Hotline Hacked Vol. 15 | The $500k Server Room Mistake
TL;DRAn IT worker accidentally unplugged a neighbor manufacturer's only internet connection, causing $500k in losses. A college student then found a campus library kiosk vulnerability, proved it with a DIY keylogger, but was dismissed by IT…
We return to Hotline Hacked with a server rack that shuts down a factory, a college library ignoring a keylogger risk, Claude unexpectedly finding its way into a recruitment backend, and a few hacking stories that spiral in very different directions.
Transcript
Machine-generated transcript; may contain errors.
Speaker 1: Thank you for calling Hotline Hacked.
Speaker 2: Welcome to Hotline Hacked. It's a call in show where you can share your strange tale of technology, true hack, or computer confession. Let's get to the first
Speaker 3: call. My name is Andre, and this is the story of how I accidentally shut down an industrial manufacturer for over forty eight hours. It all started when we were scouting a new warehouse for processing. We found a suitable location in a massive industrial park, and a visit was arranged. It was the usual corporate parade managers in crisp suits, looking as important as possible. I was there as the local IT guy, with my IT manager on the phone. While the delegation marched into the offices, I wandered off to check out the server room. To my surprise, there was a full rack of networking equipment, quietly humming along. That was odd. The previous tenants had already left and, as far as we knew, taken everything with them. I turned to the landlord and asked, hey, what's this for? He squinted at it, shrugged, and said, I don't know. Not exactly reassuring.
Speaker 4: I can only imagine I would've just thought it was a Bitcoin, like an illegal crypto farm. That's what I would've thought. Somebody stealing some power and network connection from an abandoned building.
Speaker 2: Oh, yeah. I don't know what that is. That's crazy. That's weird.
Speaker 4: I doubt that's what it is given that he says he takes down a facility, but but that's what have been the first thing through my head. It's like, oh, somebody's just, like, mining crypto on somebody else's infrastructure.
Speaker 2: Crypto farm subterfuge in an industrial setting? There's worse places. I think there's there's worse places to run that. Not that we're recommending that you do that.
Speaker 4: Yeah. Definitely not. Definitely not going.
Speaker 3: Can you find out if it's being used for anything? I asked. A quick phone call later, he returned with, it's probably from the last tenants. It's not ours. So, you're okay with us removing it? Absolutely. Do what you want. A few days later, we got to work. I had an excellent contractor from an MSP with me, and together we carefully unplugged and removed every last piece of equipment from the rack. We coiled up the cables, laid everything out neatly in an office, and patted ourselves on the back for a job well done. Fast forward to 9PM that evening. My phone rings. It's our general manager, and he is not happy. What the hell did you do? The landlord is blowing up my phone. Turns out, the warehouse next door was piggybacking off our server room for their antenna Internet connection. And they weren't just any business, they were running heavy machinery processing. When we pulled the plug, their entire operation ground to a halt. No network, no processing. By the time their IT team managed to Frankenstein it back together, they had racked up about $500,000 in losses. At this point, I was sweating bullets. I called my boss, fully expecting to be eviscerated, but he just sighed and said, don't worry. We'll figure it out. A couple of days later, during a smoke break, I overheard that the landlord's company decided to pay for the damages out of pocket. They just wanted to keep the peace and, as a cherry on top, they even gave us a little subsidy to cover the power requirements for the other company's server rack. So, in the end, everything was fine. But I did walk away with one very important lesson. Question everything you see, and definitely, definitely question everything you hear.
Speaker 4: I gotta say, if I'm in charge of the IT infrastructure for a heavy manufacturing facility that requires Internet to run.
Speaker 2: Uh-huh.
Speaker 4: Why would I not have an Internet redundancy plan? Uh-huh. Like, the like, the the world exists now where you for $50 a month, you can buy a cellular redundancy for your network. You can get a Starlink for a little bit more money. You can get dual lines. The fact that you're piggybacking a $500,000 a day, give or take, I'm assuming, in lost revenues, a facility that makes that much money off of a piggyback Internet connection that you borrowed from your neighbors is shocking.
Speaker 2: Yeah. There's that you don't have a redundancy. It's that you're running it off of a piggyback setup that's physically located in your neighbor and that the people at your neighbor don't seem to really know that. Because this all starts with the people there being like, yeah, we don't even know what that is. It's probably a subterfuge crypto setup. You should definitely spend a whole day unplugging and getting it out of here. It's like there's there's it's like a real Swiss cheese thing of just a problem falling through the holes one after the other after the other, except all of the holes are kind of dumb. Like
Speaker 4: Totally. The the thing for me that really like that that just seems insane. Like, if you if you're if you require Internet to operate, like, say they're running, I don't know, plasma cutters or something that needs Yeah.
Speaker 2: I wanna know what these machines are. But continue. Continue.
Speaker 4: If Internet is a requirement, you should have a redundancy backup plan to not draw like, for something that's, like, a $100 a month patch to save a $500,000 a day in revenue seems like whoever's in charge of your IT systems and or the chief information officer or whoever the the top person at the top of that pyramid is, just give them a bit of budget and let them do their job. Because Yeah. The fact that you guys didn't even have your own primary line that you were using, like, microwave connection to the building next to you is madness already, let alone not having multiple connections to ensure that if something does happen, your entire facility doesn't stop working.
Speaker 2: There's like a a thing people say, I'm not in IT. But with any, like, mission critical tech, like, if you're going filming the memory cards, if you're recording something, the cables and the mics and the computer is two is one and one is none. That's that's the sacred rule for that kind of
Speaker 4: stuff. Yeah. Yeah.
Speaker 2: You only have one of it, it's like you have none of them. And if you have two, that's kinda like you have one. So how many should you have? Probably three.
Speaker 4: Oh, I'm I'm the worst for that.
Speaker 2: When I think of an Internet connection for a machine that's like those plasma cutters chug through gigabytes every day or whatever this equipment was, that's a real two is one and one is none type situation. And I don't even mean like a a cheap backup. I want one of those, like, undersea cables that connects play like, it's just a fat fiber optic cable bolted into the side of the building with, like, an armed guard. And $500,000 a day, come on.
Speaker 4: I guess another shock to me on this one is is that the landlord agreed to pay for it. Like, they're they're essentially borrowing, like, they had previous permission, I would assume. Borrowing a previous entity's Internet, that previous entity left, and they somehow think that they still have access and rights to it. Like, they didn't start planning and fixing and build a redundancy and put in their own infrastructure after their neighbors who were the kind enough to lend them Internet left. Shocking. Shocking.
Speaker 2: Did you watch Breaking Bad?
Speaker 4: Yeah. Who didn't?
Speaker 2: Who didn't? Spoilers for, like, a decade old show. A a big part of that is them trying to find Breaking Bad for the unfamiliar is a show about a high school teacher who cooks meth. And at one point in the show, they're trying to find a place to do it and they end up in, like, the basement of I can't remember what it was. It wasn't a laundromat, but it was, like, the basement of an industrial setting.
Speaker 4: Yeah. I figured they made, like, soaps, like, industrial cleaners or something like that.
Speaker 2: Something like that. I just remember a big, like, piece of machinery. They got, like, tilted up, and then they went downstairs. Anyway, what I'm trying to say is I wonder if this actually is the crypto version of that, where it's like, yeah, we got industrial machines that need Internet in the back, and no one was like, what industrial machine? And it's just crypto farms. It's just like a weird underground crypto farm stealing energy from something else. Yeah. Breaking bits.
Speaker 4: Breaking bod, actually. What? Old term to refer to data transfer over networks. Okay.
Speaker 2: Okay.
Speaker 4: Deep dive. Welcome back to Hotline Hacked. We didn't do one of these for a long time. We did one recently. People loved it, so we're back to do another one. This is gonna be the first one that's on video. Welcome back.
Speaker 2: Welcome back to Hotline Hacked. Hotline Hacked is is brought to you as always by our title sponsor, NordLayer, the network security platform for modern teams. We're gonna tell you more about them later in the show. Thanks to NordLayer. If you wanna share your call, please do. You can submit audio via hotlinehack dot com, it just goes to an email. If you wanna be kinda old school about it, and we sure think it's cool when people do, you can call. There's a phone number on the website 802818869. Go check the website in case I read that wrong. We'd love to hear your calls, text, audio.
Speaker 4: You can also send us this text. We use AI voice to thing it, put any notes in email if you want us to obfuscate your voice, do anything like that. I think this next one up came in as a text entry, which we just cranked out with one of the AI voice agents and, you know, real easy to hide your identity.
Speaker 1: Hi, Hacked. Big fan of the show here. Love your work. This hack happened some time ago. I was attending a small college in the Midwest, and one day on a weekend, I wandered into the library. I was looking for a very specific book, the second book of the Mars trilogy by Kim Stanley Robinson, as I recall. And for reasons I can't remember, I had chosen a computer kiosk in the depths of the basement to conduct my search. I knew it was a long shot that the library would have this book. But when I had logged on to the kiosk with my school credentials and my search of all available databases proved fruitless, I was slightly irritated all the same. Right about then, a thought popped into my head. Might the city's public library have it? I reached up to the corner of the screen, but, of course, it was a kiosk. They weren't gonna give unrestricted browser access on a library search computer. And right then, almost by force of habit, my fingers flicked out and pressed the faithful keys. Control, shift, escape. If you're unfamiliar with Windows operating systems, this particular key sequence opens up task manager, a utility to view and kill any processes running on your computer. Way back when I was a kid, my dad had actually taught me this shortcut as a way to escape Minecraft when the program was not responding. Sure enough, task manager popped up. And right there, I could see all the processes running on the computer, including the apps that were maintaining the kiosk. Now I've been listening to your show since late high school when I first started getting into hacking. You've told enough stories about credential theft and the hazards of unrestricted network access that I knew exactly how bad this was. You see, the computer itself, a Windows 11 system, was connected to the campus network via generic credentials rather than a student ID. Malware attacking the network internally from this computer would be completely anonymous.
Speaker 4: He's right. I'm wondering where we're going here, though.
Speaker 2: It started out so simple. It was like I can terminate a a a process and clear I was like, we're just like, chill. No fuss. No muss. Let's just keep it simple. Now I'm like, okay. Where where are you digging?
Speaker 4: Now he's like, I got general network access, and I can Totally. Launch malware at this entire institution from this terminal kiosk. Let's go and see where he takes us.
Speaker 1: Moreover, the exploit I'd found gave internal network access to anyone who entered that library, not just students. And it gets worse. Remember that just earlier, I logged in? The library catalog itself had a basic search engine, But the library website also had a bunch of cool features that would integrate your library search engine into JSTOR and ILLiad, big repositories of scholarly work that required credentials. The school's tech department had solved this integration problem by having students themselves log in using their school credentials within the library kiosk. The same credentials that they use to access their school email, make tuition payments, the works. A keylogger on this machine would be really, really bad. I knew I had to report this to someone, but there wasn't really an obvious place. I knew a guy who did audio visual work for the tech department, so I reached out to him and asked the best place to report a cyber vulnerability. He told me to just email the help desk with the details, so I did. Well, I got an email back saying thank you very much, etcetera. And a few weeks later, I happened to be back in the library, and I tried it again. It still worked. So I followed up with the help desk, this time cc ing the person in charge of library technology. And this is what they said. Thanks for bringing this to our attention. After conferring with other staff, we have concluded that the user logged in to the library search workstations is not a user with admin privileges. Therefore, although task manager is available, and while tasks running as that user could indeed be terminated, the overall operating system should be, barring some unknown vulnerability, protected from a bad actor by Windows privilege separation measures. Please respond back if you have any questions. Well, you can imagine my response to that. I'm a pretty competent programmer, and I knew that I could bang together a decent key logger on my own just for the heck of it. Though, I decided to write the dumbest trojan that ever was.
Speaker 4: I love the spite hack.
Speaker 2: Yeah. There's like a you can hear knuckles kinda cracking in the ground. Well, it's like we you get the email back being like, hey, we reviewed this, for reasons a, b, and c. You're wrong. The overall OS OS should be okay. And it's like there's already clacking in the background. I'm like, yeah. I know. It's totally locked down and secure, as I'm sure we're about to hear in the last minute of this call.
Speaker 1: I copied some Python to log keys off of medium.com, and I got ChatGPT to write me a Python script to email a string to a hard coded Gmail address. I threw this all together, sloppiest Trojan you've ever seen in your life, just to prove my point. Then I compiled it into a binary, created a new, empty user profile on my PC, stuck the executable binary on a USB stick, and plugged it into my computer. No alarms. There's this directory on Windows where any executable placed in it gets run on startup. I clicked and dragged my little trojan in there and restarted the computer. Sure enough, as soon as I started typing, I started seeing my keystrokes appear in that Gmail account. I just proved that those privilege separation measures were just about useless. I reported this further back to the library tech guy, but he informed me that they'd already spoken to the tech department about the issue and that there was nothing further they could do.
Speaker 4: Oh, this is classic. This is cool. Yeah. Just it's like it's like the we're we're okay. Like, it's Windows 11. It's logged in with a non admin user. It's no big deal. And they don't see that, like, every student in the university logs in there with their private credentials and probably professors. Oh, yeah. And this person saw that and said Mhmm. It would be really easy for me to, like, bang together a a quick key logger that, like, mirrors all key inputs into, you know he sent it to Gmail. I probably would use something real time, like a messenger. But
Speaker 2: I just love the it's the it's like a tale of those. I'm thinking for your call. This is a good one.
Speaker 4: Yes. Thank you. Great call.
Speaker 2: I I love the, like, hey. Thank you for letting us know something is wrong, but no. It's not. And then you're like, I'm pretty sure something's wrong. And they're like, no. We asked the guy who knows if stuff is wrong and it's not wrong. And then you're like, I'm pretty sure it's wrong. In fact, I I I kind of exploited the thing that is wrong to prove that it's wrong and they're like as we've said before nothing is wrong and it's
Speaker 4: like well I guess this
Speaker 2: is just how these kind of things happen is a bunch of people very confidently say there's nothing wrong until someone that isn't just, like, trying to kind of, like, blue team like, trying to, like, prove that there's a problem here. It's like all it takes is someone who's not a a good actor to come along and really definitively prove it.
Speaker 4: Yeah. Exactly. That's that's the thing for me. It's like the I I would have the same output as he did. Like, I would see that as a massive vulnerability. The fact that I can get system level access just gives me access to do all kinds of stuff even if it's not in a privileged account, even if I can just walk the network, even if I could just, strip the credentials that allow me to walk the network from a, like, a ghost device that I set up. Like, there there would be a million ways to take something like that and turn it into a a serious security vulnerability. Let alone, like, no. It's not a big deal. Like, we we don't care if somebody hacks into the non administrator account on this computer. It's like, okay. Great.
Speaker 2: It's still a computer that people are plugging their credentials into, and those credentials lead to email inboxes and payment systems for the university and grades and, like, privileged private information. There should be, like, a big red button. Mhmm. So many of these calls we get are from, like, campuses and universities, and also it's really cool that you've been listening since high school.
Speaker 4: Yes.
Speaker 2: I'm a thousand year old man. It's but it's really, really like there should just be a big red button that you can just go and press and like boop it and be like, there's a big I. T. Problem. Like, all of these calls are just people trying to report I. T. Problems on their campus and everyone being like, no. Those key scanners work great. And then someone just, like, does it with a credit card or something. It's like we need we need a big, like, break in case of IT emergency protocol on on university campuses.
Speaker 4: So I'm, I think I might chase this with a little story of my own in this regard
Speaker 2: before we get to this one.
Speaker 4: I'll go to Holland Hack. What do let me set the picture. It was about three months ago. I get a LinkedIn message, recruiter out of New York. You know, I came up in a scouring of the Internet of people that they might be interested in working at a at a Frontier AI Lab. Sends me this message, says, hey. You know, if you have any interest, get back to me, blah blah blah. First thing I do, I grab the the the message. I throw it in Claude, and I'm just like, is this credible? And if it is, look at their client lists, and other job postings to figure out what Frontier Lab they might be talking about. Is it anthropic? Is it Open Is it x AI? What is it? So I just pipe it into Claude. I go away and cook lunch. I come back, and Claude has I I don't wanna say hacked their entire system because it didn't I guess, you you would call it a modern hack, but their Vibe coded recruitment system had left their Supabase, like, their database and authentication back end service Mhmm. Cloud service, had left a key for accessing their entire database in the source code. And Claude picked this key up and literally went into their back end, found the exact job that they were emailing me about, pulled the client file for it, and was like, oh, it is anthropic. This is the role. Here's the things. Here's the comp of values. Like, it gave me all of the details, and I was like, woah. Like like,
Speaker 2: I just asked you to do a little bit of work. Make a sandwich. Yeah. What did you do?
Speaker 4: Yeah. I asked you to do a little soft research and, like, see if they had any other Frontier Labs in their job postings and their active postings. And instead, you found your way into the back end of their system, and then it started telling me it's like, well, I'm looking at the applicant's table, but I probably shouldn't share it because it has a lot of, like, personal protected information in it. And I was like, yeah. Don't share that with
Speaker 2: me. Yeah. Don't share that with me.
Speaker 4: I literally screenshotted it and just sent it back to the guy who owned the recruiting company who'd messaged me, never heard back. So if if you're listening to this and you're that person but yeah.
Speaker 2: Fix that shit up. Woah.
Speaker 4: That shit up. So so an inadvertent hack.
Speaker 2: Yeah. It's kinda interesting to be sending a it's like, what does it mean to send an email to a person that will probably have an agentic system review your email and climb up the ladder of vulner vulnerabilities that may or may not exist. Totally. So be really careful sending that email.
Speaker 4: Well, the other thing too, like, I didn't dig into it because I was like, I don't need to get into this. This guy
Speaker 2: was Your hands are literally Yeah.
Speaker 4: My hands are like this. I
Speaker 2: just thought I I didn't I didn't do I I don't know anything about hugging face. I I had nothing to do with it.
Speaker 4: This was not the intention, but I was, like, fired in the message. And I was thinking to myself, I was like, you know what? I like, the fact that I haven't heard back is bad because it probably means that they haven't fixed it because anybody in their right mind would be like, oh my god. Like, especially because it came from the CEO, and, like, we had had a few messages back and forth. So it's like, if the first thing I would have done when I saw that is, like, freaked out, told my IT team and had it sealed up immediately because I could probably go into the applicant's table, bump myself up to a priority, whatever, a applicant, push me to the top of the recommended list. Like, I could do all kinds of stuff. I could delete other people that were applying for the job. Like, it had full back end control of their recruitment platform. And I'm just like, I don't understand how you get here in today's world. Like, if if Claude and we're not talking like Claude code, look at the source code for vulnerabilities here. Yeah. I'm talking about doing like a like a red team exercise. I just simply asked Claude to figure out who the who the front which frontier lab it might be. And it literally, like, took control of the entire back end of their company. And that was just, like, $19 a month Claude.
Speaker 2: You gave it one of those, like, monkey paw. Like, well, technically, there's some ambiguity in your question of what you've asked. You didn't say how to do it. So what I'm gonna do is and then, like, the the CEO's, like, smart home fridge doors being thrown open or something. Like, a a smart vac is cooking across the floor in another building.
Speaker 4: Totally.
Speaker 2: There is something funny about people that If you had done that and bumped yourself up the queue, there's something funny about, like, oh, how'd you get this job? And it's like, well, funny story. Yeah.
Speaker 4: The, I do have one more knock on to this because kiosks are always a boatload of fun, for people that think in a cybersecure way because none of them are ever secured. Traveling. Jordan, you travel. I travel. I traveled in a neighborhood where there was, like, Internet cafes that you didn't have cell phones on you full time. Like, you had to go use computers. There were, you know, backpacker hostels would have, like, a computer that had, like, you know, a fixed Internet connection, but it wouldn't let you off of anything other than, like, their hostel network's booking page or something like that.
Speaker 5: Sure.
Speaker 4: And I used to just rip through these computers because often they would have some form of search functionality, and you would just feed it a search for essentially a local file system file like explorer. Exe. It will return you, like, we couldn't find anything, but it would turn it into a hotlink. Or if it couldn't, you would just go in and inspect it and then turn it into a hotlink. And then when you could click on it, it would literally, like, launch file colon slash slash, you know, c windows, explorer dot e x
Speaker 2: e, and
Speaker 4: it would just open explorer, which gave you full computer control. So even if they had task manager locked down, you could, like, bypass it that way and then open up your own instance of Internet Explorer or, like, do whatever you wanted really at that point. And it just kind of kiosks are kiosks are just maybe one of the most security vulnerable things ever because I don't think anybody thinks about security when they set them up. They think about, like, the idea of security, but they're never secure.
Speaker 2: It's like it's not security. It's like a it's not a door. It's like, you know, like the gate arm that goes up and down to stop a car from driving through?
Speaker 4: Yeah. Yeah. The rubber one.
Speaker 2: It's like the yeah. The rubber one that goes up and down and you're like, I could go around that or under that or over that. It's only because I'm in a car, and I don't wanna just drive right through it that it is it is only in that way that it is gesturing towards security.
Speaker 4: It's a polite request.
Speaker 2: It's a polite request. It's like, please please don't drive through me. And it's like, that's what those systems kind of are, I think, for people. It's also fun. I'm assuming you were doing it quite casually, but you can imagine someone having that moment in a backpacker hostel in the two thousands or twenty tens kinda hacking into the thing and meanwhile there's the, like, hungover Australian manning the, like, front booth being like, Canadians hacking the computer again and I simply couldn't give a shit.
Speaker 4: That is precisely correct.
Speaker 6: Hey, guys. So I got a hack story for you, I guess. Wouldn't really call it hacking. The program VLC, obviously, used to connect to other people's computers. Typically, with their permission, as long as you have the password and the IP address, you should be able to connect and log in. So I, helped my girlfriend at times with her computer, and I wasn't living in the same city. And, I just installed VLC. It was a Friday, and I was on my way to go visit for the weekend. So before I left, I wrote a little note on her computer so that when she got home from school and opened up her computer, she would know that I was on my way. And, I don't know. I didn't think there'd be a big deal, really, so, I wrote the note and then made my commute, which is about two or three hours. In that time, I guess she got home and saw this note and was pretty panicked. Both her and her roommate, had a guy living down the street in a house who is, I guess, a little bit creepy at times, and so they thought maybe this guy broke into their window in the bedroom, got onto the computer, and left this note behind. What the note said was, this is your friendly neighborhood Spider Man. I'm watching you, and I'll see you soon. Something like that, anyways. So, maybe I even said x o. I can't remember. But, they ended up calling the police and made a report, axi accusations that, I guess, this guy probably broke in, so maybe they please talk to this guy as well. And then I arrived after this point, I guess, maybe an hour later or so. I I show up and, start hearing about all this news of, you know, commotion. Someone broke into the computer and left a note, and I was like, oh my god. What are you talking about? So, yeah, I almost got, criminal charges. The police didn't charge, you know, once they found out the the real situation, but they were tempted to press some type of charges against me. So, lesson learned. Even if you had access on VLC, you may not want to leave a note from Spider Man.
Speaker 4: I think he might mistaken VLCs, like, a media player. I think he's talking about VNC, which is, kind of a remote access system. So I think just just a small clarification, but I think that's it. The
Speaker 2: I was so that whole time, like, partway through when he was like anyway, I was leaving and I had access to my girlfriend's computer. I'm like, is this a good call or a bad call? Like, I was really worried this was going into, like I accidentally invented stalkerware direction. And to your credit card, that is not at all what was going on. This was a very human, normal, reasonable error, except for maybe the phrasing of your note. If I could give polite feedback.
Speaker 4: He's just
Speaker 2: trying to be cute.
Speaker 4: I'll be cute. Be cute.
Speaker 2: In the night when you don't know I'm there. He's he's trying to be cute. He's being cute. He was being cute. And Spider man maybe was like a cute I'm guessing it wasn't a cute nod, but I totally get it. I was tense this whole time because that's the kind of thing I would do and it inadvertently scares someone. Where you just you're not even thinking of it. Like I really relate to you on that one caller. I'm like, oh, I could totally see accidentally leaving something very cryptic.
Speaker 4: Jordan's very cute, so I can see him doing this.
Speaker 2: I'm adorable. What can I say? I wanna know what the cops would have charged you with because it's like, what did you do wrong? Like Yeah. There was confusion, but you didn't and you didn't frame the neighbor. You weren't like x o x o your creepy neighbor. Like, there was no none of that going on. No.
Speaker 4: Yeah. I don't know what they would have charged him with. Like, because he if he had access and permission to have access Yeah. That's not Totally. Legal. Like, they would charge it like, I guess it all comes from the hysteria of the random note, which I guess when you're trying to be cute and it comes across well, I guess, it probably all spawns from an anxiety about this unknown entity that lives down the road that they don't like.
Speaker 2: Yeah.
Speaker 4: Because I'm sure if they didn't have that in the back of their mind, they wouldn't have compounded so quickly and turned into, like, a phone to the police being like, oh my god. We're being stalked.
Speaker 2: Totally. And, like, to her credit, it was like, that would be stressful. If you were having a thing with, like, this, like, weird dude down the road and the vibe is bad, like, empathy for that, that would suck. And then you get this note and you don't immediately connect. You're gonna wanna really put like a cute pet name or like an inside joke or something like that in that note to clarify, but in the absence of that, they just sort of like put two and two together and go, oh my gosh. Oh, no. He's in the house. What are we gonna do? Call the cops. Crazy call. Interesting call. Thank you for sharing it with us. Anything else, Scott? Should we jump into the next one?
Speaker 4: I think maybe we take
Speaker 2: a little break. A little water slide. We're gonna rip down the the water slide. It's gonna have twists and turns. It's a little lads, and we're gonna change clothes.
Speaker 4: If we can choose clothes.
Speaker 2: And when we come back, some more calls. This episode is brought to you by our title sponsor Nord lair. The reality of running a modern team, your people are working from different devices, different locations, different networks, and most businesses have no real visibility into what that looks like from a security standpoint.
Speaker 4: NordLayer is a network security platform that fixes that. It gives you centralized control over who can access your company's systems, lets you grant revoke access in seconds, keeps everything connected fast and encrypted, and does all of that without any additional hardware or complex infrastructure.
Speaker 2: You can verify users by identity and device. You can block malicious sites and risky domains, and you can stay compliant without slowing anyone down.
Speaker 4: It's built for the way the teams actually work now. So check it out at nordlayer.com/hackedpodcast.
Speaker 2: That's nordlayer.com/hackedpodcast. Thanks again to Nord layer for their support.
Speaker 5: Hi, Jordan and Scott. My name is Vincent, and, I'm by no means a hacker, but let me tell you about the time when my dad, of all people, nerds nagged me into doing some harmless hacking. My dad would play Counter Strike all the time. This is early two thousands. And at the time, Counter Strike was not even its own game yet. It was a mod of Half Life. My dad would host his own games, and he would partly fill the room with bots until people would join in. This way, the room would not look empty. Bots were not common at the time, so you had to use a separate mod to run Counter Strike bots. Each time a player would join the game, the mod would send a message saying that bots in this room are from name of programmer. And this message was bothering my dad because, first, it would immediately tip-off players that there were bots in the room, and second, it was displaying somebody else's name, not his. At the time, I was still at university. I was doing computer engineering. So my dad asked me, can you change that string of text displayed when people join the game? What good is it to go to uni in computer engineering if you can't even change a string of text? And there you have it. I've been nerds knifed. While the moral of it bothered me, I thought it would be a quick and easy job, just tweak the string by editing the DLL directly. So I located the DLL, used by the mod for the bots, and I opened it in a hex editor. There, I could see all the compiled machine code, but also all the strings of text used by the mod. I thought a simple search should do it. Right? So I search for the welcome string, and I don't find it. I skimmed through the DLL contents trying to find blocks of text, and I finally find something. The author of the mod had intentionally intentionally left a string in the DLL for people like me messing around with it. It was some profanity. Basically, nice try, you jerk. That's when I thought, challenge accepted. My first thought was that guy has probably encrypted the welcome string with some basic encryption scheme. I bet it is a simple substitution cipher where each letter is always replaced by the same one. Since I know the string I'm looking for, it makes it way easier to break. For example, if I search for the word welcome, there are two e's in there at positions one and six. So I should be looking for a sequence of bytes where those at positions one and six are equal.
Speaker 4: You can always tell a real programmer by the fact that they consider the first letter zero because, like, array indexes begin at zero. So when he says positions one and six, he knows that the w is zero. It's just just a just a small thing. Like, we if you talk to somebody that's an engineer, you can pick that up right away.
Speaker 2: When you start counting from zero in a, like,
Speaker 4: a character string, that's good. Exactly.
Speaker 5: Imagine now that I have a full sentence. There will be many, many more repeated letters and so many, many more constraints on possible sequences of bytes that could represent the welcome string. I then proceed to write a c plus plus program that would sift through the DLL machine code looking for a sequence of of bytes that would satisfy all those constraints. I run the program, and there are only three spots in the DLL that could match. Very promising. I then change one byte randomly in the first spot and launch the game. Nothing happens. I try again with the second spot. The game crashes. Okay. Finally, I tried the third spot, and one letter of the welcome string has changed. Success. So it was a substitution cipher after all. I then manually associate each encrypted letter with the corresponding decrypted letter, which allows me to change the message to whatever I want as long as the string stays the same, the same length, because it cannot shift things around and compile code. And there you have it. My dad was happy. I felt good to have solved the puzzle, but also kinda bad, especially when I saw my dad lie about being the creator of the button, the new welcome message. Oh, well. So that was my harmless hacking story. Love the show, and, greetings from Montreal.
Speaker 4: That's, that's hilarious. Greetings from the West Coast.
Speaker 2: Greetings from from Western Canada, my our fellow Canadian. Thank you for calling. That was a good one. I like that. That's a that's a good story. Mostly, I I wanna talk about the tech of this because I I think, Scott, you were probably following it a little more closely than I was.
Speaker 4: Sure was. Yeah.
Speaker 2: I I got the simple substitution cipher side of things, but I just I I it makes me happy anytime I hear someone say nerd sniping. I think that's such a great phrase. Like, I think I I know a lot of people where it's just like, if we just dangle this really interesting technical challenge in front of you, like, you're you did knuckles crack, you're off. And it's like both, it's a it's a useful thing and a, like, liability where it's like, we're gonna lose them for forty five minutes. This is an hour.
Speaker 4: Forty five hours.
Speaker 2: Forty five hours. Hours if it's a hard enough challenge. So I like that. Thank you for putting that back into my my brain.
Speaker 4: The couple things here for me. Well, I know you wanna dig into the tech, but I just wanna talk about how great Counter Strike was.
Speaker 2: Sure.
Speaker 4: Great game. When it launched the mod, we used to play it all the time in, multiplayer, had our own servers. I never really played competitively, but considered it. Killed all of meister a few times in ranked matches. And if you know anything, you know that.
Speaker 2: If you know, you know. Well, we're yeah. I don't know. So what's that? What what is that?
Speaker 4: All of meister was, like, one of the top CS pros in the world. Oh. I felt we found ourselves in a rank game once. And, the first I just was like, is that the real Olafmeister? And somebody was like, yes. And I was like and then I just killed him, and I saw in the kill feed that I'd killed him, and I was like, screenshot. And then I'd like the next round came out, killed him again, screenshot, and I was like and then he left the server. And I was like, that's insane. Like, I, yeah. Anyway, that's my camera straight tail for the day.
Speaker 2: Get that printed.
Speaker 4: Put that wall. Get that framed put next to the the Guinness World Record.
Speaker 2: Guinness World Record. So I was gonna say you put it next to the you can't put it on the bathroom wall if you're like me. Half the night. Exactly. That's awesome.
Speaker 4: Text sign. Dig in.
Speaker 2: Text sign. I just wanna understand, like, what what exactly the other so this whoever had made this bot mod for Counter Strike had set it up so that whoever deployed it, their name was associated with it and the little message popped up for everyone. Apparently the name thing wasn't quite even working but basic idea was there was a little alert to everyone who joined and the caller's dad didn't want that alert to come through. So they nerd snipe their own son. Cool. Into helping them out. Love it. And what is the, like, what is the tech of what he did here in order to get into it? It's like there was a little bit of security, but it was seemed like it was really simple encryption.
Speaker 4: Yeah. Well, it's so let's back it up. So the sounds like the bot came as a precompiled DLL, which means that you don't have source code. It's been generated. It's been compiled. It's put into binary. So, essentially, you get a compiled executable. A DLL is like a library that can be, like, side loaded into a Windows application that essentially is precompiled for speed, performance, etcetera. It's not interpreted like a Python script or something like that. It's been it's been compiled. You can open up compiled things. So, like, to jump back to the Mico interview, Mico and I both have, like, similar origin stories because one of the first things that got me into computing was, like, bypassing security keys and product activations and software. Like, you download a video game off the Internet and you did either a key gen. And if there wasn't a key available, what you would do is you would open up the software in a hex editor, which would allow you to essentially look for, any kind of strings, stay strings inside of the compiled code. So you would find the place where it asks for the product key, and then you would kinda source out where the authorization occurs. So there's usually a challenge. So when you hit, like, activate, it calls a function, which then returns true if it is activated or false if it doesn't. And essentially, you find that instruction that says jump to this to either, like, jump never, so it auto approves or, like, you can
Speaker 2: do
Speaker 4: small changes
Speaker 2: You can reroute it there towards the yeah. This guy bought the software outcome.
Speaker 4: So this guy did the same thing. So they opened up the DLL, and he looked for the string, couldn't find it, and was shot by it. So then he he was smart, but he did find the, like, you know, go f yourself string. So so he knew that the the person probably knew that somebody was gonna do this, and what they did was apply some form of cheap encryption, which isn't really encryption, like a substitution cipher. Yeah. Like, Roth 13 is the biggest one. Right? Like, in the in the, in our our alphabet, there's 26 letters. So if you just take one and jump at 13 places, you kind of can encrypt things in a very easily unencrypted way. That's probably what this person did. They might not use raw 13, but they use some other form of, substitution cipher. So they took the welcome message and applied some cheap substitution for it. The hardest thing that this person did was write a piece of C plus plus code that goes through the binary to look for any of the spots inside of the binary that the string could exist, probably just based on string length, number of characters, etcetera, etcetera. And then, yeah. So then once he found the right string and the the fact that there was three places, I wonder if two of the strings were the same because what they might have done was written an authorization or, like, a test, like, make sure that this string is this string. So they have it in there twice and, like, a bit of a back end. So that when it when it crashed on them the once, it could have been failing some internal check. Because if he went to the if he went to the limits of applying a substitution cipher, writing a PFO message inside of the code, there's a good chance that he then also doubled down and wrote, like, a a check to make sure that that string never gets checked changed.
Speaker 2: Yeah. Right.
Speaker 4: So you would have to change it in two places. So that's that that would be my guess. So I don't know if you understood that, if you have any Yeah. If you didn't No.
Speaker 2: I we got the bones of it. It's interesting. Yeah. And so also his dad could I wonder if he removed the message or if he changed it to something.
Speaker 4: Yeah. Sounds like he changed it to his dad's name, which is I like like what? Yeah. I like that. It's called copyright infringement.
Speaker 2: Yeah. Fuck it. Why not? It's a botnet counter strike lobby. The stakes couldn't be lower. Totally. It's very it's the it's the are you winning son meme. You know which one I'm talking about? Like, with the dad saying that are the meme. But it's, like, it's kinda flipped a little bit. I mean, like, am I winning? And there's, like, hackers on being, like, moment momentarily.
Speaker 4: Yeah. Give me one moment. I'll make you win.
Speaker 2: Give me a sec. That was good. Violent threats against executives are growing at an alarming rate. When a company experiences backlash, executives are the first people blamed when their address and other personal details are sitting online. This backlash can lead right to their front door. The team at Iron Wall knows this better than anyone. They protected some of the most targeted executives and individuals on the planet for almost two decades. As a white glove enterprise security service, they protect your people with continuous personal data removal, proactive prevention tools, and human led emergency support. So when someone goes looking for your executives, Iron Wall ensures they hit a dead end. Here's what to do. Go to ironwall.com/hacked. Fill in the quick form and request your free risk assessment. Their team will show you just how exposed your executives are and how to lock it down before a threat reaches their front door. That's ironwall.com/hacked. Learn how to stop online threats before they become real world attacks. Links in the show notes.
Speaker 4: Teams using Notion move faster, cut friction and costs by consolidating tools and staying aligned. In Notion, your docs, meetings, projects, and more all live in one connected database system where AI has the context it needs to help you do your best work. It's seamlessly integrated, infinitely flexible, and beautifully easy to use.
Speaker 2: Because everything lives together, Notion has the context it needs to answer questions instantly, automate busy work, and keep work moving. It's AI designed to strengthen teamwork, not replace it. With over 100,000,000 users, Notion is trusted by 98% of the Forbes Cloud 195% of the top 50 AI companies, including OpenAI, Cursor, Lovable, and more.
Speaker 4: Learn more about how Notion can support your business at notion.com/hacked. That's all lowercase. Notion.com/hacked. Try Notion today, and when you use our link, you're supporting the show.
Speaker 7: Hey, guys. My name's Robbie. I live in Australia. Absolutely love the pod and especially the hotline hacked episodes. I get so much excitement when a new episode drops and saddened when I've completed listening to each as I sit feverishly refreshing my podcast app awaiting the next episode.
Speaker 4: That's far too kind.
Speaker 2: That's really sweet. Thank you.
Speaker 4: It is, though. Yeah.
Speaker 2: That means a lot to us.
Speaker 7: Anyway, been wanting to call into your hotline hacked for a while now. Finally got the time to do it. I don't really need to obfuscate my voice, but thought I would have a play with AI voices anyway. I've always been interested in everything tech since I was a kid, always messing around with computers and seeing what other things they could do other than the conventional word processing and Internet browsing. I'd also always have a side hustle growing up, whether it be building and selling PCs, a bit of web design in the mid nineties with horrendous GIFs and crazy colors, or creating and selling polyphonic ringtones and operator logos for Nokias at school. And it was a side hustle that I thought would be a good story to send through to you guys at hacked. Having grown up alongside technology, I was also very much into the games consoles that were released throughout the eighties, nineties, and early two thousands. As with all tech, I wanted to see what else they were capable of, so I learned how to hack or chip almost every console I've ever owned. I remember spending my electronics classes at secondary school, equivalent to high school in The US, soldering chips for the p s one and then installing them as another side hustle. Anyway, fast forward to the late two thousands where I had been traveling around Southeast Asia and Australia for the best part of a year after finishing uni. I liked Australia so much that I wanted to live there, so I was working back in The UK to get the money together to head back over on a more permanent basis. At the same time, I had acquired and was playing my way through various games on a Sony PSP. In true Robbie style, I was intrigued as to how difficult it would be to hack the PSP and what it was capable of. Unfortunately, there wasn't a great deal of info online at the time and certainly not a complete guide. So using what I could find, I managed to stumble my way through. Firstly, having to identify the model of PSP I had, as well as the firmware it was running and which motherboard was inside it before downgrading the firmware and then successfully hacking it. Once hacked, it could boot into any firmware version of my choice and run homebrew software. It could also play copies of games from the memory card that were, of course, backups of games I owned. Once I had worked my way through this, I thought I would be a good Samaritan and document the whole process so others could do the same. So I wrote a pretty comprehensive guide on how to identify your PSP's firmware and motherboard model, and then how to downgrade the firmware and install dev hook. I called it an ebook and put it on sale for £5 on eBay. It kept getting pulled down by eBay for breaching their t's and c's, but I kept putting it back up. I sold enough copies to pay for my first visa to Australia, which I have since turned into Australian citizenship. I've now got a lovely Aussie wife and two little vegemites, which I suppose in a roundabout way is thanks to hacking. PS, I have attached receipts.
Speaker 4: So can confirm. He did attach the entire guide that to how to attack or hack your PSP. So that is here. I am looking at it right now.
Speaker 2: We we've gotten a lot of great calls, and this isn't to malign any of them, like, truly. That just on, like, an emotional level, that one that one might be one of my faves because it hits this trifecta of like, it's a cute, sweet, nostalgic story at the end. And then, honestly, like, hacking these types of game consoles, to hear someone use chipped as an adjective, like, warmed my heart. I haven't heard that in a minute. I remember that. I remember the friend that had the chipped Xbox where you could go buy, like, archive data disks of, like, just a bunch of ROMs. Or, like, I had a buddy that had a PS two that was chipped, and he had a hard drive with a bunch of, backups of games on it. I miss that era. I I get why it's moved on, but that's pretty cool. And that you were doing that on a PSP while backpacking around Asia trying to save up money, and you cooked this up is very, very good.
Speaker 4: The I had a chip PS one.
Speaker 2: Did you?
Speaker 4: Yeah. Nice. Had to go to a grocery store Yeah. To get it chipped.
Speaker 2: The the I won't say the name of it.
Speaker 4: Is it
Speaker 2: like a central a central a city center kind of grocery store?
Speaker 4: I think we were thinking
Speaker 2: of the same heck. Yeah.
Speaker 4: It'd be good to go to the service desk, get your p s one shipped. Yeah. I think I know
Speaker 2: what you're talking about.
Speaker 4: Yeah. I'm sure you do. The I I love the story from a different thing because
Speaker 2: Okay.
Speaker 4: I feel like this is an origin story for an entire industry now. Like, if we look at Yeah. Anbernic and Retroroids and all these new
Speaker 2: consoles. Emulators.
Speaker 4: Yeah. But they they all now have new operating systems. Like, you can buy one of these devices. And if you don't like the OS that it comes
Speaker 2: default with You can
Speaker 4: Like, AmberNyx are famous for, like, you'll buy one, and they kinda come with this OS that's kinda good, but it's like there's much better ones. So, like, one of the ways on it. Yeah. Exactly. Onion. Totally. So so it you were the you were the entry point for what is now, I would say, like, a social norm in people that use these retro game emulators.
Speaker 2: So that's really
Speaker 4: cool. Is the coolest part about it.
Speaker 2: I like that a lot.
Speaker 4: As a fellow Australian, which I am, citizen, welcome to Australia. I don't live there. I would love to. It's beautiful. Love to come and visit family there. Might be coming there in the next twelve months. So if I'm in town, if you play golf, we should go get a round in. But, but, yeah, welcome to Australia as a as an Australian that doesn't live there.
Speaker 2: Welcome to Australia from the West Side Of Canada.
Speaker 4: Canada. Exactly.
Speaker 2: Your your constellation of interest is great. You got shift consoles. You got polyphonic ringtones. I've been, like, working on a polyphony has been a project part of a project we're working on. So, like, my my ears lit up when you were talking about that. That's a lot. That's very, very fun. And it also reminded me of like, this was such an underground weird thing to have to do. It's the same point that you already made, Scott, of like, you have to go to the, like, kinda janky grocer, let's liberally call it that with it. Well, they'll, like, they'll, like, yeah. We'll take your PSP and you get it back and who knows, to, like, buying a PDF on eBay that was sold as an ebook all the way through to like there's just companies that make this product now and retro emulation is not only common but like an increasingly important thing I would say in gaming.
Speaker 3: Like it is Preservation?
Speaker 2: It's the preservation. Like it's Totally. There's this event horizon past which the big game companies won't typically pursue people for copyright infringement. And everything on the other side of that line, the way you play these games is either on a computer, which is fine, but or through these, physical emulators. Like I'm really excited about that as like a product category. I think it's really cool because it's archiving games. Like it's important for a medium to have longevity. So it's going bigger than this, but I'm like, I'm I'm staunchly in favor. I think it's pretty cool.
Speaker 4: I I'm I'm here for that chat because there there is such a now that everything is going digital first, you essentially don't own it. They have the right to revoke license in real time. Archivism of, you know, our childhoods has become a real thing. Yeah. Like, the the physical cartridge based, video game consoles, much easier to archive. But now that we're going to a world where literally, like, the PS five is probably gonna be one of the last well, actually, that's not true. Didn't PS six said they were gonna do no?
Speaker 2: I think it was Sony that announced that the PS six was gonna be digital only, and now everyone's looking to see what Microsoft does in response. They already sell a digital only console and digital only consoles are very popular. It's it there's nuance to this like a Steam box flew off the shelf. It's digital only, but it's it's taking something away from people that they already had. It it hits a different emotional register.
Speaker 4: We're seeing like, this is the the throwback mentality. Like, the I've got another friend that collects DVDs like crazy.
Speaker 2: Sure.
Speaker 4: And and not only because they want to physically own the video asset, but they are a license to it. I guess it'd be a better way to put it. But Yeah. But the quality difference. Like, people have kind of forgotten what things that aren't streamed and hyper compressed in one gigabyte an hour look like?
Speaker 2: A Blu ray through an HDMI cable to a really good television is like, there's a there is a quality. It's good. It looks good. Like, it's visible. Even if you're not a big, like, pixel peeping person, you can tell.
Speaker 4: Yeah. Yeah. I hear I hear there's, like, scenes in Star Wars and stuff where if you watch it Blu ray on, like, an 85, 90 inch four k up res, you can kinda see the styrofoam jank of the set construction and and things like that. Like, if you watch it in that level of quality, but we just we've just kind of sold to the streaming life.
Speaker 2: Interesting. Well, I think those devices are cool, and it's very cool that your story positions you kind of at the at the start of that whole thing. And that you've you've got this document that you published out into the world, and it it's like, I don't know, there's this, like, tick in the history timeline of those devices, and you're like, that's my little tick. And then it then led to you your personal story of like and not for nothing but it paid for a visa that led to a citizenship and now I'm married and have the two little veg in my head I was like that's just really that's cool it's a good good good call
Speaker 4: I love the I love the the fact that you might be the origin story for the entire, like, mobile operating system open source community, which is phenomenal.
Speaker 2: When we make the Hackboy, the hacked official retro game emulator, we'll we'll give you a shout out in the in the OS or something.
Speaker 4: Totally. An Easter egg.
Speaker 2: Yeah. A little Easter egg. That was good fun. That was a fun batch of calls. Thank you to everyone that submitted. Please share your strange tale of technology. True hack computer confession. You can go to hotlinehacked.com. We got an email, we got a phone line. We, you could submit it as text. Tell us if you want it anonymized. We're here to make sure that you feel comfortable submitting your story, but we're gonna do more of these types of episodes. We really get a kick out of it. So please submit your story. Hacked as always is brought to you by our title sponsor, NordLayer. They are the network security platform for modern teams. Big thanks to Nord for sponsoring the show.
Speaker 4: Yeah. Check them out at nordler.com/hackpodcast.
Speaker 2: Means a lot, everybody. Excited for another one of these in the future. We'll catch you in the next one. Take care.