episode.ascii — live render
● episode

Hotline Hacked Vol 14

TL;DRA caller recounts hacking his parents' Net Nanny software as an 11-year-old Guild Wars addict by installing a keylogger, then socially engineering his dad to log in so he could capture the admin password.

We're so back. Another call in episode featuring strange tales of listeners hacking laundry machines, video games, 90's home computers and so much more. Share your strange tale of tech at hotlinehacked.com

Transcript

Machine-generated transcript; may contain errors.

Speaker 1: Thank you for calling Hotline Hacked. Share your strange tale of technology, true hack, or computer confession after the beep.

Speaker 2: Hey, guys. So this isn't the most technically sophisticated story, but I thought you might enjoy it anyways. So this happened back in the February, and I would have been 11 years old. And I was playing a game called Guild Wars. And for those that don't know, that's kind of in the same vein as, like, World of Warcraft. And my parents thought that I was playing it too much, rightfully so, as I was, waking up after they had gone to bed and sneaking downstairs to play for, like, an extra two or three hours.

Speaker 3: Come on. Who hasn't done that?

Speaker 1: I'm feeling nostalgic right now. But let me let me just sneak on down the stairs to that family computer that makes, like, a jet engine sound when you turn it on, and you're like, they don't know. It's like they knew.

Speaker 3: They they knew. It was terrible for you. You needed your sleep.

Speaker 1: Yeah. Let's get back into it. In this episode, brought to you as always by our title sponsor, NordLayer, the network security platform for modern teams. Tell you more about them later in the show.

Speaker 2: Definitely not good for me. So the first thing they did was they just started taking the power cord out of the computer. And

Speaker 3: Easy solution. Just pull the power cord out, and I'll let them turn it on. The only problem is that the power cords are super easy to get.

Speaker 1: If that's where this is going. It's like I rapidly figured out that the, like, blender that we use has the exact same power cord.

Speaker 2: That didn't last last very long because I would just dig through old computer stuff, find a spare power cable, and then hide it in my room to play when I wanted to. So then after that, we, our house didn't have Wi Fi or didn't have Ethernet. So we had a Wi Fi adapter for the desktop, and, it was basically just a little USB that plugged into the back of the computer.

Speaker 3: Poor kid had to play on, like, a USB Wi Fi adapter. The latency? Oh my god.

Speaker 1: I feel like they're about to take away the USB dongle, and you've gotten into a, like so we had rats, so we got a snake. And then we had snakes,

Speaker 4: so we got a mongoose problem type situation. I'm curious what's

Speaker 3: going on. I'm really hoping it goes deeper, and what he does is, like, runs Ethernet cable through the vent ducting in his house and, like, hard lines his computer.

Speaker 2: And, my parents would just unplug it and then hide it somewhere. And I would always find it in closets, drawers, desks, cabinets, all over the place. So it was starting to become a big headache for my parents because it's like they have to limit me, but at the same time, it's like if somebody needed to use the computer, they needed to get the USB. So if they hit it too well, it would be kind of become a huge pain. So, one day, my dad comes to me and he hands me a login, and he's like, here's your login for the computer. And I'm like, okay. Head downstairs, turn it on, and I'm greeted with the login for a program called NetNanny. NetNanny, I believe, still exists today. It is a program that is used by parents to monitor online activity and also limit time. So I log in, and I'm like, okay. Realize that I have a two hour time limit, and I'm like, yeah. Okay. Go to uninstall it. Obviously, they thought of that. Couldn't uninstall it. Couldn't manually delete the files either. So I'm like, alright. I'll play and see what happens. Two hour time limit hits. Obviously, I'm booted off. So I can't do anything on the computer anymore. But I can still access the nanny UI. So I'm going through it, and I I can basically you can see the entire control panel, everything that, the admin can do. But if you click on it, the login pops up, says you need to be an admin, asks you to log in. So I basically prodded poke the program as much as I could. I was like, okay. I I'll just try to guess the password. And every day for, like, a month or two, I would literally just try to physically brute force the password.

Speaker 3: A month or two. See, this is the beauty. It's like, this is how hackers are born. You face adversity, you figure out how to overcome it, and then that just becomes habit to you.

Speaker 1: Just sitting there banging your head against the desk trying to guess your parents' password to the Net Nanny software so you can play Guild Wars.

Speaker 4: That

Speaker 3: This kid's going through withdrawal at this point. Because if he was going places to twelve hours. Yeah. If he was going he was playing ten to twelve hours a day, and now he's being, like, a month and a half of two hours a day, he's I can't believe he has stolen another computer at this point.

Speaker 1: He's jonesing at this point. Yeah. I guess what I I get why you'd be get sitting there guessing passwords.

Speaker 2: So without any luck, obviously. And eventually, I I was like, damn. They got me. Like, I I don't know what to do. I can't get around this. And then I was talking with one of my online friends, and they were we were talking about, one of our friends that had gotten his account hacked. And, they were like, oh, somebody installed a keylogger on his computer. That's how they got him. They got his password in his email. And, you know, I I I quickly start to connect the dots. I'm like

Speaker 1: Hey. I I didn't see it coming. I didn't see it coming. It's a great solution to

Speaker 3: the problem that he's currently currently facing. As long as Net Nanny's not gonna stop him from installing a key logger.

Speaker 1: Can you imagine being this kid's parents? You're like, okay. We we got the power cable. And they're like, he figured out other stuff has the same power cable. Fuck. Okay. The Ethernet. Oh, okay. He got around that. We got a Wi Fi dongle. He found the Wi Fi dongle. Okay. We installed NetNanny. Be like, the kid got a key logger to find our admin login. Yep. I think you just don't own a computer.

Speaker 3: Like No. I I think you just celebrate the kid, and you support them in their journey. You get them you say, you know what's more fun than Guild Wars? Writing code. And we're gonna put you in in online courses, and you're gonna have a Roblox store where you make millions.

Speaker 1: Yeah. Truly. Where does this go? Let's find out.

Speaker 2: Key loggers steal passwords. I need a password. Maybe this will work. So I, you know, Googled online, installed the key logger, tested it out. It worked. So I'm like, okay. Cool. Now the only problem is now that, Net Nanny is set up on the computer, there's not really any reason for my dad to log in again. Like, it it just it runs itself. So I waited till Saturday, and then I I ran the time down a bit. And then I went to my dad, and I was like, dad, I I start this dungeon as soon as I I logged on. I thought it was only gonna take two hours, but it turns out it's gonna take longer than that. Could you give me some extra time? And he's like, you know what? You've been good this week. Sure. You can have an extra thirty minutes. So he goes, gives me the extra time. I open up my key logger and just kind of in disbelief, I'm like, there it is. There's the password. Log in. I'm like, oh my god. I did it.

Speaker 3: You did it. You did it. You did it.

Speaker 1: Ain't no one could take that away from you.

Speaker 3: Little social engineering. Get dad to log in and give you a bit more time.

Speaker 4: Pop up.

Speaker 1: Logging. Oh, I just want to game a little more.

Speaker 3: This dungeon, daddy.

Speaker 1: Gotcha, motherfucker. Like, it

Speaker 3: I love it. I love it. Oh, it's great. The big thing for me on that one is just, like, that's how like, that's just where the where the skill comes from. You know? You get put in a situation where you're facing adversity and need to overcome challenges. And then next thing you know, you're got a key logger on your family computer, and you're hacking your parents' Net Nanny account.

Speaker 1: Is there any more to the call, or was that the end?

Speaker 3: That's the end. Okay. Yeah.

Speaker 1: I mean, I wonder when this would have been because that that Guild Wars came out in 2005. So I we're kind of in the heyday of, like, the MMO cultural moment where it's like people are playing World of Warcraft for ten hours a day. Like, that was a that was a real moment.

Speaker 3: Yes.

Speaker 1: But, like, so what you didn't get back to till, like, the pandemic. It felt Yes.

Speaker 5: I don't

Speaker 1: know if that's statistically true, but that's the vibe I get was, like, there was two big spikes of online gaming. It was those two moments.

Speaker 3: I remember and this is, like, going a bit off topic, but you bring up World of Warcraft. And I remember just sitting down at, like, $2,006.07 ish, and just running the numbers because it was a monthly subscription based game, so everybody's paying whatever it was, $29.39 bucks a month. And then you've got, like, tens of millions, hundreds of millions of players globally, and I was like, this game is just a cash machine. But

Speaker 1: Yeah. And Guild Wars was Guild Wars didn't have a monthly subscription. It was one of the it was a weird one that you bought it cash. If I'm remembering my two thousands MMOs, it was a cash game. And I was like, that that's a great way of doing that. And then we weirdly kind of, like, looped all the way back around to, like, not only do you not Yes. Pay a monthly subscription, not only do you not buy it cash, we're gonna advertise the shit out of this thing for free to get you to play it for free so that, like, one percent of you get addicted to, I don't know, pants in the game. It's just a totally different economic model. But at the time, that was really, really cool that they were like, no. You just buy it once, and you and you get to play it forever.

Speaker 3: I don't play any games on my cell phone, but I had some flights recently. And I was like, yeah. Maybe I'll just take a peek and see what games exist. There is nothing that's not free to play anymore. Like, if you look at all of the top charts, they're all free downloads with in app purchases, and you, like every single game is built on that, like, that cash machine model now. So

Speaker 1: The other day, I bought it was a game from, like, 2013, I wanna say. I bought a copy of the game Journey by That Game Company, which is, like, an iconic game. It's, like, beautiful. It's a little piece of art. It's the game people talk about when they wanna make the case of games as art. It's like that in Shadow of the Colossus always comes up. And I went to the App Store, and it was, like, I wanted to play it on an iPad with a controller. I thought that sounded nice. And it was, like, $7.99. Was, like, just press a button, give us $8, and here's a video game. And I was, like, chef's kiss. Beautiful. That's exactly what I want. I was so happy to see that.

Speaker 3: I think the biggest shock in that statement is that Journey is from 2012. That is so long ago. It feels like that game kinda just came out.

Speaker 1: I think that's when it's from.

Speaker 3: I might be talking about

Speaker 1: my ass.

Speaker 3: It is. No. No. I I just looked it up. Interesting. I feel like anyway, we shouldn't we shouldn't meander too much. Let's get some more stories.

Speaker 1: We'll we'll get some more stories. Thank you for that call. Is it's a very cute use of a key logger. We've talked about key loggers on this show. It's like the Zeus hack. Like, all Trojan like, all of these different crazy big cybercrimes that turn around keyloggers, and you just wanted it to game. So thank you for calling. Appreciate it.

Speaker 3: I think a keylogger is one of the most, like, under discussed super powerful hacking tools.

Speaker 1: Yeah. We know.

Speaker 3: Like, just the ability and, like, they're super easy to get on to computers. Like, bad USB was, like, a classic keylogger deployment. There's so many ways to get a keylogger on. And once you have a keylogger on a computer, especially, like, I remember, how do I frame this? Allegedly, not me. University computer labs, you know, you could often sneak a key logger into active memory. And

Speaker 1: Oh, wow.

Speaker 3: You could get access to other people's accounts. Like, it was just like, they're such a powerful utility because they just literally give you in a in a challenge response security world that we're moving away from. I'll say that. But, in the classic challenge response username password world, they were just they're titans, titans of the exploit world.

Speaker 1: I feel like, the clipboard has become a much more interesting surface than the keyboard in the age of password managers. It's like I never most people aren't typing passwords. They're copying and pasting passport passwords. So there's been a, like, an interesting shift there. It's like, I wonder if this this I don't know would work the same way in 2026 as it did whenever this happened, but sure shit worked in whenever this happened.

Speaker 3: Well Appreciate it all. Just to just to hang on that for a second. True password manager usage is the password gets auto filled directly into the input box on a web page or whatever.

Speaker 1: Oh, it it's not even a clipboard.

Speaker 3: You're not supposed to, but so many people use it by going in and copying the password out and then pasting it. And the other crazy thing is is that you can access live data in the clipboard from JavaScript in a web page. So if you had a major web page like

Speaker 1: Sure.

Speaker 3: Newyorktimes.com and you had a JavaScript injection on it that literally just copied the active clipboard components, you would probably actually get a decent amount of passwords just coming out of people's clipboards.

Speaker 1: Probably wouldn't get the email credit. We're getting into the weeds at this point, but it's like Yes.

Speaker 3: We are. Yes.

Speaker 1: It's interesting. Next call. Next call.

Speaker 3: Next call.

Speaker 6: Hey, guys. Here's a few stories starting from the late nineties narrated by Scott's better looking twin.

Speaker 3: Oh, better looking twin. Oh, I do appreciate your voice. I feel like we come from the same nasally camp.

Speaker 1: Yeah. I I can't tell as of right now. I'm I'm gonna hold out judgment. Keep playing. Keep playing.

Speaker 6: Back in the days, during the last two, three grades of primary school, I started my career by hacking a online computer store and moved the number delimiters one position on all items to give my myself a nice discount, but still having prices that didn't stick out too much. My

Speaker 3: Kind of a brilliant move.

Speaker 1: Number delimiter. Delimiter. So the

Speaker 3: period between cents and dollars. So if you were a $100.99, it would become $10.09 or 10¢.

Speaker 1: The $3,000 gaming PC becomes a $300 gaming PC.

Speaker 3: The $6,900 GPU becomes a $690 GPU. Okay. Exactly. Smart. Smart.

Speaker 1: Yeah.

Speaker 4: I

Speaker 3: hope I I I feel like he's going somewhere else with this story, but I'd be interested to hear how he did that.

Speaker 6: My thought was that if things are automated, their system would probably print a package list, which some youth employee would grab and pack without inspecting it a lot. I am from Denmark, so the currency was Danish crowns. So for example, I bought a disc burner, which I think costed around 3,800 Danish crowns, which equals to about 600 USD. After the delimiter was moved one position, the price was instead 380 Danish crowns. I also bought a bunch of burnable discs, a top notch graphics card, and some other stuff. The level of tech and security back then was laughable. The web shop sent the product price as a URL query parameter when adding it to the

Speaker 1: Woah. URL query parameter helped make this make sense.

Speaker 3: Help this make this sense to me. So so URLs have, question marks in them sometimes as, like, an end. Like, you'll see, like, you know, google.com question mark

Speaker 4: Sure.

Speaker 3: U equals something. So those are parameters being sent to the web server via the URL that are then parsed. So if the price is coming like, when you click on a product on an online store and it's like, you know, microtech.net/gpu/5090 quite like, question mark p equals 36,000. Like, the price is a a variable in the query, and you can just modify the the query. That would be very, very easy to do and and the insane security flaw in whatever online store they were using. Sure. Does that make sense?

Speaker 1: I think so. Yeah. I'm curious how that translates through into, like, payment and all that other stuff.

Speaker 3: Yeah. It must I Overpaid

Speaker 1: overwrote it or something. Yeah.

Speaker 6: Rather than than referencing a product ID and pulling the details by that. So you had to simply copy the link on the add to cart button, paste it into the URL bar, change the price, and hit enter. Surprisingly, the order went through. A few days later, the goods was delivered, and I never heard anything from the shop. I tried to make another order a few months later, but it got canceled due to system errors. So I get

Speaker 3: It's good that they found it. It's good that you managed to somehow snake a deal, but

Speaker 1: Yeah. Your deal is probably how they found it. Like, they probably were like, ass. We just sold this disc burner for $19 or whatever. Like, okay.

Speaker 3: What happened? Little month end reconciliation. They're like, how did we sell this for $20?

Speaker 1: Yeah. Who who gave out the coupon code and then you go digging? That's a pretty good one.

Speaker 6: Yes. They introduced some manual order confirmation.

Speaker 3: Smart.

Speaker 6: Now with one of the best disc burners available on hand, I started raping my 56 key modem, downloading m p three music from Napster.

Speaker 3: This is also making me feel like, nostalgic. Interesting. Just just a dial up modem, downloading MP threes, burning yourself CDs.

Speaker 1: I found my this is a tangent. I found my CD binder from when I was a high schooler.

Speaker 3: Oh my god.

Speaker 1: Just just felonies. And not like, just piracy. Like, just That's felonies. My felony is worth it. The volume. Oh my goodness. You would have thought I was, like, arc I was, like, a prepper. Like, I was archiving for the end of the world.

Speaker 3: You really if you really think about it, like, as in like, Canadians are a bit different, so we were thankfully, we had a different copyright law, but

Speaker 1: We sure as shit did.

Speaker 3: We sure as shit did. The iPod, like, literally everybody that had gen one, gen two, gen three, like, up to, like, the 80 gig, 160 gig, like, classic iPods. Like, a 160 gigs of almost exclusively pirated music was in the pocket of, like, 60% of society. Yes. Just a massive block of, like, provable felonies.

Speaker 1: Oh, yeah. The sticker value. Like, you remember those commercials that, like, you wouldn't download a car, like, anti piracy commercials?

Speaker 3: FBI.

Speaker 1: Just whole fleets of vehicles worth of music by sticker price. Like, I downloaded cars, brother. Like, we there was a lot on that thing. Even before the iPod, it was like I remember figuring out I never had a bougie enough CD player that it was an m p three CD player that could read the files. You had to burn it to the timeline version.

Speaker 3: Yeah. Yeah. Yeah. Yeah. Yeah.

Speaker 1: But figuring out that you could back up m p threes and still use them on a computer computer, I was like, oh, we're off to the races. That means I can just have, like, records and records and records saved to one CD. Very exciting.

Speaker 3: Car a fleet worth of theft. Okay. Let's see where it's going.

Speaker 6: At the time, the Absolute Music albums was popular. They came out frequently and had the most popular ten twenty songs of the period. So I copied the songs of these and found the disc album covers online and printed them on the school's color printer. I now had a pretty good copy of the original. I then started selling them on my school for 50 crowns each.

Speaker 3: Woah. K. We just went we just went we just crossed from, like, joking about felonies to actual felonies. Yeah. But, like, cute.

Speaker 1: Like, he's still in high school. Like, come on.

Speaker 3: Like, a kid, like, selling pop albums.

Speaker 1: Yeah. He's, like, the the nerdy kid that has the CD burner and the inkjet printer. It is just, like, pack I I don't know what absolute is. I'm guessing it's like we had those here. I think it was called Now Music. But it's the thing where they just take, like, the top charting songs, license them, put them on a new CD, put the year next to it.

Speaker 3: 2025.

Speaker 1: And you're a parent being like, I don't know what to get this kid.

Speaker 3: 50 krona is about $8 American now. I'm not sure what it was back when this was going on, but just a little context.

Speaker 1: There you

Speaker 3: go. Probably substantially under what the store because I remember, like, even when I was a kid, buying a CD of music was, like, a $20 purchase. And that was back when

Speaker 2: Yeah.

Speaker 3: $20 was

Speaker 1: worth A lot. A lot.

Speaker 3: What $50 is now. Yeah.

Speaker 6: In stores, the price was about $15,200 crowns. They became popular pretty quick, and I sold, like, one to three copies a day. My profit was at least 40 crowns out of the price of 50. Pretty good business at that age, and it was before no one really knew what it was and before the music industry set in towards piracy and so on. Even the teachers didn't say anything against it. I think I even sold some to the teachers as well. A few years later, now with an ADSL connection, I was playing Diablo two a lot. After accomplishing several level 99 characters and often being in the top 50 Europe ladder, I started becoming a bit bored and wanted to explore what else I could do. I started being active in Blizz Hackers and similar forums and played around with various exploits and tools that could manipulate the game, for example, giving you a fully visible map always, which would optimize your magic find runs a lot, item duplication, and much more. Unfortunately, Blizzard started becoming aware of this stuff and began banning account or perform account rollbacks so that, for example, duplicated items was removed. Therefore, I was wondering how I could up my game. It

Speaker 3: this is an interesting thing. I always find this interesting is when when a game company knows that you're cheating and their response is like a a slap on the wrist equivalent of being like, well, you know, you shouldn't have got that win or that item, so we're just gonna take that away. But, like, you know, don't cheat again, please, instead of being, like, full account ban. Like, I always find that interesting

Speaker 1: when it happens. It to me, it tells a story of, like, the scale of the problem. Totally. Listen. If we went nuclear, we built the tool. We figured out how to figure out that you're doing this. And by the numbers, if we come down really, really harsh on everyone doing this, that's a lot of people that we're gonna kick out of this game. So we're gonna play ball. Like, I have to think there's a little bit of a, like, wow. That would be a lot of people. Value. The the jail's gonna be real full if we start throwing all of y'all in jail for this kinda situation.

Speaker 3: See, but as a game so this is like this I run into this, and we've talked about this before with, like, online first person shooters and stuff is the cheating group is actually relatively small, I think, but they're just so invasive, and they cheat so hard. They have, like, hundreds of accounts. And if you're not hardware banning instantly, it's like, what are you doing? Like, the second somebody's caught cheating, they're probably a prolific cheater. Just hardware banned them instantly. If they wanna go buy a new GPU to, like, play it again, then fine. It's like they the the if the cost of entry of cheating is, like, $5, then rock and roll. But, like

Speaker 1: Yeah. Sure.

Speaker 3: For the love of god, like, please I don't know. I I'm of the camp that, like, if if you the second you start showing you're cheating, you should just be banned because you're ruining the gameplay for everybody else. And I know that the investment side of it, like, daily active users, being able to show that, like, Jordan in Canada has 1,100 active accounts is, like, great for shareholder

Speaker 1: record. Say. There's a reason to keep that number. Yeah. Maybe inflated.

Speaker 3: Yeah. But it but it just causes people like me to just stop playing your game because,

Speaker 1: like When Scott runs his MMO, they will it will offer no quarter.

Speaker 3: Exactly. Hard hardware bans instantly. Spoofers will be busted and caught. Everybody everybody to the gulag.

Speaker 6: It was still in the era of clueless people on the Internet, so I got a free .k domain and uploaded a file to the server. Wildly enough, it was a straightforward Windows executable file, which was named as variants of, for example, new working d two to duper tool, Exa. In reality, it was a NetBus Trojan. I then spammed the file URL and all in game lobby channels and quickly started receiving emails with IP addresses of victims who had opened the file. I would then

Speaker 1: Okay. The AI voice is butchering some of these acronyms. Can we explain this? He sent he spams a URL with He he

Speaker 3: registers Yeah. He registers the garbage domain, throws up a single executable file, says that it's a great Diablo hack, and then spams it across all of the, all of the Diablo what would be Discords now, but Diablo web forums and stuff like that for all the hackers. They all promptly go download this blind executable and run it, and it turns out it's just a Trojan that just throws, like, a remote control, exploit on their computers.

Speaker 6: Neck to their computers and have full access to everything. I could even get livestream from their webcam without, I think, the light indicator of the webcam turned on. I had some great fun looking around in people's stuff or watch their face on webcam. When I randomly opened and closed their disc driver, swapped left and right mouse button. After having fun with this, I started using it for my original goal to see if I could steal some Diablo two accounts. The issue, though, was that screen capture stream wasn't a feature available due to the connection speeds at the time, I guess. And when starting Diablo, your username was saved on the login screen, so you would only enter your password. So if I activated key logging, I would only get random passwords without knowing which user it was associated with. There's a solution to every creative mind, though. I found out that if I open the victim's registration keys database, there was an entry for Diablo. It had a value of the last used username, which is where the login screen would read from to. So I copied the username to my local Tieks file, and then I crashed their running Diablo game. The victim would then start the game again and with key logger activated. I now got the password for the username. I

Speaker 3: any questions?

Speaker 1: It's the first call, but bigger and scarier. I just wanna I just wanna loop back to there's such a wild, like, reverse jump scare in that. We're, like, this guy has this software running on all of these people's systems. Has if we're just sort of believing the story as it's presented, like, webcam access and complete system control, Very spooky situation. And then the the quote I wrote down was, I got back to my original goal, stealing Diablo accounts. So I was like, thank God. Thank God that's all you were trying to do with this. Because there's a much spookier ceiling with, like anyway, I was basically in their living room, unbeknownst to them, watching them in the night like the invisible man. I'm like, thank god you just wanted a game.

Speaker 3: Yeah. There's there's some dark stories about people doing things with this kind of access and people, you know, doing things to themselves. But we don't have to go there. The the only thing that I think we touched on here is so he couldn't see the screen, so he couldn't see their username or their, like, email address they were using to log in, but he could steal their password through the key logger. Yes. So he went into the Windows registry, which if you don't know, there's, like, a massive database in Windows that kind of stores all kinds of stuff. Parameters, settings, you know, control like, it has everything in Windows. Like, can lots of things can be tweaked and twisted in the registry, and it's a place where programs like Diablo can save, like, a cache of, like, what was the last username, like a cookie, essentially, to be like, when I open this up, pull this registry key and populate this field. So he figured that out, figured out how to grab that last down username, would then crash their game, causing them to re log in when he had the key logger on. He would get their password. BadaBingBadda boom. K. He has their account.

Speaker 1: Understood.

Speaker 6: I then made my own game ready at the login screen with the username and password filled in. I then crashed their game again, logged in, and changed the password. No two factor authentication existed back then. Job's done, You would think. But Good Players has multiple accounts because of character limits or for security reasons. So I left the key logger on and waited. I could see the victim entering his password again and again trying to log in. After realizing it doesn't work, they had the thought. What about my other accounts? They would now go through all of their accounts, typing usernames and passwords for each, and everything ended up in my little account collection. Some people was also kind enough to have a texty file on their desktop with all their account credentials. To give myself some time, I would shut down their computer and then log in to each of the accounts and change the password. I quickly collected a huge amount of accounts and moved all valuable items to my own mule accounts. I had several accounts packed with, for example, stone of Jordan rings. Probably the best item in the game as it was mandatory for all character types. And a great item name for this specific podcast too. I had hundreds of all the best items in the game and started making a decent profit by selling them on eBay. LAN parties was also a thing at the time, and I would have all expenses covered easily by swapping an item for a pizza and so on. That's it for now. I can probably dig up some more stories, but that'll be another day. Today, I'm working as a senior software developer, which I probably wouldn't be if it wasn't for all the interesting computer stuff that caught me in the early days. Sorry. But not sorry to all the victims. Hopefully, you learned a lesson and only had your Diablo account stolen and not your nudes, and not your bank accounts either. Well, maybe. But as I said, another day, another story. Thanks for a great podcast.

Speaker 1: Aw. Thank you. And maybe Stone of Jordan will be the name of this episode.

Speaker 3: Oh. Stone of Jordan.

Speaker 1: Stone of Jordan.

Speaker 3: I gotta say that this I think this is a classic tale. Like, kids that get interested in this shit get interested in this shit, and they become kids like me and kids like my better looking twin.

Speaker 1: Yeah. I mean, it's like, what more do you want at that age? Right? I think this call is cool because it's like that that call took us from CD piracy of the February through Blizzhacks and comp a a big escalation of, like, compromising accounts. Totally. But it's just like a person Remote access trojans. Relentlessly to the point that they're deploying remote access trojans to, like, crack other people's Diablo accounts. And it's interesting because it's like this guy now works in security and, like, knows, like, oh, there's there's extremely valuable stuff on these systems that I had access to. It's like it's a minor miracle that nothing worse happened given that people were just deploying EXEs they downloaded off of a hacking the video game forum. Like, it's a that's an interesting one.

Speaker 3: Oh, this still this still happens. You know? Like, everybody's looking for some edge in especially in games where they're not maybe as good at as other people.

Speaker 7: Yes.

Speaker 3: And they're willing to do silly things like download random files from random places and run them on their computer. And then next thing you know, their Bitcoin is gone. And it's like, well, that's kind of the price you pay for doing dumb things.

Speaker 1: It's, just very briefly, that was I get why you would use a a, you know, text to speech and then an AI voice on that. Makes total sense. Classic hacked hotline hacked move to train the AI on some cocktail of our voices and have it read back to us in our own voices. Funny thing about hosting this show is that people will regularly bring up the thing about computers they find weirdest or strangest or most interesting when they find out you host a strange technology tales show. And one of the most common ones is, did you know that people can fake your voice? And I always have to resist the urge to be like, do I know? I have an email inbox that is just not but people sharing their strangest secrets often in my voice. And that's just good fun, and I appreciate it.

Speaker 3: Yep. And once again, this episode is brought to you by our title sponsor, NordLayer, the reality of running a modern team. You know, your people are working from different devices, different locations, different networks, and most businesses have no real visibility into what that looks like from a security standpoint.

Speaker 1: NordLayer is a network security platform that just goes ahead and fixes all of that. It gives you centralized control over who can access your company system, lets you grant or revoke access in seconds, keeps every connection fast and encrypted, and does all of that without any additional hardware or complex infrastructure.

Speaker 3: You can verify users by identity, device, block malicious sites and risky domains, and stay compliant without slowing anyone down. It's built for the way teams actually work today. Check it out at nordlayer.com/hackedpodcast.

Speaker 1: That's nord layer dot com slash hacked podcast. Thank you again to NordLayer for their support.

Speaker 5: Hey, Jordan and Scott. So first of all, obligatory. I really love the show. I discovered it about two years or so ago.

Speaker 3: We love you too, buddy.

Speaker 1: We love you too.

Speaker 5: Oh, and since then, I've been listening to every single episode available in my podcast player starting at the beginning and working my way forwards. So, hopefully, no one else has had this story in the past year because I'm about a year behind, but I guess I'll find out sometime in 2026 when I get fully caught up. So I recently listened to a hotline hacked episode in which an Australian caller told the tale about how they had gotten free payphone use by tricking payphones into thinking that they had input a coin. Basically, making a cha ching sound and the payphone thought that it had been, paid and connected the line. That reminded me of how I used to get free laundry, in college through a sort of similar, but not quite the same trick. So when I was in university, my last two years of university, I spent in off campus housing, living in an apartment building with some friends. And this apartment building had multiple apartments in it, and it also had a communal laundry room on the 1st Floor for anyone in the building to use. Of course, this laundry room did not have free machines. You had to pay each machine for every single load you put through it, because that's just how things are, at least at least here in The States. There were two ways to pay for these machines. You could either pay with quarters by cash or with a mobile app on your smartphone. And if you use the smartphone, the way it would work is you would load money onto your account. So So the phone would have to be connected to the Internet, and you'd add it to credit or debit card, load money onto the account, and then you could use that account to pay every single time you ran a washer or dryer. And what you do is you'd bring your phone into the laundry room with you. Once you had your machine set up the way you wanted it, had your clothes in it, you would select which machine to use in the app, and you'd set the settings on the machine. You'd hit a start button in the app. It would connect with the machine. You'd hit start on the machine. The machine would talk to the app, and then the machine would start and money would deduct from your account. What I found was that if you hit start on the machine and then immediately threw your phone into airplane mode and disconnected from all Internet, the machine would still start, but the money would never deduct from your app. So what you could do then is completely close out of the app and reconnect to the Internet, turn off airplane mode, and the money that you had supposedly spent would still be there. I used this trick for about two years. I loaded my phone maybe once or twice, spent 5 or $10 or so, and just used that 5 or $10 the entire time, I was in that apartment building.

Speaker 3: Shocking fault in the development of the app, but a brilliant bypass.

Speaker 1: I'm slow clapping over here, brother. I lived in an apartment building with a pay laundry system. There's nothing you can do to those machines that I won't be in favor of. I found that so annoying. I was like, I pay to live here and I gotta pay for my like, I was I hated it. The the debit charging machine that you had to mine worked with a card. You had to charge a card using a credit card machine. Yeah. I had to send money to this card and then tap the card. I resented it every single time I did it. I probably didn't do laundry as often as I should have. They kept ratcheting the price up the entire time that I lived there. If I could have done this, I would have done this every day. Like, I'm I'm so on side with you right now. The next part of the story could be horrific, and I would probably you have just so much goodwill for me. Yes. Hell, yeah, dude. I'm gonna

Speaker 3: go, actually, I'm gonna save it for the end. Let's see what he's gotta say.

Speaker 1: Okay. Okay.

Speaker 5: And it worked out great. Told some friends about it. Some friends who had already lived there before I moved in were a little bit upset about they had A little bit upset about how much money they had spent on laundry, but at the end of the day, they were grateful for this trick. I'm not sure if it's still able to be used today. Soon after that, I moved into another apartment building in another city, that had a similar system. I don't remember if it was the exact same app or not. I tried the same trick, and it didn't work. The machine just didn't start when I threw my phone into airplane mode. So it was a little bit sad about that. But I guess at the end of the day, two years worth of laundry is, good enough. I'm content with that. So I hope you all have a great holiday season and happy New Year, and look forward to listen more to the show next year.

Speaker 3: Someone obviously came in at the end of last year. We've got a like, truthfully, we have hundreds of submissions sitting in an inbox. So we're gonna be working our way through these. Yes. But here here's my, here's my old man analog to this

Speaker 1: being Okay. Theft is wrong. Even if it's laundry, you wouldn't download a car. Go off, king.

Speaker 3: That's not at all what I was gonna say. I was gonna say that the back in my day Yeah. Back Yeah. Yeah. Back back in the day. So quarters. Right? The laundry machines used to be a dollar and quarters or a dollar 50 or whatever, and you had to put quarters in.

Speaker 1: Like a nickel, but more. I'm familiar.

Speaker 3: The in electrical, boxes, so those little boxes that are inside of your drywall that hold the hold your power plugs.

Speaker 1: Okay.

Speaker 3: There's little round rings in them that used to be exactly the same size as a quarter. Talking like a washer. Yeah. Well, kind of. They were like a plug that was, like, cut out of the side of these boxes. You'd have to knock them out to run-in conduit into the boxes.

Speaker 1: K. Understood.

Speaker 3: Those those plugs were the exact same size as a quarter. Mhmm. They weren't the same weight, so any kind of, like, complicated vending machine system wouldn't take them. Foams wouldn't take them. Anything that had any kind of control mechanism, but these dumb washers just looked for things that were the right height to slide in. Often, you could get them that were plugged out, so they actually had a hole in the middle of them.

Speaker 1: I was gonna say if you have a hole in the middle, you got a string situation on your hands now.

Speaker 6: So you

Speaker 3: take a little bit of dental floss

Speaker 4: Sure.

Speaker 3: And you tie our fishing line, and you create essentially four, like, yo yos, essentially, with the size of a quarter. And when you slide it in, it clicks the triggers to say, yes. I've been paid. And instead of the money falling down over the chute into the bin, you just keep tension on it. And when it slides back out, you take the take your fake quarters back out, but the laundry machine's running. Ta da. There's the old analog of it.

Speaker 1: Pretty good. I never figured out a hack for my, crappy pay washer situation. I just, like, overfilled it, I think, was probably where I ended up. Destroyed it. Just like well, probably just messed up my clothes and my sheets and stuff because I think it's more damaging to the the stuff you put in it. So I'm I I adore this. I think that's good fun. I think

Speaker 3: Jordan's all in. I'm like free laundry. Laundry is human right.

Speaker 1: We're pretty careful about, like, allegedlys and couching stuff for, like, we're not recommending you do this. And I'm I'm, like, I'm on the verge of being, like, get free laundry. I don't get free laundry. Maybe, like, maybe, like, a mom and pop laundromat type situation. That's a small business. I'm like, yeah. If you're gonna go there. But if there's one of these things in your building, go off. Like, do do what you do what you gotta do. Live your life.

Speaker 3: K. So the next one we've got Yes. Has a has a tale to it. Okay. We were we were sent a story. Oh, yeah. Then we were immediately sent a thing being like, please delete what I just sent you. So we did. You're welcome. And then we finally got a resubmission that had undoxed themselves in it, apparently. Apparently, that was the concern because we didn't listen to the original one.

Speaker 5: I haven't heard of

Speaker 3: the show. Yeah. Yeah. None neither of us have heard this. This might not even make the show. We'll see.

Speaker 1: Let's find out together.

Speaker 3: Let's find out together.

Speaker 4: Alright. I'm gonna take you for a trip. Let's go. I step back in about

Speaker 3: That is unlistenable.

Speaker 1: That is unlistenable.

Speaker 4: 2011, 2012. I was working at a rent listing company. So I you wouldn't have

Speaker 3: Can I can hear it, but do we wanna do it? Because it is madness. Like, they put multiple filters on this.

Speaker 1: It's very hard to tell.

Speaker 3: Let's roll it for a second. Just Roll it

Speaker 1: for a second and see if we could do this. Yeah.

Speaker 4: Alright. I'm gonna take you for a trip. Let's go. So back in about twenty eleven, twenty twelve, I was working in a web hosting company. So I So I feel

Speaker 3: like I'm gonna jump in and just summarize.

Speaker 4: Yeah. We had a lot of customers

Speaker 3: Works at a web host, a lot of ecommerce sites, some WordPress based ones. The most popular one was Magento. They dealt with it a lot on the customer service side. They got pretty good with it.

Speaker 1: K. Was this before or after they worked for the Decepticons trying to topple Optimus Prime?

Speaker 3: I'm just gonna keep pausing and doing summaries so that if we have the option of just not playing this entire audio file, but still to translate

Speaker 1: this thing. Sort of faded down in the background as it's talk. Yeah. I really, really genuinely do appreciate a person calling and doing a recording with their own voice. Like, it's I really appreciate that, and I totally appreciate the need for anonymity. And, boy, did you achieve that.

Speaker 3: But in the in the email thread or the follow-up email thread, they mentioned that their boss had gone to jail and was in prison and stuff. So this is Well, this has a has a yes. This has a tangible outcome

Speaker 1: Okay.

Speaker 3: That they probably are still desiring that anonymity for. So let's see.

Speaker 1: Keep summarizing it, Scott. Keep summarizing it.

Speaker 4: Do something really disastrous. Well, I had to spend a lot of time on that one. That was a pretty ridiculous fight, but, we are really good at seeing how a layout of Magento really looks like with the layer navigation and whatnot. And, one day, I was just showing

Speaker 3: So one day, sitting at work, he opens Pirate Bay. Interesting website to go to at work. And on the top bar, there's a link to a free something. I think he said free Burma.

Speaker 1: It was Burma. Free Burma.

Speaker 3: Yeah. Free Burma.

Speaker 1: I I caught that. Yeah.

Speaker 3: Yeah. Yeah. Myanmar, for those of you who aren't living past 96 or whenever Burma became Myanmar. The and it turns out it's an ecommerce store selling hacks and t shirts and a bunch of stuff. So that's where we're at.

Speaker 4: Alright. Okay. Supporting the good. You know? We're we're terrible people.

Speaker 3: So he figures out that the store that he's looking at is Magento. Right. He starts querying the directory structure as he's very familiar with it and determines that the mage file, which sounds like the site config file, is fully exposed.

Speaker 1: And for just just for my own purposes, Magento is an ecommerce platform?

Speaker 3: Yes. Correct.

Speaker 5: Yes. K.

Speaker 4: Such as, details about

Speaker 3: So he is looking in this mage file. Database Sees that there's a ton of exposed database login information. All of the all of the access information is in there, some SSL configurations. And he notices that the database username is root, which is classic database admin superuser, but also a Linux admin superuser. He also has all the IP addresses for the database server, the web host, everything. So

Speaker 1: Is this for the entire ecommerce platform or just for the one website being hosted on being directed to by Pirate Bay?

Speaker 3: The one website being directed to by Pirate Bay, not for Magento entirely. Cool.

Speaker 4: Who am I saying that that's not actually a root password of the server? I'm just gonna guess, you know, maybe I did. So

Speaker 3: So he has the natural curiosity of if your username and password for the database is Root and then a password, then what are the likelihoods that the username and password for the server, the host, the Linux host, is the same? So now it sounds like he's roped in a colleague and has sent it to one of his colleagues across the office saying, hey. Here's the username and password. See if you can root this server quick, which is you know? Let's see.

Speaker 4: And he says I'm in. He says I'm in.

Speaker 3: Yes. He is. He says I'm in. He says I'm in.

Speaker 4: And I'm like, really? And I said, who's in that server with you? He said, there's just some dude from Romania. And he just said, oh, who is on that thing? Okay.

Speaker 3: Working with me. So, apparently, it was the Pirate Bay's server, not just some e com shop. It was hosted on the Pirate Bay server, and they just managed to backdoor their way into the Pirate Bay server. They ran a who on the Linux box to see who else was in it, and there was one other user from Romania. And the guy who logged in to the admin account didn't even know who it was and didn't even know what the server was. He just got this instruction from somebody in his office being like, hey. Can you get in here? And, apparently, they've just rooted Pirate Bay.

Speaker 1: And without getting into how you feel about that, the high five part was cute.

Speaker 4: Really awesome. But being, like, you know, respectful as we are, we took a look at the lack of an HTTPS file. Rather than fix the problem for them and have them never know, we simply open VIN or the I and let them know in the room. I'm just saying, hey, guys. Look at this. You should really put an HD access here. Blah blah blah. Let's sign you in.

Speaker 3: So instead of so once they're in, they realize what they've done. And instead of doing anything bad, it sounds like instead of fixing the bug that allowed them to get access to it, they left a note in the rooted root user directory explaining how to fix the hole that they came through.

Speaker 4: Maybe we let them know some how to do it in NGINX as well so they can hide these directories. But, anyway, the end of the story is, like, we were able to read into something that the buyer may either own or sanctioned, almost instantly through a shopping cart software. And if we had gone any further, who knows what we could have found? And we didn't care. We don't wanna get shanked by anybody on the dark web. So that's the story, and I'm telling it for two. And I hope that somebody out there recognizes this. And if you, if you know anything about wings, you'll know exactly who you're talking or who you're listening to because, because wings is a very, very peculiar word for a lot of us. I, guess.

Speaker 3: Okay. Okay.

Speaker 1: A mystery. Did you say wings?

Speaker 3: Yeah. I said the wings. It must be some code

Speaker 4: Yeah.

Speaker 3: Acronym for something. So he was kind of like him doxing himself at the end, letting if somebody knows the story or worked in the same place or was a part of the Pirate Bay at the time, maybe he picks it up. Sounds like they were really gentle. They hacked in. They left a note being like, yo. Your Magento install is vulnerable in these ways, and it led us to essentially rooting your box. Here's how you should fix it. Add an HD access here. Ban, you know, access to these folders, etcetera, etcetera, which I think is the sweetest thing one can do when they hack a server.

Speaker 1: Well, let's let's also think about the specific server they hacked. I think it's probably our last call, so let's let's dig into it a little bit here. I my mind goes back to the second or third call where they were like, I'm on a on a a forum, a BlissHacks forum where I can where people are even inclined to download something to try it. Meanwhile, this person has hacked the Pirate Bay, the website where you go to just manically download files that you probably shouldn't have and hope it's the thing that you're looking for. So Correct. There's a world in which this person could have gone up to some real, real chaotic shit. Yes. Not just at the people that run the pirate bay, but of, like, what if just everyone trying to download a torrent instead downloaded this?

Speaker 3: A remote access Trojan.

Speaker 1: Even if that runs for nine minutes or something before someone figures out what's going on, that's probably that's a lot of compromises, I would bet.

Speaker 3: Yes. Yes. You are not wrong.

Speaker 4: Yeah.

Speaker 3: Yeah. Interesting interesting I don't know. Like, gotta be scary. I understand why his back and forth and delete all this stuff now because Of course. I I don't wanna get shanked by anybody on the dark web, which is, was his thing. And and that is probably the case. You don't wanna mess with people above your pay grade in that space. But, yeah, interesting, you know, just classic, hey. We downloaded a new platform, and we set it up so we could sell this stuff to raise money for Burma. And we don't know anything about the configuration of the system, and now, boom, we've just left a big wide open hole in our security and now some random web service customer support people who sounded pretty technical Yeah. Just walked into our server and are now like, hey. You guys have rooted your own box and left your admin password exposed in a web file accessible by anybody in the world.

Speaker 1: I wonder how often that's not the first time we've had that narrative beat where someone leaves the note behind. Like, we've made jokes about this before of, like, the night fox from Ocean's 12, the little thing that the the sleuth leaves behind sitting on the shelf is like a calling card. I I just I I wanna get some calls from people that have been on the other side of that, where they got the polite note. They were the recipient of it. They're like, anyway, then I went in and I checked. And there's the the little text file being like, hey. We were in your house last night, metaphorically speaking. You have a lot of nice stuff in here, and we could have stolen all of it. So, here we got in through the the doggy door. You you're gonna wanna go ahead and secure that somehow. I wanna I wanna hear the other side of that.

Speaker 3: Is it classic? Like, they're back in the back in back in the day. Back in the day. Back in the day. When you'd get onto a UNIX box, like, one of the first commands you run is, like, who? Like, who else is in here? Oh. Is there other other usernames logged in? Because you're all terminal. Right? You've come in through, like, terminals. Yeah. So you're like, oh, there's, like, a few admin accounts and a few user accounts. Like, if you were to be a part of, like, a university computer lab and log in to one of the Unix servers, you would run Hue, and you'll get, like, a 100 people logged in.

Speaker 1: K.

Speaker 3: But there's also another Unix command called write. So one of the OG things is, like, you jump onto a server, you'd who who's on it, and then you just send them a message. And it just pops up in their terminal, like, root at this tty says

Speaker 1: this. Yeah. Yeah.

Speaker 3: And you're just like it's like, hey. And just like like, just, hey. I'm not supposed to be here. And people are like Oh. So yeah. It's like there's a note in your in your in the home directory for for Root. Go take a look at it. Oh, that's It's like and then you're out. Poof. Poof.

Speaker 1: Oh, that was a good call. I'm glad we stuck with that one. The voice was like, sorry if you were listening. I don't know how we're gonna chop this up if we'll play the whole thing or if we'll fade it down and have have Scott summarize it, but I'm glad we stuck with it. That's a good story.

Speaker 3: That is a good story. I think the the big thing is is thanks to all the callers and people that have sent stories in. Like I mentioned, we've got, like, another 150 to 200. Mhmm. We miss doing online hacks. We just haven't had the time. We've had other interviews and stuff booked where we've been kind of focused on that. So today was just a great chance for us to do one, so we're happy to do one. And, yeah, I think we're gonna try and do one a little bit more regularly because they are super fun. So if you have an interesting tale story, hotlinehack.com, you have the ability to dial 1800 number and leave us an up to five minute, and I will repeat this, up to five minute message. Lots of people get cut off halfway, and we can't use your stories. Yes. So so make sure that, like, you're not calling in with a a massive, like, a novel for us. We need a sub five minute tale. Should have a good start and an ending. Please do that for us, and, maybe your your story will make it on the show. Or you can email and text, and we can just, you know, run it through 11 labs and turn you into an old British woman.

Speaker 1: Or one of us. Or one of us. I'm excited to be doing these again. It's been, like, close to a year since we did it. We we did them kinda once a month. It's really fun to be back. And, again, a big thanks to NordLayer for their sponsorship of Hacked. Check them out at nord lair dot com slash hacked podcast. We got people doing the CD m p three piracy. We got crazy pirate bay hacks. We got a lot of good stuff this episode. Thank you again so much for listening, and we'll catch you in the next one.

Speaker 3: Catch you in the next one.

Speaker 8: Starting a business can seem like a daunting task unless you have a partner like Shopify. They have the tools you need to start and grow your business. From designing a website to marketing to selling and beyond, Shopify can help with everything you need. There's a reason millions of companies like Mattel, Heinz, and Allbirds continue to trust and use them. With Shopify on your side, turn your big business idea into sign up for your $1 per month trial at shopify.com/specialoffer.

Speaker 7: The World Cup champion will be crowned this week, and you can trade the tourney through the finals on Cauchy, America's number one prediction market platform. Right now, England is trading at 44% to beat Spain, meaning a 100 trade pays out 176 if they win. On Kalshi, you're trading against other people in a live market. No house, no odds makers. For a limited time, download the Kalshi app and use code hoops to get $10 when you trade $10. K a l s h I. Kalshi, trade the beautiful game. 18 plus only restrictions and eligibility requirements apply. Event contract trading involves risk and may not be suitable for all investors. Prices, values, and available markets may differ from those mentioned. For more information, see .com/regulatory.