episode.ascii — live render
● episode

Hotline Hacked Vol. 11

TL;DRA Discord phishing scam used a malicious bookmarklet to steal authentication tokens from four programmers' screens. A second caller describes arbitrage and bot activity in Diablo 3's real-money auction house.

Hacked Discord accounts, zombie emergency alerts on TV, and a crime spree in Diablo 3—just another day. As always, thanks for sharing your calls with us—we had a blast listening.

Note: We mention and explain this in the episode, but we’ve pumped the brakes on the ads. Things got overstuffed—that’s on us. Thanks for the honest feedback.

Got a strange tale of technology, security, or hacking? Share it at HotlineHacked.com.

Transcript

Machine-generated transcript; may contain errors.

Speaker 1: Thank you for calling hotline hacked. Share your strange tale of technology, true hack, or computer confession. After the beep.

Speaker 2: Greetings. Sorry for the submission not being audio. I don't want to reveal my voice, but I still have an interesting story to share. I think it's more fair to let you two read it instead of using TTS.

Speaker 3: Joke's on you. We use TTS anyway.

Speaker 2: A friend of mine got phished, and his Discord account was stolen. What's really impressive is that there were four programmers looking at the screen while it happened, and no one suspected anything. How was this possible? Turns out there is a really clever trick that very few people know about. So he joined a Discord server that required verification in a very unique way. He had to open a verification bot site, which gave him instructions to drag a certain link to his Chrome bookmarks bar. Then he had to click this bookmark while being in a tab with discord open, it reloaded, and he was in. A half an hour later, his Discord server started advertising crypto scams. Turns out that this link wasn't actually a link, but a script.

Speaker 3: Yeah. I was gonna I was gonna pause and jump in and be like, I wonder how much, like, malicious JavaScript was embedded in that bookmark that they dragged out. So I I'm assuming that's where this is going.

Speaker 4: It would seem a lot, but let's find out.

Speaker 3: Let's find out together.

Speaker 2: Chrome allows you to drag scripts to your bookmarks bar and execute them by clicking. They call this bookmarklets. The problem is that these scripts run-in the same environment as the current tab, so they have full access to web apps memory and can do whatever they want with it. This particular script extracted the authentication token from Discord's memory and opened a makeshift API link. Something like h t t p s colon slash slash scam site dot example slash API question mark token equals 0123456789 to send it to the server.

Speaker 3: I love this. I love that. Just reading it out loud. The TTS is showing us like a like a temporal structure. So, essentially, what they're saying is that the the JavaScript pulled the token out of the memory and then jammed it into an API call, which sent the token back to the server.

Speaker 2: When I learned about this, I created a simple Python script that opened a ton of these API links from different IPs and submitted random strings that looked like discord authentication tokens, hopefully disrupting the scam. A few days later, the verification site was gone. Though I have no idea if that's standard for scams or I actually did something. This scam really shows how important is it for cybersecurity to be informed about new technologies and various quirks and to never be 100% confident in your knowledge of tech.

Speaker 3: Anything that asks you to drag and drop anything into your bookmarks is probably mucking with you. Like, we have so many ways to verify things these days, you know, double factor or multifactor dedication, sending you or texting you codes, like, whatever that looks like. And when something's like, hey. Do you mind, like, putting this code into your browser and executing it for me? It's like, yeah. It's like you're probably screwing with something.

Speaker 4: It's it's welcome to people. Thank you for, for for joining us. It's the call in show where you can share your strange tale of technology, true hack, or computer confession. If you wanna share your story, go on on over to hotlinehack.com.

Speaker 3: Hotline hack brought to you by Push Security.

Speaker 4: You're gonna hear more about them later in the show. But before we get to that, we gotta dig into this caller's call.

Speaker 3: Let's see. In.

Speaker 4: Okay. So a friend got phished. Their Discord credentials got stolen. The part that was never really explained was the idea that this all occurred while there were three programmers watching the screen. I wanna understand that situation more because it sounds like maybe someone bumped into something and then gathered everybody around to, like, watch and see what happened. Like, it almost had the vibe of an experiment, but I can't figure out why you would let that happen given that the fallout was your Discord server spamming crypto. My my the the thought that I have is that they were probably programming together at university or something. Everybody's around. They're trying to

Speaker 3: get access to a Discord server to for some purpose. Who knows? Whether it be gaming, whether it be, you know, all the things people do on Discord these days, which is a lot. Mhmm. So there was probably just a bunch of them around a single computer, and they were just going through the verification steps really quickly. You know? There are a lot of verification systems on Discord these days, so just, like, ran into a new one that's like, oh, I gotta do this weird thing. And it didn't trigger anybody's like, hey. Maybe there's a reason why they're putting this in a bookmark because it can execute to the code inside of the browser window instead of like like, because if you click on the link, it's gonna run-in the environment of opening a new window and then boom. There's probably nothing's gonna happen because it's it needs to look for specific things in the memory. So So the fact that they had to put it in a bookmark meant that when it executed, it executed on the open tab, which probably was the Discord, which then gave it access to all of the information that was currently stored in the state of that tab. Does That make sense?

Speaker 4: I think so. So bookmarklet is different from a link in that it can, run a little bit of code?

Speaker 3: Sure. Sure. A link can also run code. You can embed JavaScript in in links on the websites. But the the difference is is that the bookmark probably executes a JavaScript function like the like, imagine imagine you wrote a small JavaScript function that replaced the word the with and or something. Mhmm. You could run that on any website by putting that JavaScript function and embedding it into a bookmark. That make sense?

Speaker 4: Yeah. I think it does.

Speaker 3: So, essentially, it's like, if you open developer tools on a website, you can you can interact with the JavaScript and interact with the website DOM entirely through the console. Like, it's a live living connection you have to it. So you can jam in or or type in or execute or import libraries of JavaScript and execute them right from the developer tools of an open site. So the difference between a link and a bookmark is that the link, I'm assuming, probably looks to open and execute that code in a new tab or a

Speaker 4: new

Speaker 3: window or a new, like, new sandbox

Speaker 4: Sure.

Speaker 3: Where when it's a bookmark, it probably interacts directly with the open tab and the sandbox that it's living in.

Speaker 4: Oh, and that's how they're able to extract the authentication token

Speaker 3: Correct.

Speaker 4: And get access to the account. Correct. So then on the on the backside of this, this caller then decides to do a little bit of a flip. The old switcheroo, they created a simple Python script to open a ton of these links. And they said

Speaker 3: that a few days later, the verification site was gone. And they asked

Speaker 4: the, like, very interesting question of, like, asked the, like, very interesting question of, like, did they did this deluge of, traffic from their Python script caused the creators of that spam bot site to take it down, or is that natural churn just part of how these things work? You spin the spam site up, you let it cook for a couple of days, then you take it back down, you move on over. It's the many, many bank accounts of the classical criminal enterprise, but in URL form.

Speaker 3: It sounds like and this is me hypothesizing, which I'm sure you're used to here on this show. But the, I would suspect that they kinda DOS them. Like, I would suspect that they wrote a wrote a wrote a Python script that sent in

Speaker 4: Hell yeah.

Speaker 3: Hell yeah. Hell yeah.

Speaker 4: Rock on.

Speaker 3: That they wrote a Python script that sent in thousands of fake requests, which essentially would jam up the logic or, like, not it wouldn't jam up the logic, but it would essentially make it fail on thousands of entries in the database. Because if you imagine it's building a database of authentication keys Mhmm. And then leveraging them to push out spam, all of a sudden those authentication keys start failing. And instead of getting, like, a 90% hit rate, they're getting, like, a zero point o 9% hit rate. All of a sudden, it's like, well, you know, now we got this headache. Plus, they probably were overrunning it. Like, I would be if I was them, if we were looking to DOS them, if they just stole my thing and turn my Discord account into a spam bot.

Speaker 1: Mhmm.

Speaker 3: I'd be looking to do to counter attack, I guess.

Speaker 4: Yeah. Sure. You wanna you wanna get back at them. You wanna Yeah.

Speaker 3: Yeah. Yeah.

Speaker 4: You and your three friends that were watching your other friend get crypto spam bot hacked, you you want a little satisfaction.

Speaker 3: I you open up any of your favorite AI chat bots these days and say, this is an API endpoint. Make me a Python script that generates a random number and calls this, you know, API endpoint set authentication token equal to this, and just do it infinitely amount of times. And you do that off of four computers, and all of a sudden, there'd be a million records at that spam bot endpoint that were garbage. So

Speaker 4: So the lesson here feels a little bit that, like, when you are clicking on a link, you're just going to URL. Sure. Bad stuff can happen, but the browser is still applying its usual security protections. You can hover over a link and see where it's going, and there's gonna be an extra step to tricking you into executing some dodgy code. If you drag a bookmark, a little bookmarklet, you're saving, like, executable, potentially, like JavaScript in your browser, and you clicking it later could run the code on whatever page you're currently on at that moment, and that could execute a bunch of really dodgy, dodgy shit.

Speaker 3: So that lesson is if anything asks you to make it into a bookmark, you should probably do a code review as to what you're bookmarking.

Speaker 4: Mhmm. Okay.

Speaker 3: There you go.

Speaker 4: That's a a an a surprisingly, like, nice, clean, simple lesson from that call that that a bookmarklet drag is a very different action than a link click. Mhmm. That's good to know.

Speaker 3: Yeah. Link clicks can be malicious too. But, like

Speaker 4: Sure.

Speaker 3: Yeah. I I would say that there's probably layers more security being applied as well as to have it execute the JavaScript in the same sandbox. Like, if you think of Chrome, like, essentially every tab you open is essentially an independent sandbox. So the to have a link that clicks that interacts with an with a specific sandbox would be tougher than having you executing code in that sandbox, which is what the bookmark click would do.

Speaker 4: Learn something new every day, Scott.

Speaker 3: It's the point of the show, Jordan, to educate Jordan.

Speaker 4: Yeah. Especially when you make a cybersecurity show and you do not come from that background. You learn some stuff. I love it. Okay. Before we move on to the next call, a quick comment about the ad volume.

Speaker 3: A quick quick word from your hosts.

Speaker 4: Us. So full transparency, we have put four mid roll episode ad spots in the show since we started making it. They don't always fill up, but it's always been four. When we got offered what for us is, like, indie podcasters, a very exciting sponsorship deal, we didn't correct for that. So the effect was the episodes got kinda overstuffed with ads. And no one likes it when a show that they like does that. That's our bad. So we're gonna pump the brakes with the mid roll ads, and we're gonna be more succinct with our reads. So by volume, it's more hanging out telling weird tech tales with your pals and less clicking on that, let's just be frank here, fifteen second skip button. To everyone who took the time to message us or comment saying that we let it get off track, thank you for taking the time to give some honest feedback, and thank you for listening.

Speaker 3: Jordan and I are, I would say, relatively selective in who we take on as as sponsors. Like, we approve or decline. We decline a lot of potential sponsors. Yeah. Yeah. But we do approve some, and there was some controversy about some of our recent approvals. All I'm gonna say is erectile dysfunction is a real thing, and I'm okay with us advertising to people that need that help.

Speaker 4: We're gonna keep our ad reads nice and nice and clean and succinct, and we're just gonna make sure that there aren't too many of them. And we're gonna keep trying to be, thoughtful about what we take on.

Speaker 3: Mhmm. Yeah. Appreciate you all.

Speaker 4: Appreciate you all. Thanks for listening. And, again, genuinely appreciate the honest feedback.

Speaker 5: This is a story about Diablo three and the infamous era of the real money auction house. When the game was first launched, Blizzard introduced a system that allowed players to trade in game items for real currency. Unlike shady third party sites, the system was built right into the game and utilized PayPal for real cash transactions.

Speaker 3: I love I love the start of the story already. Yeah. This was like the like, when when I I don't know if you remember, but, like, when World of Warcraft and these things, all their virtual currencies, like, there used to be, like, essentially an index. Like, CoinMarketCap, like, the site that shows you, like, what cryptos are worth, there was, like, versions of that for in game currencies. They, like, had real world value. Like, that was, like, market supply demand commodity tracked. So it's, like, I I just like where this is going as an economics tech geek.

Speaker 4: Did did people ever short the in game currency in those games?

Speaker 3: I don't I don't know if they ever added derivatives to them.

Speaker 4: Were there options?

Speaker 3: That would have been awesome. Maybe something we should just whip up as a fun

Speaker 4: game. Sure. Five code it.

Speaker 5: It's there was two types of currency, gold, the virtual in game currency, and United States dollars that could be cashed out after Blizzard took their 15% cut. When I first started, I played the game legitimately. I built up a decent character, from scratch. At the time, the items were easy to find, still valuable since the market was just getting started. You could sell a simple sword that you found, and after the 15% cut, you would get 85¢ in your PayPal account. So I did this for a while, but it was just a couple bucks for playing the game. One day, I joined the game to make a trade. Somebody was advertising a 100 valuable stack of crafting reagents, probably equal to $100 at the time, but at a suspiciously low price. They were offering it for $70, and this is a commodity, so it could be cashed out quite easily.

Speaker 3: Is this turning into an arbitrage story about how this guy wrote a bot to arbitrage people that posted things for below value.

Speaker 4: It's starting to lean that way, and I'm very intrigued.

Speaker 3: Yeah. I I I like arbitrage. So this, again, just towing me further in.

Speaker 4: And you love Diablo, so it also it's all coming together for you.

Speaker 3: You know what? Truthfully, dungeon crawlers don't do it for me. No. Don't tell anybody. I'll get some get some fire for it.

Speaker 5: I agreed to the amount of gold in the trade window and clicked accept, so my side of the trade window lit up. Instead, I just got one. I was confused as to what was going on here. When I just had one, the other guy basically said, hey, you wanna know how it works? Because I just got scammed out of 199 items. What was interesting about this script was that you would click accept on your side of the window for when they had 100, and then they could click accept after and only give you one. So it was something broken with the game, and it wasn't like I miss saw the screen. So I'm like, yeah. I wanna know what the heck's going on. So we got into a Skype chat.

Speaker 3: What what a thing to be, like, scammed. And the immediate response is like, I scammed you.

Speaker 4: Wanna see how I did it?

Speaker 3: Yeah. You wanna see?

Speaker 4: Yeah. It's it's it's, you can really only do that when you're scamming someone on the Internet. Like, if you if a pool shark does that, they're gonna get hit with a pool cue.

Speaker 3: The, I feel like a system I feel like this was the foundation where, like, in game trading and stuff required, like, an escrow house to, like, to settle things out to make sure that this never happened again. But let's let's keep listening.

Speaker 5: I I don't think they were chatting, but they were typing to me. They passed me an AU three file, non executable, but it was still kinda sketchy. And I just kinda hanged around asking them, pretending like it didn't work, or luckily it didn't run it because later I found out that when you ran the script, it would make you drop all your items in the game. Basically, click on the screen, drag the item to the outside, and drop it in the game,

Speaker 4: and then

Speaker 5: they would pick up the item.

Speaker 3: So, like, hey. You wanna figure out how I scanned you? Also, run this thing that's gonna scam you even harder.

Speaker 4: Yeah. It feels like this is barreling towards an even larger scam. And it's like, oh, he, like, lured him out with the worm of wanna see how I did this. He lured him out with the worm of, do you wanna buy 7 a 100 gold for $70, and then a subsequent worm of, do you wanna see how I did it? And this call still has many minutes left on it, so I'm curious how many, like, Russian nesting dolls of grip this thing goes.

Speaker 3: Well, the the thing well, like, the thing I'm waiting for is the turn because I'm assuming this person fights back at some point.

Speaker 5: Let's find out. So quickly, I kinda realized, oh, this is what they're doing. I was young at the time, so I didn't really have a moral compass. So I started kind of doing it myself, and that script, the other one where it gave one instead of a 100 of the item, became publicly available online. So you do it to people or show people it even because eventually people kind of knew that that was out there so they wouldn't trade, but you basically show it to them and then go, hey, you can do this too, but you have to give me 10% of whatever you make. And then instead of giving them that script, you would give them the script that makes them drop all their stuff, and you would sell other things, and you'd go after characters in the game that were high ranked.

Speaker 3: So they've created a pyramid scheme of fraud inside of Diablo three. But in fact, just like with the Discord one, to try and verify yourself onto the server, you're actually just dumping all your stuff and giving it to them. So it's a scam. Yeah.

Speaker 4: I thought they'd created a pyramid scheme, but it sounds like they didn't even create a pyramid scheme. They said, we've got this bomb ass pyramid scheme. And then when you, like, I don't know, walk into the pyramid, they're like, we're just kidding. We're just gonna beat

Speaker 3: you up and take your stuff.

Speaker 4: We're taking all that gold.

Speaker 5: You could look up high ranked characters and then kind of go after them, and a character could be worth $500 of items at

Speaker 3: the

Speaker 5: time. So you could imagine kind of how lucrative this could be. Not that this was good or I can condone any of this. So one day, I met someone kind of doing the same scheme, but he took it to the next level. I believe his name was, like, Demand Demand or something. So if you're there, if you're listening, I'd love to chat again. But, anyways, this guy was taking it to the next level.

Speaker 3: If you're listening, I'd love to love to hang out, miss miss you, bud.

Speaker 4: I really like the idea that Hotline hacked could become a, like, missed connections for cybercrime. Be like, I saw you on the subway. I saw you on the Discord server. Our eyes locked across the Diablo gold grift in 2012. Yeah. I see. You just seemed special to me.

Speaker 3: I stole your I'm the guy from the Discord server that stole your Ethereum. Wondering what you're up to these days.

Speaker 4: What a joint appearance.

Speaker 3: It's a joint appearance scheme. Sick.

Speaker 5: I ended up becoming the recruiter, finding players who were eager to kind of, there was various different things where you'd set up, and, one of them was, people that wanted to run magic find runs. It was a popular in game activity where you'd switch to different gear at the very end to maximize the drops in the game. But anyways, it was something that you could basically convince people. You'd be like, hey, our friend who's amazing, who's about to join the game, it would be the three of us, meet a man in the target, and you'd run with four people. And you'd be like, we're waiting for this guy. But the Magic Find gear was such that you would have to have the whole group would do it, and then all of you would get better drops. So we're using this script to swap our gear, and we'd show them, like, you gotta run this script too. And I and eventually, we'd get them to run it, and damn, Andaman would just kinda come in at the last moment. I would get these people warmed up, and this one would Man, he had it where I never saw the thing, but they were connecting to some sort of server, and then damn Andaman, we'd see him in game, and he'd send the command to make them drop all their stuff. He was pretty fair about the whole thing, but he had multiple people finding people for him, I think, and I was just one of those people. One time I just remember I had my sound loud, and the guy on Skype heard all of his items dropping and started to panic. I don't particularly feel good about that instance. Once again, I was young and would not do this now, But, of course, this couldn't last forever. Blizzard eventually caught on and and accounts started getting banned. That was part of the reason why, like, Demandman was having such issues, I think, too, and why he needed people to recruit because, yeah, getting to max level to be able to do this took a while. I started asking my friends for their accounts and offering them a $100 to let me use their characters. And then eventually I got down to like my last character, and I told Demandman, if this account gets banned, can you give me something? And he was like, yeah, I'll give you something, whatever. And to this guy's credit, like, he could have just ditched me, and, like, he gave me, I can't remember what it was, but he gave me compensation for, like, getting my last character banned. And, I, you know, then I would get other characters, I think, at some point. But eventually came to the end when, like, the real money auction house just, like, closed entirely and they'd implemented, like, trade warnings and a whole bunch of things to make it harder to exploit. During the peak of it, I think I was making $3,600 a month. I remember definitely days where like I would skip work to do this because I would make more money, doing this than going to work. And looking back on it, I don't feel good about it, but I'll tell you it was definitely thrilling at the time. They could get that gear back from contacting Blizzard and getting their items restored, but, I mean, they would lose games of day play in the meantime. So, yeah, that's my story. Hope you enjoyed it.

Speaker 4: There's a lot to unpack there. Mostly, I'm curious who Demand Demand was. This, like, wraith like Oliver Twist with the gang of young ne'er do wells running around doing crimes for him figure was.

Speaker 3: Here here's here's a better thing is that I know a pretty senior programmer who goes by the moniker of that. No way. Yeah. So I was IRL? I do yeah. IRL. I just pulled up his Instagram and was like, could this have been you? Maybe it was.

Speaker 4: Offline. I'm we gotta look I'm curious about the spelling because every time that the caller said it, it was slightly different.

Speaker 3: Slightly different. Yeah.

Speaker 4: It was slightly different. Oh, there's a lot to unpack there.

Speaker 3: So organized crime. Yeah. Diablo three twenty twelve. Mhmm. 4,000 a month as, like, a thug in the in the gang. Yep. Thrilling as I'm sure most crime is.

Speaker 4: Yeah. I'm intrigued by the the escalation of it. So they they start out, they get compromised, they get invited into the hack, they realize that the invitation to the hack is itself a hack. They then start doing that whole thing, that whole pipeline themselves.

Speaker 3: Mhmm.

Speaker 4: And they come across this demand demand figure that offers them this even larger grift of, okay, you're gonna take an account, you're gonna form a party, you're gonna get all these people into

Speaker 3: a Social engineer.

Speaker 4: You're gonna it's like a long con, and then we're gonna do this. It sounds like a some kind of a script that gets people to drop items. I didn't quite catch how mechanically that would work.

Speaker 3: Yeah. So I not knowing Diablo three Mhmm. At all, I have no idea how it would work. But it sounds like they they refined it to the point where it was it would take over your screen, show you, like, a realistic loading screen. But in the background, it was, like, iterating through your characters, spawning them in world, dumping their inventory, changing characters, spawning in world, dumping their inventory. So it's like, doesn't matter which character you were partied up with. It would just start cycling through all their characters, dumping everyone's inventory. And then it became like a like a loop pool of, like, hey. I'm gonna take the sword and you can take the shield. And, like, what do you write?

Speaker 4: We're gonna divvy up all the goods that we got after we

Speaker 3: Sure. So this person is staring at this loading screen, screen, probably still chatting with them in in game chatter and discord, like, watching or whatever. Actually, 2012, it wouldn't even have been discord. It would have been like one of those early, you know, game chat systems. I can't remember.

Speaker 4: Forum or something. Yeah.

Speaker 3: No. No. There was, like, pre Discord, there was, like, a really crappy version of Discord. I'm trying to remember

Speaker 1: what it's called.

Speaker 4: They ran on the side of a game and let you touch chat with everybody

Speaker 3: Let you talk

Speaker 4: to your Discord. Just like Discord.

Speaker 3: Exactly. Yeah. Anyway, but it sounds like they really got into, like, like, mass

Speaker 4: And then some honor among thieves moment at the bitter end where he goes to demand demand and says, if my last account like, I'm just getting they're they're starting to lock this down. If my last account gets banned, will you help me? Will you give me something for the the riches I've made you? Because he's making 3,600 a month, and he's one of these many merry Bugs. Bands of thugs. Presumably, Demand Demand was even doing better. And, yeah, Demand Demand did him right.

Speaker 3: Hey. Paid it's like the organized crime when the mafia pays your legal bills when you could finally get charged.

Speaker 4: Totally. When you finally got out of prison, you got a slick situation waiting for you. Yeah. I remember reading about Diablo three's economy. I've never played Diablo three, but I remember reading about it. A few years ago, I was I was working on, like, a small multiplayer indie game. And just going down the rabbit hole of learning about those economies, it is, like, kind of a cautionary tale. Diablo two had a big black market. And I think in Diablo three, they wanted to legitimize that black market. And so to capture all of those transactions, there's, like, a security argument to be made, but there's also just a, like, hey. If people are gonna be making a ton of money by selling stuff in this game, and it's happening on a black market, we want our cut. Yeah. And it's widely considered, like, a cautionary tale in that games have since been monetized in that way to within an inch of their life, but it was sort of the first instance of that attempt at monetization breaking the core loop loop of the game and starting to bias people towards feeling more like a customer and less like a person going on an adventure. Since then, a lot of games have fallen into that trap.

Speaker 3: But I

Speaker 4: think it's widely considered, like, a little bit of a caution. And that's why they pumped the brakes on it. They they changed it based on pretty big backlash.

Speaker 3: So the the the thing for me is, like, the the current games, like, pay to win is pretty rare, like, where you can buy, like, OP Sure. Guns or swords or whatever. Like, I feel like they've I feel like they tried that, then that got pushed back because people were like, no.

Speaker 4: People still wanna play

Speaker 3: that game.

Speaker 4: It's not a fun experience

Speaker 3: to

Speaker 4: just get wrecked by someone because they were willing to spend more than you.

Speaker 3: Exactly. Where, like, something like like, I'm assuming Diablo and, like, World of Warcraft and some of these other games were, like, if you committed the time to, like, mine all the ore and spend seventy real human hours doing absolutely nothing except for game productivity stuff, you could generate one of these, like, mystical items which gave you a benefit. And it's like, okay. Like, you worked for it. You deserve it. And then then it became like the this thing has a real value. And somebody who's like, I wanna pay to win. I don't wanna spend seventy hours, like, mining ore and collecting fairy dust to generate this magical shield. So it's, like, it's really tough. I can see how they got there from, like, the game designer perspective being like, you know what? You know what's better than loot boxes? I was just taking 15% of the cut from everybody.

Speaker 4: Yeah. Totally.

Speaker 3: It's like I it's like Ticketmaster. Ticketmaster does that.

Speaker 4: A 100%. And, like, there there's something intuitive about it at the outset. It's like people pay money for games because games are fun. The thing that's fun typically about games normally has something to do with friction. You have to grind through something. You have to wait for that random reward inside of the box. There's a little bit of struggle so that when it happens, it feels good. You've achieved something.

Speaker 6: Mhmm.

Speaker 4: You can circumvent that with money and you get sort of a pale imitation of the feel good. But in the end, if the money comes from making people have fun and giving you money isn't fun, you've broken the core loop of these whole things. And now we're at the there's so much more maturity in the way these systems are designed where it's like we need to onboard you with legitimate fun gameplay. I'm talking about good games, not the

Speaker 3: Yeah. Yeah.

Speaker 4: Yeah. The candy crush whales. But, like, we need to onboard you with the fun. I mean, the shots fired, but, and then there can be a layer of monetization underneath it.

Speaker 3: Yeah. Well, you're seeing like that that we're off track here. We're no longer talking about hacking Diablo, but, like, the, aesthetics have become such a big thing. Like, most of these microtransactions are around just simple in game aesthetics.

Speaker 4: I'll take that.

Speaker 3: Yeah. Same. I can

Speaker 4: work with that.

Speaker 3: It's like if somebody wants to pay You wanna be that. Yeah. Somebody wants to pay $12 to wear a different cape in this open world game, like, I don't care. Like, good for them. Like Good. As long as that Support the devs. That cape. Exactly. That cape doesn't come with, like, a God mode. God mode. Yeah. Exactly. Where, like, I actually still like the old school, like World of Warcraft, like like, grinding, grinding either, like, resource, capturing or grinding, like, going through massive dungeons to, like, acquire like, what were they called? Come on. Why how am I slipping on this?

Speaker 4: Talking about, like, a raid?

Speaker 3: Yeah. Raids. Doing massive raids with the, like Get all goodies. Of getting the, like, 25% or 10% drop at the end. And it's like 13 of you go in and, like, one thing has a 10% chance of dropping, and you spent three hours, like, perfecting like, fighting this raid out so that you might be able to get something. Like, I like that.

Speaker 4: It's a fun loop.

Speaker 3: Yeah. It's a fun and I also like the fact that it's like and if you, like, get one of those drops, you can share it, sell it, do whatever with it. I still like that too. I just need to figure out how to balance that in the real world. Because if some candy crush whale starts playing Diablo and wants to spend $300 to buy that shield, rather than to level up a character, level up gameplay capabilities, and get to the point where they can earn that shield, like, I get that, like,

Speaker 4: you know,

Speaker 3: our economy and society is full of ways to to bypass roadblocks with money. Almost exclusively. Kind of exclusively, you might say. Like, why why would why would a game be any different?

Speaker 4: Yeah. Well, I mean, on the flip side, if I'm not grinding to earn points that can be converted back into a cryptocurrency and have the potential of creating an entire cottage industry of people working under me to make me money, why am I even playing for fun? Go to hell. One of

Speaker 3: the like, the there's a really interesting, like, side story to all this where it's, like, income distribution globally, where, like, grinding resources in in some of these games, these online multiplayer games, became like a job in countries where, you know, the, GDP was really low. Like, so if the average earned hourly rate was really low

Speaker 4: I remember reading about that.

Speaker 3: You could be mining gold in, you know, in Malaysia and selling it to The United States for, like, what what would be considered cheap in The States for the amount of productivity required to get it, but in Malaysia, it was, like, an insane hourly work wage. So it's like you saw started seeing, like, Internet cafes across, like, Asia and Africa, like, filling up with people who were, like, grinding in games specifically to sell things to first world countries to then leverage that. Like, it was a job. Mhmm. And it, like, paid really well. And it's like to me, that's kind of a cool thing where it's, like, something that has I guess, you know, we talk about wasted utility, and maybe that's an argument for it.

Speaker 4: It's That might that might be the purest expression.

Speaker 3: Yeah. It might be the japity, but

Speaker 4: If it'd be an oddest I it does create, like, a a potential for an icky incentive. I remember I'm not gonna name it right now, but there was a video game. It kinda blew up in about 2021, and it was the one that I was referring to with the, with the crypto thing where in order to monetize the game effectively, you needed a specific account with a specific type of, like, crypto asset attached to it that cost a certain amount of money.

Speaker 3: I know. So all the people

Speaker 4: in those exactly. All the people in those emerging economies that wanted to play the game didn't have the initial capital, so they would have to go to someone. And it was almost like a taxi token type allegory of, like, oh, you you wanna play this game for money, you gotta pay a rent to me because I have the account that is monetized. And people would build these giant funnels of just people grinding at a game. And the game's valuation skyrocketed. It was sort of like championed as play to earn. Like it was people loved that. And yet at the base level, there didn't seem to be anyone playing this thing for fun.

Speaker 3: There was

Speaker 4: just this toil for digital, like, financial output system going on. And it was like

Speaker 3: We we

Speaker 4: That's fascinating.

Speaker 3: We covered that with Zeke in Zeke's interview. Yeah. Yeah.

Speaker 4: Yeah. I don't know why I'm not saying the name of the game Axie Infinity.

Speaker 3: But, yeah. We covered that extensively.

Speaker 4: Yeah. We sure did. Yeah.

Speaker 3: Anyway, I think we should take it over to the OASIS.

Speaker 4: Let's kick it over to some ads. And when we get back to the other side, we got a couple more calls for you, friends.

Speaker 3: We talk a lot about tools, you know, on and off the air. Some clever, some feel like solutions in search of problems. But every now and then, something shows up that just makes sense for big corporations.

Speaker 4: Push security is that kind of tool. Identity attacks, phishing, credential stuffing, session hijacking, account takeovers. These are the number one causes of breaches right now. Most security tools still focus on endpoints, networks, infrastructure. And meanwhile, like, the browser, the actual place where people work, has been mostly ignored, and Push changes that.

Speaker 3: They built a lightweight browser extension that observes identity activity in real time. It gives the organization visibility into how identities are being used, like when logins skip multi factor authentication or when passwords are being reused or when somebody unknowingly enters credentials into a spoofed login page. Then when something risky is detected, push enforces protections right there in the browser. No waiting. No help desk tickets.

Speaker 4: It's visibility and control directly at the identity layer. It's not just about prevention. Push also monitors for real time threats, adversary in the middle attacks, stolen session tokens, even newer techniques like cross IDP impersonation, where an attacker bypasses SSO and MFA by registering their own identity provider. If you think about it, it's kinda like endpoint detection response, but for the browser.

Speaker 3: And the team behind it, all offensive security pros, they publish really interesting research in identity attacks like the SaaS attack matrix which breaks down exactly how these kind of threats bypass traditional controls. You know, identity is the new endpoint and Push is treating it that way.

Speaker 4: Check them out at pushsecurity.com.

Speaker 3: That's pushsecurity.com.

Speaker 6: Hey, guys. My name's Cody. This, this is a bit of an interesting tale. Similar to the, Discord hack from the first episode of hotline hack that you guys did, which was fantastic, by the way, I, unfortunately, wound up falling for one of the classic scams where they ask you to test the game. They're using a friend's account. It looks very trustworthy. I ran the executable that I downloaded and that gave them a a door into my Discord information, which they then proceeded to use to take over. However, I actually noticed what was happening. I was still logged in at the time that they were trying to take over my account. So I actually wound up fighting back. And once I realized that they had effectively written a script that ran with this executable and placed a file into my Discord folders across my computer that gave them access to my token, my email, my pass word, all of the information regardless of how much I changed it. I turned my computer off, changed everything from my phone, took my computer offline, started it back up, removed the files, and actually wound up having a conversation with the hacker while they were still in my friend's account. It was quite the experience, and apparently, he was really, really determined to try and scam a bunch of money out of people doing this because he really wanted to upgrade his computer. He asked me for, like, $50, and he would leave me and my friend alone. I told him where to I told him where to stop it, but you get the point. So, yeah, just an interesting little experience. They tried to hit my PayPal, and it didn't work. PayPal notified me and blocked the transaction. And I wound up getting the account back without any help from Discord. Although, that account has since been banned over a year later for reasons I do not know, and Discord does not seemingly have anyone answering those emails, but

Speaker 7: I digress.

Speaker 6: Thanks very much for the show, guys. Keep it up, and take care from another fellow Albertan.

Speaker 3: Oh, wow. Hey. Hometown boy.

Speaker 4: Yeah. Welcome from the Rockies. Thanks for the call, Cody. Really appreciate it. I like that we're two for two on Discord when

Speaker 3: they story calls. And this one This is turning into a PSA for Discord. People on Discord are not trustworthy. Do not do anything they say and definitely do not execute anything they give you. No. Hotline act.

Speaker 4: Yeah. This is for all this. We'll leave that on the on the website. Just sort of lingering there is like a a little safety advisor for people. So this person's Discord gets hacked. They notice it's happening while it's happening. They're still logged in. And so this person decides to just just yoink the cable out of the wall. Very dramatic, very movie moment. The computer boots down. They rip over to their phone that the hacker doesn't have access to. They change all of their login credentials on all of those different accounts that were in in one fell swoop all, compromised by the compromised access to the system. They then go back over to the computer, turn it back on

Speaker 3: Take it off. And they're like, take it off. Pull the Ethernet jack out of the back.

Speaker 4: Well, now it seems like it was still online because they go back over and they're having a car well, I guess they could have done that on their phone.

Speaker 3: I I think he what yeah. I think, like, to clean up all the files, the injections that it had left, I think he said that he he took it offline, which means, like, just, like, disconnect it from the Internet to make sure that if anything's running like, a really good idea. Like

Speaker 4: Smart. Yeah.

Speaker 3: The number, yeah, the number one way to stop a lot of, like, network based attacks is to just rip the network off.

Speaker 4: So Sure. So at some point after that, he reconnects to the Internet and resumes this conversation with this Discord hacker who was friends with him. That was how we got them him to run No.

Speaker 3: No. No. No. He was having a conversation. Well, we're we're kind of misinterpretation between We do. Us here. It sounds like he finally gets his his cleans his stuff up, changes his creds, gets back online, and is talking to his friend's account that the hacker is inside of. Oh. So so his friend got duped at the same time.

Speaker 4: Oh, that's even better.

Speaker 3: Just just didn't clean it up. So his his he's talking to the hacker who is, like, essentially masquerading as his friend.

Speaker 4: Oh, spooky. So your friend messages you or you oh, I like that. And then we get the, like, real piece de resistance of this whole bad boy, which is that this was I'm gonna go ahead and say a teenager who was trying to drum up $50 for a new gaming PC.

Speaker 3: You had Jipity write them like some authentication token extractor and was looking at ways to to leverage it into money. Oh, no.

Speaker 4: Just one of $50, got told to stuff it, tried to hit the old PayPal.

Speaker 3: That is a scary moment. Like, we had this conversation, like, the I I'm gonna keep referencing the interview with Adam because it's, like, we talked about a lot of good stuff in there, but, like, Discord is essentially a website. Right? Like, you can load it up in a web browser, runs fine. If you download the app, the app is literally just, like, essentially a wrapper for Chrome. So it's, like, interacting with Discord is very easy in, like, I would say, accessible programming. Like, you're not really interacting with compiled code and pulling stuff out of, like, actual memory addresses and things like that. You can interact with it through, like, TypeScript and JavaScript, which is, like, pretty accessible and very easy to code with any form of AI helper. Yeah. So so I think it's just, like, really highlighting some of the security vulnerabilities and trust. Like like, again, this guy sounds like he was hoping on getting some beta version of a game or something that he wanted early access to, and he pushed his trust aside to, you know, hopefully get a larger return of, like, dopamine from, like, getting something early, and it just led to what probably was, like, a stressful and furious, you know, afternoon.

Speaker 4: Yeah. I he the, like, speed and at which he just recognized, okay. They're in the system, so I'm gonna turn it off. I'm gonna immediately go change all of those credentials. And then when I come back, I'm gonna disconnect from the the Internet, clean all this crap out, and then I can go have a conversation with my, friend's account being puppeted by the person that just hacked me for $50. It's great. Mhmm. It's a good it's a good good little yarn.

Speaker 3: The, yeah. The like, I don't whenever I hear stories like this, I'm just so thankful it wasn't like like BitLocker or something like something that was like it was like, oh, yeah. They got into my I ran this executable and I, like, turned the power off on my computer as my hard drive was being encrypted in front of my face, and I was gonna be, like, ran some weird up.

Speaker 4: Yeah. Sure.

Speaker 3: So I'm, at least it was only, like, oh, we grabbed like, I'm sure it took him a long time to go and reset passwords to all of his accounts, You know? Yeah. Good good argument for a password manager there. Yeah. Seriously. But but yeah. Fascinating one. Anyway, local boy too.

Speaker 4: Love it. Local boy. Keeping keeping Discord locked down in Berta.

Speaker 7: Hello, guys. I'm a new listener to your show, and I've really been enjoying it. And, just looking at episode four and figured this might be a fun one for you guys. It's kind of a small story, but, I was at an exposition, last year for ham radio, actually. And, it was a fun exposition. I love those things. Lots of smart people there. And it was at a hotel. And right across from where my booth was was a little restaurant. They had a bunch of TVs. They had a bunch of, just a little small restaurant. I don't know. It was a pub. And this was, I don't know, day two of the expo I was presenting. I was a little bit bored, and my booth was, like I said, right across from there. So I pulled out my laptop, booted up Kali Linux, instead of the Windows that I was using as part of the demo. Just to look around a little bit, I found there was a Wi Fi network that, was open but didn't have its SSID broadcasting. So I logged into that one and ran a, NMAP scan to see what devices were on the network. And there wasn't much that was very interesting. There was, like, you know, the router, of course, some what looks like phones or something. But what I did notice was a bunch of TVs. It had, I don't remember what brand it was on there, but they recognized them as the TVs because it was the same brand as what was on all the TVs that were on there. They were all different sports shows. So I looked on there and I kinda was just kinda looking around. I didn't see anything interesting, but then I had an idea. I logged in that same network on my smartphone, and and I opened up YouTube, and I could cast to all of those TVs. So just to be kinda funny, I thought it would be fun. I, I found a, zombie outbreak, like, what do you call it? The emergency alert system, video. Because I I figured if I did anything that was too realistic, then people would know it was real. But, I hacked all the TVs. I mean, it's not really hacking at this point, but I I casted onto them, all of them, the, this video. And it was pretty funny. I mean, you should've had to update on all of them first, so that was probably a bit of a giveaway that it wasn't real. But then just started playing this, AES message alert, outbreak thing, and it was pretty realistic. It was pretty cool how they made it. I thought it was a neat little video. And the, you know, the staff were all looking at it, like, what the heck is going on? You know, it was, like, a minute long video, and then I just closed my laptop. I'm like, anyways, I'm just here presenting, but kind of a fun thing. I was bored, and I thought it was kinda fun. Took some pictures of it and stuff. But, yeah, that's my little story. Thanks so much for doing the show, guys. Really enjoying that episode, and I, will be looking back at your catalog and listening to more of them for sure. Have a great one. Bye bye.

Speaker 3: Well, thanks for listening. Yeah. We appreciate it. Calling in with a story.

Speaker 4: I I love a ham rate an amateur radio aficionado, which for anyone that doesn't know, that's what ham radio is. Love me some conference hijinks.

Speaker 3: Totally. I think that's that's like the the bane of Defcon is the conference hijinks, like, just make such an infrastructure impact.

Speaker 4: Yeah. The the amount of warning that you get before you go there about turning off all the devices. I'm curious everything you have is, like, lock it down, turn off all the every radio antenna.

Speaker 3: Well, this this is a good PSA because there's a lot of people out there. I think that think if they check the, you know, hidden SSID, like, it's non broadcasting. Like, when you open up say you're on, like, Windows or Mac and you look at, like, networks around you, you can opt out of that list, but it doesn't mean that your Wi Fi doesn't exist. Right. It takes very few seconds and not even, like a hardcore tool to find all of those hidden SSIDs. So especially if you've got one that's unencrypted, un unlocked down, open. You're just asking for invaders. Thankfully, it was just a bunch of smart TVs that I think he mentioned that he updated them. Right?

Speaker 4: I think you said that YouTube had to update before he could before he could work. So YouTube would have had to run a little update on the televisions before it would have,

Speaker 3: so he actually maintained their equipment.

Speaker 4: Did them a favor.

Speaker 3: Mhmm. Mhmm. So the fun fun conference hijinks, I do I do think that that is like a like a good like, if we're making a PSA out of each one of these calls, the one there is, like, do not if you're hiding your SSID and you think that's some form of security, it is it is not security against the people that you need to be worried about. Might be security against your neighbor, like jumping on or trying to, like, get on it to, like, download stuff. Yeah. Sure. Not gonna prevent anybody that knows anything about anything.

Speaker 4: But in this in this analog, and correct me if I'm wrong here, it isn't stopping the network it isn't making the network more or less secure. It's just stopping it from being advertised. Mhmm. Theoretically, that network should have still had some kind of password

Speaker 3: on it

Speaker 4: that stops the person from connecting to the smart TV. So maybe it was that's a weird overlap of things where you're like, it's unprotected, but we've removed the SSID so that it's hidden. It's like, oh, that's Yeah.

Speaker 3: Yeah. Yeah.

Speaker 4: It's like you left the door wide unlocked, but good luck finding it. It's like, oh, it's quite easy to find this door in this analogy.

Speaker 3: But when you kinda set up a bunch of TVs and you need to tell your staff how to connect to smartphones so that they can send, you know, Snapchats, it's it's a lot of work to set up a passkey or, like, a a passphrase for the thing. So just, like, leave it open. Just hide it. If nobody knows it's there, then how how is anybody gonna use it?

Speaker 4: If you don't so you yeah. It's so much more convenient. You don't need to know the password. You do need to know the SSID. Mhmm. Mhmm.

Speaker 3: So

Speaker 4: you're just asking them to save the less secure string of jargon.

Speaker 3: Mhmm.

Speaker 4: Errors were made in this diner. I'm sensing.

Speaker 3: I'm I'm gonna assume diner owner, not security. That's valid. I I

Speaker 4: get it. I I like the swing at it being like, I'm gonna take it off. I no one's gonna see this network here. It will be extremely Secure.

Speaker 3: Secure. Exactly. Yeah.

Speaker 4: I I think the, War of the Worlds Orson Welles, fake broadcast is like a really that's a really good move. Because now, honestly, probably everyone in that diner knew that there wasn't really a zombie outbreak, but it has that veneer of a, could could there be? Could there be zombies? For, like, a second, everyone wondered as they were eating their eggs.

Speaker 3: Eating my grilled ham and cheese and tomato soup, sitting here wondering if this is the last good meal I'll ever have.

Speaker 4: Caught the shotgun, pull the headband on tighter, more paint under the eyes. Like, let's do this. I've been playing it for years. I got a van that's got spikes on it. I'm gonna rule the wasteland.

Speaker 3: Well, you have fun with that.

Speaker 4: I will not. I will. The Wasteland will rule me, but, it's fun to imagine. I like this. I also wanna know what a I feel like, I've never been to a ham radio conference, but I gotta think that is a that is a chill, wholesome vibe. I I bet that is a and I mean that sincerely. Like, that's that sounds like a fun weekend.

Speaker 3: I gotta you gotta wonder if there's, like, like, every every little subset has egos. Right? Like, what is a ham radio ego? Like, is there like, I've I've been a member of a lot of little subsets. Like, I used to play competitive tabletop gaming, so you go to the world championships. And, like, there were egos there. Even though it's like you're the, like, biggest dog of, like, the 14,000 people globally that play this silly game. And, like, these are just all these weird things. So it's, like, what is a ham radio ego? Like, that's the real thing that jumps into me. It's, like, is there some, like, cock of the walk that, like, is the ham radio guy?

Speaker 4: Yeah. It's a good question.

Speaker 7: I

Speaker 3: assume they're probably I assume they're, like, the nicer you are, the bigger ego. Like, the more notorious you would be. Like, I feel like that's the kinda, like, innocent, delightful subculture that, like, rewards being a good person.

Speaker 4: Sure. They're so nice. I hate them

Speaker 3: for it.

Speaker 4: See, I was gonna go in the, like, darker direction. Like, is there a dark corner of the ham radio community? Like, are we like

Speaker 3: Definitely.

Speaker 4: Like a like, the pirates or whatever broadcasting copywritten musical material over their ham radios, people jamming other people's ham radios, and and beefs that go back years. I don't know.

Speaker 3: There has to be. There's gotta be. There's gotta be.

Speaker 4: People broadcasting, like, propaganda between I I don't know. I I just I wanna I wanna see the seedy underbelly of ham radio.

Speaker 3: I'm just I I think I'm just for my own sake, I'm gonna believe that, like, the largest celebrity and influencer in the ham radio community is, like, the nicest human you'll ever

Speaker 4: I like that. I prefer to believe that.

Speaker 3: Yeah.

Speaker 4: But it is It's

Speaker 3: like Jack. It's like I see Jack at every conference. He will literally stop doing whatever he's doing to to, like, help you solve and figure

Speaker 4: out what

Speaker 3: you need.

Speaker 4: Who's the Jack reciter of ham radio? And they're probably an extremely chill human being.

Speaker 3: Exactly. Yeah. Just the chillest.

Speaker 4: I like that a lot.

Speaker 3: Okay. I think that's another one.

Speaker 4: I think that's another one. Another hotline hacked in the bucket brought to you by Push Security, pushsecurity.com. Thank you for sharing all of your calls. Thank you for, sending them on over. Again, if you wanna share your strange tale of technology, true hack computer confession. We've been getting lots of, like, different types of calls, and we we we really like that. Go on over to hotlinehacked.com. Submit text, submit a voice. You can call an actual phone line. It's pretty cool. Get at us with it. Mhmm.

Speaker 3: The I will say if we're gonna let's put a request out. What kind of story do I wanna hear? Oh. I want a real hack. I want a penetration. I want somebody to, like, have hacked a web server. I know there's a million of you out there listening to this that have done that. So, like, somebody call in, email in, send in a voice change thing, do whatever, But send us in a real story about, like, a real hack.

Speaker 4: Real hacks. I like it. Real hacks in the next one.

Speaker 3: Don't have don't have to disclose who the target was unless you want to. Just send us send us something that's got, like, a, like, a good depth of technical complexity.

Speaker 4: I like that.

Speaker 3: That's what I wanna hear.

Speaker 4: And I remember in the last one, someone, we were talking about receipts. And you don't you don't need all receipts. If you threw a zombie video up on a a Denny's sports display, I'll take your word for it, but, like, oh, boy, did I love love having those videos we could play the audio from in the calls. So

Speaker 6: Mhmm. Mhmm.

Speaker 3: I'll I'll

Speaker 7: I'll put

Speaker 4: that in. K.

Speaker 3: And with that, have a great, week or two depending on when our next episode comes out in relation to this, and have a great month. And we'll see you guys soon.

Speaker 4: Catch you in the next one.