the sport for half of the day and learning for half of
Speaker 4: the day. There's a funnel. There's this big thing about identifying talent and fostering it and building it. I see where you're going with this.
Speaker 3: Yeah. Yeah. And it's like and this is the thing. It's like, we don't do that that much in STEM. And it's like and maybe we should be. Sure. Because it's like, if if they like, when Trojan rat or troll rat
Speaker 4: Troll rat.
Speaker 3: Found the first time, like, that's not just, like, a marker that, like, there's somebody up to some malfeasance. That's a marker that there's somebody in the school that's, like, seven years past the technological expectation that they're there. There's some people have on them.
Speaker 4: Likely talented, if nothing else, passion. There's there's some enthusiasm for something. And you're right that if this was basketball, there would be like a coach standing off to the edge being like, this kid's got it. And instead, there's a comm site teacher going, why is there malware on my computer? Thank you for writing a script that turns the malware off. I can't get over that.
Speaker 3: Yeah. Yeah. Me either. That's that's a wild response to that. But but that's the thing. I would love to see better identification of of like as as having been one of these students. It's like there was thank God I found some positive outlets for it because if I didn't find those positive outlets, I don't know where it would ended up truthfully. Like, because there was so much I wanted to explore, so much I wanted to do, so much you're learning at such a rapid pace. And especially in today's world where like, you can literally sit down with an AI and learn anything in, like, thirty minutes, like, you can build these skills so quick. And it's like, if you have a passion and interest and a desire for it, it's like, we need to I I wish maybe I should run for government, Jordan. Maybe I need to we need some better policies about talent identification in STEM. Or hack the
Speaker 4: school district, get some monitoring software so that next time this happens before the IT people from the district show up, you show up and be like,
Speaker 3: this kid's got it. I think that's the premise for, like, a, like, a sitcom or,
Speaker 4: like, one of those, like really really writers' room at this time. Totally. Yeah. That's like a bad network shows origin story for editors. Like they were recognized when they were seven when they hacked the school. It's like that's not real. And yet we're here advocating that that would actually be kind of rad if that sort of thing existed. The thing is, it probably does exist in certain countries. If you told me that there wasn't that kind of a role in some places on Earth right now, I would be like, you're lying. There's definitely a guy whose whole thing is just being like, someone hacked the school in this province over here. I'm getting an in my car, and we're gonna go figure out who did it because when they turn 18, they're hired.
Speaker 3: Well, all of those bad miniseries, like, bunch of people fighting crime, and they've got an hacker nerd on the squad, and that hacker nerd was arrested breaking into the SEC. It's 18 years old. And it's like, yeah. But you could have identified that person at, like, eleven.
Speaker 4: You could have got him way earlier. You
Speaker 3: could have got him way earlier. Give him better training. He would have been amazing, or they would have been amazing.
Speaker 4: That's really, really good. Yeah. Good call. I just just I I the least interesting part now in retrospect was the modded Xbox, but, boy, that took me back. When I was a teenager, a buddy of mine had a modded Xbox with a, like, hard drive an aftermarket hard drive installed into it because they don't think they had the first version of Xbox had, like, much, if any, local storage, certainly not enough to store a game on it. Yeah. Correct. And he got it was an aftermarket hard drive with, like, 150 full tilt triple a games on it. I remember playing Fable for the first time running it off a hard drive that he bought. I was like, this is the greatest thing I've ever experienced. I wanted one so bad.
Speaker 3: See see, Jordan can see me, but you can't. But this is actually an imported Xbox sitting right there. Hell yeah. Hell yeah. Should we cut over to the ad roller coaster?
Speaker 4: The ad roller coaster. Dang. The infrastructures get build out. It was first, it was a calm oasis that it was a water slide much quicker, and now we're on a roller coaster. Is it a drop? Is it one of those just, like, straight vertical rips? Could be. Could be that we're
Speaker 3: Could be.
Speaker 4: Brought to the people by push security. Yeah.
Speaker 3: I was gonna say could be an identity attack. Oh, boy. There you go. Could be credential stuffing, session hijacking, account takeover. These are all the number one causes of breaches right now, but most security tools are still focused on endpoints, networks, and infrastructure. Meanwhile, the browser, the actual place where people are working, has been ignored.
Speaker 4: Push changes that. They built a lightweight browser extension that observes identity activity in real time, gives you visibility into how identities are being used across your organization, like when logins skip multi factor authentication, when passwords are reused, or when someone unknowingly enters credentials into a spoofed login page. Then, when something risky is detected, push can enforce protections right there in the browser, no waiting, no tickets. It's visibility and control directly at that identity layer where it all happens.
Speaker 3: And it's not just about prevention. Push also monitors for real time threats like adversary in the middle attacks, stolen session tokens, and newer techniques like cross IDP impersonation. The way to think about it, it's kinda like EDR but for the browser.
Speaker 4: And the team behind it, they're all offensive security pros. They publish some of the most interesting identity attack research out there, like the software as a service attack matrix, which breaks down exactly how these kinds of threats bypass traditional controls. Identity is the new endpoint, and Push is treating it that way.
Speaker 3: Check them out. Pushsecurity.com.
Speaker 5: Hi, besties. Love the snow and listen every time it comes out. Love the new hotline format. Mine's not so much a hack, just something we stumbled upon internally. I worked for a large mass conveyancing firm in The UK in the IT department rewriting one of their systems. For some reason, all the machines has SMB file sharing turned on. So if you knew a computer name, you could double backslash computer name c dollar sign folders, etcetera, etcetera, and access their c drive and essentially see all their stuff. This was probably mid two thousands before en masse HR SAS, but we found the HR manager's computer and then just had a good old troll. We found everything. GDPR, EU data regulation didn't exist, and apparently neither did security. We then found a large spreadsheet with the entire staff salary on. We quickly saved that externally and then sat on it. How much the directors c suite were on and what we weren't. A week or so later, we felt we had to disclose it. The hole was closed. The fun was over. We never got on trouble. Shout to my boys Dan, Shuck, Chill, and Lobber. Gilbo remains the worst boss I've ever had. Free to use this on air. Probably don't use my last name. First is fine.
Speaker 4: I really like the shots fired right at the end, and I feel this. Gilbert was the worst boss. You can feel free to use my first name. What was it?
Speaker 3: It it was Gilboe. Gilboe.
Speaker 4: I assumed that the AI had sort of mangled the pronunciation. Gilbo was the worst boss. That's really, really good.
Speaker 3: K. We got some we got some some location clues. He works for conveyancing and love nicknames. So I'm gonna say
Speaker 4: Is this British? Didn't we get some some direct confirmation that this is UK?
Speaker 3: Do you say that? Do you say UK?
Speaker 4: I might have miss I might have just projected the accent of the AI onto the call. They made reference to EU regulations, so saying that this was in the mid two thousands. This was before the point where there were whatever kind
Speaker 3: of Yeah.
Speaker 4: Encryption and protocols for storing that kind of information. And so there was just an HR person who on their computer was a file that wasn't data protected in any way and just had everyone's salaries in the spreadsheet, including the, the c suite and whatever level Gilbo was at.
Speaker 3: I bet I bet most companies still have this spreadsheet.
Speaker 4: Yeah. Yeah. It's like At best, there's a spreadsheet. There's an Apple note somewhere that just says what everyone makes, and it's like, oh, that's that's secure. You got that locked down champ.
Speaker 3: But, it's funny. Back to back story is kind of about Samba shares. So this
Speaker 4: Yeah. What happened here?
Speaker 3: So this is the exact almost the same as the high school one where they found out that, like, if you had the kindergartner's credentials, you could use Samba to, like, kinda walk across the network and go on every computer's hard drive.
Speaker 4: Get onto someone else's device. Right.
Speaker 3: It does have that. This, this enterprise had the exact same thing. It had Sam to set up openly. It doesn't even sound like they needed a kindergartner's credentials, though. I was gonna
Speaker 4: say maybe it had that that a z one two three username password classic Combo. I wonder if they use that to log in. That's damning.
Speaker 3: But just, just like a tale as old as time, you get access to a network. This is, like, this is something that I have an issue with where it's like, when you put me in a network, I inherently just look around it. Like, it's like if you were to take me and put me in a hotel on an island that I've never been to, I would just go for a walk and see what's out there. It's like, I would just fully assume that anything that I'm allowed to see or anything that you let me see, I'm allowed.
Speaker 4: Yeah. I was like, you are using allowed in a very, very loosey goosey way there. You're like, if I'm able to pick the lock and Jimmy the door open, well, how how could I be expected not to see what's on the far side? But, like, it's
Speaker 3: like I've been I've been given access to, like, enterprise networks and stuff, and it's like, if you put in my login scripts an auto mount for a shared drive, I'm assuming you've done that for a reason. So I'm gonna take a look at what's in that shared drive and because some of it might relate to what I need.
Speaker 4: Sure. There might be something like, a good faith reading is, like, if you gave me access to three things, I'm not gonna know until I went into all three that the third one wasn't actually for me, and I wasn't supposed to look at it. That's why you don't give access to stuff that isn't relevant, and you definitely don't give access to stuff that is privileged.
Speaker 3: Yeah. Exactly. So it's like, to me, that's the thing. Like, this is a bit different, I guess, because you're, like, literally using Samba to go into a computer's hard drive that you don't have access to. But I don't know. Like, yeah. Yeah. I mean down your data.
Speaker 4: Yeah. So there's there's two different things here. It's one is, like, don't share things that you don't want the person looking at. And the in this particular cases, the line was I found the HR person's computer. It's like, well, you went you went looking. And I get why because that's where, for lack of a better word, the juicy stuff would be, such as what that turd Gilbo is making. Because that's they just on a human level, you got a you got a bad boss. You wanna know what they're making. Exactly. It's very
Speaker 3: Shout out shout out to the boys.
Speaker 4: Shout out to the boys. Yeah. This one's good. Do do you get the sense this was an external vendor?
Speaker 3: No. Internal employee.
Speaker 4: Internal? Okay. So they so if you're just hired on to rewrite the system, figured out how to get access, this makes sense. Okay. Yeah.
Speaker 3: Yeah. Stumbled across it, found that the network sharing was turned on by default on every PC, and that the c drive was being shared on every PC, probably done by a lazy IT person to Sure. Facilitate file distribution and stuff like that in the back end.
Speaker 4: I wonder if so they they the resolution of the story is, you know, they went, you know, a couple days passed, week passed, or whatever, and we said, we're gonna go report this. We're gonna make sure that they can seal this up so that they can close the hole. I wonder if in that process, they revealed that they had gotten access to the spreadsheet with everyone's salaries in it.
Speaker 3: Oh, definitely not.
Speaker 4: Yeah. I feel like that's something well, you could go two ways with that. There's the and I'd like more money because I know what you all make, which isn't how you deliver that news, but it's the subtext to be sure. And then there's the just I'm gonna go ahead and keep this to myself and not draw a giant spotlight on myself in the form of knowing what the top brass makes as opposed to me.
Speaker 3: I feel like going into a salary negotiation with a piece of confidential data that you stole and took externally, which they did note.
Speaker 4: Mhmm.
Speaker 3: And asking for more money and justifying it by pulling out that confidential information is probably gonna get you fired.
Speaker 4: Or get you the biggest raise of your career. I'm not recommending doing this. If there's any five year olds listening, that's a joke. He will probably almost certainly get you fired or even in more trouble than you you would have been previously in or fat stacks. Anyway, on to the next one.
Speaker 6: I was 17, a third year high school student at a boarding school in Brazil.
Speaker 3: All school ones pretty much. One employee one?
Speaker 4: Yeah. We got we got almost a full house here. We got
Speaker 3: a trend here. We do have a trend. You called it early.
Speaker 6: Yep. The kind of place where you lived and breathe school. Internet access, however, was a different story. This was before smartphones made Internet ubiquitous and Wi Fi, while starting to appear in homes, wasn't common public infrastructure. Our school had no WiFi in the dorms, only in select spots like the library. As a self confessed nerd, I owned an HP iPAC Pocket PC, a handheld device that crucially had WiFi. The school, surprisingly, authorized me to use it. To get online, they had to assign my iPAC a specific IP address. Back then, access control was often managed by white listing IPs. If yours wasn't on the list, you were out of luck. So with my iPax authorized IP in hand, I noticed something. The school was slowly wiring the dorms for cable Internet. The physical infrastructure was mostly there, but IT was configuring computers room by room. Even before they officially activated Internet in my room, my desktop could see the internal school network. It just didn't have an IP address cleared for internet access. A thought struck me. What if I use my iPax IP on my desktop? I tried it. To my genuine surprise, it worked. My desktop was online. For about a month or two, I was one of the few, if not the only students with reliable Internet in my room, all thanks to this IP trick. Then came the official rollout. Our school was Adventist, meaning on Fridays, after sunset, all work stopped. It was a Friday and the IT team was making their way through the dorms. As sunset neared, they were in the room before mine. My room was next. The problem? The technicians were friendly with those guys and were stalling, chatting. I saw the clock ticking. They wouldn't make it to my room. I approached them humbly. Hey, it's almost sunset. Any chance you could quickly pop into my room and configure our computers? We had three in our room. No, we can't. They said firmly that I pushed. Okay. But if I can get them configured, am I allowed to? One tech, probably thinking I couldn't, just shrugged. If you can manage it, go ahead. That was all I needed. Back in my room, I fired up an IP scanner. This tool pings devices to see which IP addresses are active. Since it was Friday afternoon, many computers were being shut down. My scanner listed active IPs and importantly, those becoming inactive. By night, I had a list of free IPs from offline computers. With three PCs in our room, I figured I'd grab two for my roommates. The plan, use them for the weekend, then Sunday night, revert everything to avoid IP conflicts when everyone returned Monday. It worked like a charm. We had Internet all weekend. Come Sunday night, I removed my IP and my cousin, one of my roommates did too, But our third roommate decided he wanted more. I'm gonna use it a bit longer, he said. I warned him, okay. But if you see any IP conflict messages or things get weird, turn off your computer immediately and unplug the network cable. Monday morning, I also worked at the school cleaning grounds. My non compliant roommate came tearing towards me. Dude, he panted, it hit the fan. They came to the room. They found the IP. I was confused. What do you mean? Didn't you turn it off if there was a problem? He explained, I was using the Internet and man, it got super fast. Incredibly fussed. I was downloading stuff like crazy. It was awesome. So I just kept going. The IT team had traced the problematic IP to the network switch on our dorm floor, then to his computer. When they burst in asking who configured the Internet, he immediately pointed, he told me it was you. Great. Ratted out. My first thought, well, at least I technically had permission from that technician. Here's what had actually happened. The IP my roommate was using wasn't just some random students. It belonged to a server. The IT guys were vague on how an IP conflict could cripple their infrastructure or why a server's IP was even available. But the head of the IT said, the problem likely stemmed from how the network switches handled the conflict, particularly concerning the time to live of entries in their IP or ARP tables. When his machine claimed that server's IP, the switches would have updated their tables to point traffic for that server to his machine's MAC address. If the TTL for that entry was long or if the switch's programming didn't handle duplicate IPs gracefully, legitimate traffic for the actual server would be misdirected to his computer for an extended period. His machine, unable to process server requests, effectively created a black hole. This likely caused the cascade failure. The Internet for the entire campus went down. The only place it still worked? My roommate's computer. That's why his connection became blazingly fast. He had all remaining campus bandwidth. Once he named me, the news spread like wildfire. Every student knew. The campus was offline, people panicking about assignments, and I was public enemy number one. Walking to my dorm was a gauntlet, pointing fingers glares. It was him. Students approached stressed. I have a paper due tomorrow. You broke the Internet. I mumbled apologies trying to explain it was unintentional. Reaching my dorm floor, the entire IT team was there clustered around our network switch. As I entered the common area, my dorm mates were there too. Accusations flew. It was you. You don't know the trouble you've caused. The technician who'd given me that dismissive, if you can, go ahead was among them. Seeing him, something snapped. I got angry and yelled back. I only vaguely remember the specifics, but one exchange sticks out. One of them shouted, what do you have in your head? I retorted, can't you see? I have hair. A heated but not technical argument. The next day, formal proceedings. First, the coordinator's office. I explained everything. The IPAC IP, the text conditional permission, the scanner, the weekend plan. Then, a meeting with the head of IT. I apologized sincerely, reiterated it was never my intention and stressed I believed I had authorization and had instructed my roommate to disconnect. My point, I set the stage, but the final trigger wasn't entirely my fault. I even offered my talents and knowledge to help restore the network. Nota que es. My next stop. The school's general director. They seriously considered expelling me. It was close, but I was allowed to stay. Ever since I was a kid, I wanted to be a hacker. More prankster than malicious. Someone understanding systems enough for cool unexpected things. Millennial hackers might recall dial up days. Often no home routers or firewalls. Your IP directly exposed online. This made grabbing an IP via MSN Messenger for innocent pranks, like remotely opening CD ROM drives or changing desktop backgrounds relatively straightforward. I never consider myself a real hacker In this campus incident, while impactful, wasn't technically complex, but the story became legend. At my graduation, as I walked up for my diploma, the entire student body started chanting hacker, hacker, hacker. In that moment, though I didn't feel like one, I'd sort of achieved my childhood dream that I became a mechatronics engineer, though my career leaned toward electronics and programming. Security is a hobby. I have done capture the flag competitions. I guess I'm a hacker now, ethically exploring. The thrill is to break in, the puzzle solving. I don't have much imagination for afterwards. One big lesson, official technicians aren't always the most knowledgeable. I realized I knew more than some school IT staff then. That shaped my problem solving approach and my enduring fascination with security.
Speaker 3: Full circle.
Speaker 4: What a saga. Full full circle. A crime saga set in a boarding school in Brazil. That's pretty good, and a lot in common with some of the others all the way right down to the disk drive opening up and shut.
Speaker 3: I gotta say the thing that gets me about this Yeah. I'm, like, I'm I'm mad on behalf of this person Okay. Is the the technician being, like Right. Two things. One, the technician being, like, whatever. Yeah. If you can do it, go for it. Passively dismissing them. And then the other thing that gets me is the roommate, the idiot that caused all the issues. He was like because that's the funny thing is, like, this person knew that he was borrowing approved and authorized IPs and using them. So he knew that there was gonna be conflict headaches. So that's why they were like, k. Sunday night. Let's clean up the mess a lot. Like, we don't get in trouble. Like, we've been playing Counter Strike all weekend, and now we have to stop. Mhmm. And then the one roommate who was just too selfish, she's like, no. I'm just enjoying this too much. Like, I'll do it later. I'll do it later. I'll do it later.
Speaker 4: Yeah. We need to clean up this crime scene. Make sure you clean up the crime scene by Sunday. Otherwise, the crime scene won't be clean and will get caught in this crime scene. Your friend's like, I love the vibe of this crime scene and just lets
Speaker 3: it run out. It's like, no.
Speaker 4: We had you had one rule.
Speaker 3: Yeah. Exactly. It's like, I did you a favor and now you destroyed me with it. Because had had they actually removed it and the technician showed up and configured on the Monday, it would have been fine. Nobody would have even noticed probably.
Speaker 4: Yeah. And instead, this person gets turned into public enemy number one. We've had a few calls where there's everyone kinda knows. Sometimes no one knows who the copper was in this case, it sounds like. To quote them, public enemy number one, everyone's pointing fingers. It was him. It was him. I have a paper due. What did you do? And now this person's on the road to notoriety culminating with everyone chanting hacker as they walk across the stage. Oh,
Speaker 3: yeah. I'm glad that as a positive incident, though. Like, he was crossing the stage and they were yelling hacker, and he's like, I did it. I did it.
Speaker 4: My childhood dream. That's a silver lining kind of person, and I appreciate
Speaker 3: that. Absolutely. As the eternal optimist here, I'm with him.
Speaker 4: I'm glad that when it got escalated to the head of IP and eventually to the school's general general director, and more so with the head of IP, I'm glad that I believed I was okay. Like, this person graduated. Like, obviously, this all worked out okay for them. And I think that that is a good that to me should be a good excuse. I I explicitly asked the IT people in my building if I could get this up and running. Was I okay to try and get it up and running? And they said, sure. Fill your boots. So I filled my boots, and now everyone's livid at me for how full my boots are. Like, it's a fair point. The people in charge of this said that I could do it and then I didn't. It was fine. And I knew that a potential conflict could emerge if it wasn't undone by Monday. And I asked this snitch, capital s snitch, to get on top of this, and they didn't. So you should be mad at me. You should be mad at that rat.
Speaker 3: I do. Yeah. I love I wonder how the meeting went with the head of IT when they was just like, do you want me to help you guys fix it? It's like a room full of paid technicians, and then there's like a like a student being like, well, clearly, you guys need some help. Right?
Speaker 4: Yeah. It's like, do you want me to fix it? And they're like, well, hypothetically, how would you fix it? It's like
Speaker 3: It's like, well, your arp table cache has got too long of a lifetime, and you just gotta refresh it. It'll all be fine. Just, like, chill.
Speaker 4: Yeah. We're slowly accumulating a dataset on this show Mhmm. Of what leads people into different tech related careers because we always get the origin story, and then people and I really appreciate this tend to share where they they went with things, more so when you get these, less confidential school age stories where people can be a little bit more forthcoming with who they are and where they are in life currently. Sometimes they don't share anything personal about themselves because there's a lot of confidentiality because they hacked a major retail chain, for example, just hypothetically. But I feel like we're accumulating a lot of information on how people get into different tech jobs, and that's interesting to me. I think
Speaker 3: the I think the, like, the yeah. Kind of. Because I think what comes like, the chicken or the egg, you know, what comes first? And, obviously, these people are have the passion and the interest. Like, if you're carrying around a pocket computer Yes. Like, I had one of those. Like, I'll tell you. Like, I've always I was always obsessed with portable computing until portable computing became the mainstream. Now we all have portable computers
Speaker 4: that's sick. And I am it is sick, and I'm obsessed with reducing the amount of time I spend portably computing.
Speaker 3: Totally. Now I'm going the other way being like, am I spending too much time on this thing?
Speaker 4: Now there's a portable computing crisis, you might say.
Speaker 3: Yeah. But, like, I had an HP iPAC that I installed Linux. Really?
Speaker 4: Yeah. Yeah. HP iPAC.
Speaker 3: I'm trying to pick that up. P a q. This looks like I didn't have one of
Speaker 4: those. Sick.
Speaker 3: Yeah. Yeah. For sure.
Speaker 4: A little kinda Palm Pilot looking
Speaker 3: Yeah.
Speaker 4: Looking buddy.
Speaker 3: It's a a personal what are they? PDAs. What does that even stand for anymore? Personal data data assistant Assistant Accessibility. Sensory. It's a that's an acronym I haven't said
Speaker 4: in so long. PDA. Yeah. It's public display of affection is, yeah, personal digital assistant.
Speaker 3: Yeah. There you go.
Speaker 4: That's a great way of branding those. Yeah. Yeah. There was a there was a store near our house that sold used stuff. And at some point, one of these I can't I think it was just palm. I think it was like after the palm pilots, like, era of superiority had faded, and they were just kinda becoming, like, they made cheap ones that you could buy new for around a $100. You get them used for less than 50, and one of them showed up. And I got, like, a used palm PDA when I was younger. And I was I was a businessman. I was a hacker. Like, I was it was, though, the world opened up to me.
Speaker 3: I was
Speaker 4: I thought it was so cool. I was whatever I wanted to be. I thought that thing was so cool.
Speaker 3: And, like, now our phones are ridiculous supercomputers.
Speaker 4: Yeah. And they'll be on our faces soon enough.
Speaker 3: Yeah. They'll be in our eyes very soon in in a few months. And, apparently, on a necklace. I'm not sure if you saw that OpenAI. We could talk about whatever. We don't have to talk about
Speaker 4: Johnny, I've got another payday.
Speaker 3: Yeah. 6 and a half billion dollars for a company that literally has no products. Cool.
Speaker 4: That's a that's an aqua and that might be the world record for Acquihire. Acquihires. Yeah. That's pretty wild.
Speaker 3: 6 and a half billion is a lot of money to pay somebody to come work for you.
Speaker 4: They gotta have a gizmo. We're way off track here right now, but they've they've gotta have a thing. There's gotta be a presentation you give where everyone goes, wow. That was pretty cool. Or Jony Ive is just the all time great pitch man. Like, it's just like those videos that were such a big part of design and tech culture for his era of, like, you know, the white backdrop, Jony Ive talking dramatically over marimbas. He just did that in a room and 6 and a half billion dollars fell out of someone's pocket. We'll see. Wild. Anyway,
Speaker 3: back to the back to the
Speaker 4: the hotline. Good call. I'm fascinated by this boarding school in Brazil that and, like, just this this sort of, like, transitory era of, you know, the dorms getting all wired up for Internet in real time as you're there. Good story.
Speaker 3: Good story. Fat the I'm glad they let you stay in school.
Speaker 4: Me too.
Speaker 3: Yeah. To I wish I should go to it. Didn't have to go to a different boarding school and hack their networks. You could hack a network that you're already familiar with.
Speaker 4: If, if you wanna share your strange tale of technology, true hacker computer fashion on Holland hack brought to you by post security, go to Holland Hacks Dot Com. You can find the phone number. You can find the email. You can submit it as audio. You can submit it as text, and will AI voice of Fiat? We love to hear your calls. Be they set in schools or not schools. Wherever your story is set, send it in. We wanna hear about it.
Speaker 3: And, we'll see you soon.
Speaker 4: We'll catch you in the next one. Take care.