episode.ascii — live render
● episode

Hotline Hacked Vol. 3

TL;DRTwo hacking tales: high schoolers hacked their school network and played Alice Cooper on the website as a senior prank; a pen tester accidentally crippled a multinational's European network via ARP spoofing on oversized Cisco switches.

It's our third call in episode and we're cooking now. Share your strange tale of technology, true hack, or computer confession at hotlinehacked.com. We discuss accidentally causing internet outages, creating a botnet pandoras box, and the proud tradition of hacking into stuff to play great songs the man does't want you to.

Transcript

Machine-generated transcript; may contain errors.

Speaker 1: Thank you for calling Hotline Hacked. Share your strange tale of technology, true hack, or computer confession. After the

Speaker 2: Alright. I got one for you guys. When I was in high school, I went through, like, a computer phase, I would say, with, a friend of mine. We were kind of the computer nerds, for our class. And, naturally, we gravitated to the, print shop and who was also our sysadmin for the school and befriended him. And, he inadvertently challenged us saying that we could not break into our school's network, which you should not do with high school boys. So, my friend and I were able to successfully compromise the network. I'm not gonna go into details for obvious reasons, but, fortunately, we're both good kids, and it didn't change grades or anything like that. But for our senior prank, it did modify our school website, to reflect, our year in school as well as play schools out for summer, by Alice Cooper. As soon as you loaded the page, which is exceedingly irritating, then, we ended up getting caught, but not for the reasons that you think. There was no technical reason why we were caught because we're very careful. We were the likely suspects. So the sysadmin approached my friend who ratted me out, and we served two days of in school suspension. Fortunately, we had no ad history of doing anything malicious. We were both honor students and, didn't have any they didn't have any reason to really throw the book at us, fortunately. But in the meeting with the superintendent, the sysadmin, and our high school principal, we were given the analogy that it was like breaking and entering into someone's home and messing up their closet. So hopefully you enjoyed that story. Take care.

Speaker 3: Schools out.

Speaker 4: Schools out for summer. Hey, everybody. Welcome to hotline hacked. It's a calling show where you can share your strange tale of technology, true hacker computer confession. So many things to it's just so many things with this one. The print shop was the sysadmin is a great way into any story. It's just I wanna I want the life story of this guy because he sounds rad.

Speaker 3: He's like, I work on the technical things, the printing and the computers.

Speaker 4: And also hammers. Hammers. It's great. Yeah. I mean, don't inadvertently challenge, I think was the phrase. Don't inadvertently challenge high school boys to do anything because they have a lot to prove and a lot of time on their hands. It's it's never a good move.

Speaker 3: This is I I I it's foolish to me. Like, the you're gonna challenge, like, the nerds to whether they can do something.

Speaker 5: They're gonna figure

Speaker 3: out how to do it. I'm sorry. It's like this is something you just don't like, you how do you even get mad at these kids? Like, you're the one that you're the one that spurred them on. You're like, I dare you to do it. It's like you're the sysadmin. You just dared me to violate your security. I'll violate your security if you really want me to.

Speaker 4: I feel like when this happened, everyone turned to each other and was like, who could this have been? And that dude knew immediately.

Speaker 3: Oh, immediately.

Speaker 4: Well, I did pose a challenge to some nerds with gumption, that they couldn't do the exact thing that just happened. Do we think maybe it was them? Also, a real no honor among thieves thing with the friend immediately ratting him out.

Speaker 3: Hey, man. You know? It's if if I've seen enough Hollywood movies about nerds in my life, it is that they crack under pressure. It's out. Crack under pressure.

Speaker 4: I I won't go into the details, but I had a really similar situation. High school wasn't nearly as cool as this, but it did involve being somewhere we weren't supposed to. And the way it all shook out, no no word of a lie. Someone cracked under pressure and ratted everybody out.

Speaker 5: Yeah.

Speaker 4: We got pulled into the into the the school cop office and everyone was tight lipped except one person. And it, it all fell apart.

Speaker 3: My, my in laws are, both, principals. And apparently my mother-in-law was exceptional at getting children to crack. She's like, yeah.

Speaker 4: What a thing to know about yourself.

Speaker 3: Exactly. She she knew, like, the right buttons to push and, like, when to leave them to stew and, like, let their internal emotions, like, take over. And it just, like, always led to, like, she would reenter the office, and they'd be like, I did it.

Speaker 4: She's like, I know.

Speaker 3: I know.

Speaker 4: Still standing in the doorway.

Speaker 3: Exactly. Like, we all

Speaker 4: Casting a long shadow into the room.

Speaker 3: Yeah. We've known since we've known since this morning, of course. But the

Speaker 4: walks out and someone else is like, how did you know? She's like, we had no idea. I just knew that kid. He was sweating bullets the moment we brought them in.

Speaker 3: I think, I think I would have a story similar to this from my youth, which I you know, maybe. Maybe. I have a story similar like this. But the, yeah, a lot of lot of security in school networks, not so great. Even in school divisions and even in provincial school networks, used to not be so good. A lot of, when you have that many staff, a lot of them are technical. You know, security protocols can be pretty lenient. So

Speaker 4: For sure. It's, it's nice that they I like breaking and entering someone's home and just messing with the closet. I think that's, I'm glad that they just messed with the closet and played a song. I, this just brings up the fact that there's such a proud history of hacking and breaking into stuff just to play bops, just to s just to do a sick needle drop that the man doesn't want you to. I feel like there's so many great hack stories that were just about playing a song over the radio or the Internet or a website or an intercom. I remember there were I remember there was one a couple years ago where, the rapper it was a song by YG and I think Nipsey Hussle called FDT is a political song. And it was a South Carolina radio station that there was like twenty minutes just looping this song on repeat. Sunny one hundred and seven point nine and someone, like, hacked into it because it had a Internet connected, antenna. The antenna had an Internet intermediary where you sent the audio to it through this web system and then it broadcast over the air. They got in the middle of that and were able to just write a song on the loop.

Speaker 3: Brilliant.

Speaker 4: And then the other one that I remembered, and I I I dug it up, was it was a British radio station, and they, there's a song band in 1978 in Britain called the Winker's song by Yvor Biggin and the Red Nose Burglar. Language advisory here. The song's lyrics are just I'm a wanker said 36 times and someone took over a radio station in Britain and just rang that song on repeat for a little bit of a little bit of time and, caused a whole bunch of trouble in The UK. I don't know if they ever got caught, but, I guess it made it, like, it cert caused the song to surge a little bit in popularity in The UK.

Speaker 3: Wow. Affect the charts. Shot to the top of the billboard charts.

Speaker 4: Effect it affects the charts. Yeah. Sure. Pumped someone off them. Exactly. Yeah. So a proud tradition.

Speaker 3: Proud tradition. The, I've never really I guess the thing for me is is, like, if you're gonna break into something, the second you mess up the closet, people are gonna know you were there. Sure. Where if you break into it and you don't

Speaker 5: Where if

Speaker 3: you break into it and you don't even mess up the closet, maybe you go through the closet, but maybe you kinda put it back like it's supposed to be, and then you leave.

Speaker 4: Maybe you change some grades.

Speaker 3: No. Not even change some grades, but just, like, take a peek in. Like, usually, the nerds don't need to change their grades. Like, let's be honest. The the the No. You're, like, taking a peek in and you, like, just

Speaker 4: Right.

Speaker 3: Just kind of a little bit of a voyeur, and you just kinda look around, take a little detail, read some stuff you're not supposed to, look at some schedules, do some things like that.

Speaker 4: Scott.

Speaker 3: No. No. But then you can leave, and then come back later because nobody knows you were there. The second you put, like, schools out for summer on the main website, they're like, okay. Hold up.

Speaker 4: We got

Speaker 3: a problem.

Speaker 4: Yeah. It's the, it's the Ocean's 12 thing of the the burglar that leaves the little onyx fox behind so that you know the night fox was here kind of thing. I get that temptation to just be like, look how gosh darn clever I am. We are the nerds. We will inherit the Earth's schools, in fact, out for summer.

Speaker 3: It's almost like that motivation is the motivation behind this show, hotline hacked. Okay.

Speaker 4: And with that, why don't we, why don't we spin our own? Why don't we do our own needle drop and play another one?

Speaker 3: Okay.

Speaker 6: Hi, Jordan and Scott. I'd like to share with you a war story from back when I was, quite a lot younger. Back in 2014, I was working for a small pen test outfit, and we'd scored a gig at a multinational, and I was sent to the London HQ. We'd been making steady progress, or rather I'd been making steady progress because I was doing the testing, but I'd hit a bit of a wall, so I started looking at ARPS spoofing. So there I am at the European HQ of this company, and I've done a little bit of ARPS spoofing, but not got very far. I think I've managed to grab one set of admin creds. I decided to widen the net of my ARP spoofing without really thinking things through and not really anticipating the consequences of my actions. Just to add some technical context, which will help explain what is actually going on, ARP or ARP is Address Resolution Protocol. So ARP is a way of making sure that packets on the wire get to where they're supposed to be, and this is done by advertising your location information to everybody. ARP spoofing is when an attacker wants to impersonate another endpoint and redirect traffic and act as a man in the middle to read any data crossing between host a and host b.

Speaker 3: Tonsko provided us great details here, but so your computer is sitting on a network. It has an IP address. The routers kind of look to your hardware ID, your MAC address, and ARP is the protocol that connects your hardware ID with your network ID. So it's kind of like the it's kind of like the glue in the middle. And and the thing with ARBs moving is is, like, you can essentially broadcast that you are a different hardware ID and start getting packets routed to you that shouldn't be routed to you. So you can kinda man in the middle network traffic a

Speaker 4: bit. Right.

Speaker 3: So that's very applicable to the how and why this story when we continue how

Speaker 4: Right.

Speaker 3: Where where the pain point came from so we can get there.

Speaker 4: It's equivalent to putting a, a different address on the front of a house and waiting for the mailman to deliver someone else's mail kinda thing.

Speaker 3: Yeah. And then opening that mail, looking at it, and then taking it back and putting it in the right mailbox.

Speaker 4: Sure. Sure. So they never know. Exactly.

Speaker 6: I'd found three Cisco switches that looked innocent enough. However, they turned out to be Cisco Catalyst 65 hundreds. Big core switches the size of a cabinet capable of shunting up to four terabytes per second around. As I started to ask spoofing that, it directed them to send all of that traffic through my little MacBook Pro's one gigabit network card. I didn't really get much juice, so I kind of stopped and started throughout the day.

Speaker 3: So there's the there's the rub, and you'll understand it in a bit, is is massive, you know, institutional four terabyte a second data throughput switches start funneling all of their traffic through his one gigabit Ethernet port in his MacBook. So So essentially you're taking this massive funnel and funneling all of the data down to this tiny little channel, which I guess I want a gigabit Ethernet card is a tiny channel in in comparison to four of these monster switches. So So that's gonna be very Sure. Very relevant. So I'm just hoping to help you understand.

Speaker 6: I was sat in this room, a big open plan office, and IT were on the other side of the atrium. And I noticed that there was a bit more activity on the second day. Not really thinking any of this increased energy, I continued with what I was shortly to realise was my rather reckless ARP spoofing attacks. About halfway through day two I saw a group of people threading their way through the desks towards where I was sitting. I clocked them, and they looked purposeful. More to the point, the purpose appeared to be me. They stopped at my desk. One of the people, seemed senior, asked me to stand up, and a fellow checked under my desk to see what port I was plugged into, which became clear was the port they'd identified was causing whatever problem they were trying to solve. I was asked what I was doing and why I was here. This is the point you present your get out of jail free card to say that you're authorized to be there and do some testing. I explained that I was trying to ops spoof some switches, at which point they interrupted me and said that my testing was causing widespread European network disruption for the last day and a half and politely requested that I stop what I was doing immediately. As they were talking, the enormity of my error dawned on me, and I felt this huge hollow hole open up in my stomach.

Speaker 3: So now you can see, like, imagine all of that data. Every time that he would spoof and pull that data through his computer to, like, you know, analyze it and look for, he was looking for credentials, like, unencrypted credentials. But, like, every time he would do that, like, they own those monster switches for a reason. Right? Like, they have the network connectivity to push all of this data throughput. And every time he would hijack it,

Speaker 4: he

Speaker 3: would bottleneck it so that it would just cripple, like, the the network connections for everybody trying to use that information and and use data going through those switches. So so he was causing intermittent hell for this company because just every time he turned on, like started spoofing, they would just kind of cripple the network and then he'd turn it off and go through the data he collected and it would go back to normal and then, you know, two hours later he'd turn it back on And it just doing that repeatedly would just become such a headache. So they obviously trace the network load to his Ethernet port and went and, you know, interjected. So just to help you understand.

Speaker 6: I was lucky enough to be spared the walk of shame and allowed to stay until the end of the day, but it was made very clear that I was deeply unpopular. Thinking about it later from their point of view, I would have been causing that worse sort of support issue, the intermittent problem, with no obvious pattern. In the report, I described the attack and suggested that Cisco's anti ARP spoofing control was enabled. My boss was good enough to not chew me out, but I suspect he got severe bollocking by the client. We never went back. I was the layer rate problem.

Speaker 4: Oh, that's a good story. I clocked them, and they looked purposeful, and the purpose was me. So Tonsko, for everyone listening, is is a good friend of the pod. Mhmm. But I'd listened to this when I first came in. I I forgot how good a storyteller he is. There there's some great there's a really well told story. The metaphor I was cooking up as you were explaining to me is it almost feels like there was this industrial water infrastructure, some massive pipe that everyone's drinking from. And he managed to reroute it through a tiny little garden hose so he could take a sample out of the water, not realizing that a bunch of people's taps stopped working every single time he did that. That's a good one.

Speaker 3: Okay. So that so that like, this is a cut down version of it. He I think he sent us, like, 19 parts to this. So his little his little tail there, like, I was the layer eight problem is, like, a really is a throwback to a joke that I didn't realize that I didn't include in the edit of the story, Story Tonsko. But networks are seven layers, and layer eight is like is like a technical joke to say that, like, it's a user problem. Like, it's like skill issue user error. So, like, he was the layer eight h problem is saying, like, I was the user that was causing the headaches.

Speaker 4: Oh, sure. Okay. That makes sense.

Speaker 3: So I so I totally when I listened to that there, I was like, oh, man. I missed that. But but but it it is good. He did provide tons of technical context and a bunch of color and commentary about things, but it just would have it was, like, twenty minutes, I think. So I chopped it down. I think I think I think I kept the core part of the story, which I'm happy about. But

Speaker 4: I think we got the the big ideas that he'd been brought in to do this job as part of this pen test outfit. He was he was gathering data and just inadvertently caused widespread European outages, which is it's it's fascinating that that's a a thing a person can sort of, like, walk their way backwards into. I also like that he talked about the idea of and this is true in more than just tech, but especially in tech is that the intermittent problem is the worst

Speaker 3: problem to solve.

Speaker 4: If you're not getting a signal, you're always getting a signal you shouldn't. That's pretty easy to figure out. Whether it's regardless of what it is, you can basically do some unplug, replug in, and work your way back to whatever the thing is that's causing the problem. But when the problem's intermittent, it's a lot harder to troubleshoot because you kinda gotta wait for it to

Speaker 3: flare up. Yeah. And and then if if it doesn't last long enough for you to properly diagnose it, it just goes away. So, like, the word the term intermittent used to be like a keyword when you dealt with warranty support. Like, if you're I was gonna

Speaker 4: bring this up. I was gonna bring this up. I was like, it's also how to get a

Speaker 3: new iPhone. Yeah. Yeah. So, like, I remember, Rach, when I had my first iPhone, I remember I was having intermittent USB problems. Like, it would back before before iCloud synced everything over the over the air, You just have to back up your phone to your computer and stuff through through a cable. And every now and then, it wouldn't work. So I remember booking an Apple Genius Bar appointment and going in there and being like, I'm having intermittent USB problems. And they were just like, here's a new phone. Like, there's no way that it looks like it's working fine now, but there's no way that we can prove that it's not not working. So here's a new phone. Have a great day.

Speaker 4: I remember a a friend a mutual friend of ours, this was years and years and years ago, but telling me to do the exact same thing. It was like I had a phone and there was something trivially wrong with it, but it was still under warranty. I wanted to take it back in and kind of just get a new one. And this mutual friend of ours looked at me and said, it's not that there isn't a problem. It's that whatever problem there is is intermittent.

Speaker 3: And he said it to me

Speaker 4: like, I'm going to teach you abracadabra.

Speaker 3: Exactly.

Speaker 4: This is the thing you say to the genius bar to get them to give you a new one. It's like going in the gray market situation going into the to the the special doctor's office and saying, I have this thing on the page, and they they give you the thing you want.

Speaker 3: Totally. It's the

Speaker 4: magic spell.

Speaker 3: Totally. Yeah. Intermittent like, as far as technical issues go, things that are, like that aren't constantly reproducible are just a nightmare because it means that there's multiple factors affecting what's going on. And, Tonsko's layer eight intermittent problem here, kinda shut down this big company.

Speaker 4: It does make me wanna I'm I'm sure it's not a big enough outage for it to ever made news, but I do wanna see

Speaker 3: if I I wanna see if

Speaker 4: I can find some reports of a of a, outage somewhere in Europe because, it it's fun. I wanna I wanna find I wanna find out more. Great story, and thank you for sending that one in, Totsco.

Speaker 3: Totally. He actually had a a little extra story, so I'm just gonna fire that now.

Speaker 4: Oh, amazing.

Speaker 6: And just as another little little extra, one of my colleagues at a different time was using Burp Suite to test a website, and it was testing so they could go live the next day. He had admin creds, and he'd used Burp's explore every button feature within the website. Unfortunately, one of those buttons was delete the website. And as he was logged in as an admin user, the website went bang just before they had to release the next day, and they had to really hurriedly rebuild everything. Again, it was not deeply popular with anybody.

Speaker 4: And the website went bang. I'm using that one for catastrophically destroy oh, it just went bang.

Speaker 3: So that's just, like, such a classic story about, like, knowing the tool you're using and understanding the exceptions that you don't want it to do. Mhmm. It's like running running like a like a testing suite or suite to, like, go through a website and make sure that all the links work and make sure everything's functioning and make sure that the buttons are reacting. And then you run it through the admin panel, and all of a sudden it's like creating garbage posts and changing content, and then bang, it hits the delete. And then and then test the verify that you want to delete it button, and then boom, the whole thing's deleted.

Speaker 7: Sure. Interesting.

Speaker 4: That actually makes a lot of sense. Yeah. You you unleash these things, like, test everything. It's like, you want me to test the burn this thing down button? Exactly. I said, test everything. Exactly.

Speaker 3: So may maybe if you're gonna run something like that, don't point it at the admin panel.

Speaker 4: Yeah. Sure. Sure. Also, just I Burp Suite. Good. Burp Suite. Good good stuff.

Speaker 8: Hey. So I had an interesting interaction trying to find some data online. I was looking up, some leads for my company, and I found this one company that had leads apparently for every state, tens of thousands of leads. And they had some sample data, which if you clicked on the sample data, it would say Alaska. Here is the few, sample leads we have for Alaska. And it was kind of just, like, dip your toes in and tell you a little about it. But I noticed in the URL, it said dash Alaska at the end. So I tried it, and I did dash Ohio, dash Idaho, dash, another state, and ended up being able to find the entire repository of data, that they were selling for tens of thousands of dollars, all of the leads, because all of the URLs were just plain text. Kind of easy to find URL. But, yeah, they wanted near $10,000 for access to all of the leads, but I was able to find all of them for free.

Speaker 4: I wonder what the highest ticket data that is hiding behind a guessable URL is because it's sort of a fascinating question. It it it evokes like a treasure buried somewhere, but there isn't a treasure map. But, like, if you just knew to dig there, there'd be gold. And sales leads feels like a pretty good potential realm for that kind of thing to be in because, man, our sales leads not cheap.

Speaker 3: No. Yeah. I think yeah. Personal information for sure. Yeah. Yeah. For sure would be would be up there, especially confidential personal information.

Speaker 4: Totally.

Speaker 3: Socials, things like that. Definitely like the ebike story from last Holland hack.

Speaker 4: Mhmm. Then

Speaker 3: this is I sent I threw this one in because it's it's in the same regards. You know, it's we're talking about, like, people people who have built web structures that work, but they don't explore how they work if you just make a few little obvious changes.

Speaker 4: Mhmm.

Speaker 3: It's like paywalls and, you know, web developer inspector, and you can just disable the paywall on a website. If if the site still loads all the data in, all you have to do is take out the HTML layers that are blocking you from seeing it, and you can still see the data.

Speaker 2: Mhmm.

Speaker 3: And it's like, I feel like this is the same this is the same thing. You know, it's just basic basic security solutions and people that don't perceive the future security problem, especially with valuable information, which is crazy.

Speaker 4: Yeah. There's whole massive industries built on this. We we've talked about third party data brokers before on this show, but the third party data broker ecosystem has a huge subset of it that is just dedicated to sales leads. It is a massive way that companies find sales leads is purchasing them from other people that have typically purchased them from someone else. And it gets very difficult to know the sort of Genesis of that information, by the time it gets to an end buyer. And it's like apparently quite a quite a problem. There's a lot of overreliance on these third party groups. They're quite under regulated there's security and regulatory risks when you don't know where the data came from. None of that has anything to do with it being, publicly visible behind a guessable URL, but it is a fascinating world that, this caller sort of inadvertently weighted themselves into just by tweaking a URL.

Speaker 3: Yeah. Totally. Like, the I can always tell when I've been added to a new dataset just by the flooding of garbage that I get into my inbox.

Speaker 4: That's a good call.

Speaker 3: Like like it's Yeah. Like, very recently as of recently, I've been seeing a a strongly increased presence of phishing attacks in my inbox. So I'm assuming something some website where I had an account got hacked. And then I I'm also getting just a flurry of newsletters from companies that I've never heard of nor have I ever signed up for. So I'm assuming I was added to another dataset, and I'm gonna report them all as spam and get their Mailchimp accounts banned. But

Speaker 4: if you buy a giant list of names with a disregard for where they came from, you've got to acknowledge that you're gonna piss a lot of the people you reach out to. Like, it's I'm not saying there aren't situations where those third party leads don't make a lot of sense, but you gotta know that it's like somewhere down the line, the, the source of that data could be, you know, a data leak. Totally. It it's a fascinating world. We this is a bit of a tangent, but so for anyone that doesn't know, CPM cost per melee is the way advertising on the Internet is monetized. It's whatever a thousand impressions costs for the advertiser to get. So if your audience is 10,000 people, it's 10 times the CPM cost. Sales leads operate on a similar system at CPL cost per lead. And the ceiling on CPL is, is considerably higher than CPM. It bottoms out at around 10, but it maxes out at around a 100, which is an exceptional if it was a CPM would be exceptional, which makes a lot of sense because depending on what you're selling, that audience could be worth a ton of money.

Speaker 3: Well, I know, like, my brother is a real estate agent, and I know the realtor world, like, leads and lead development, lead generation. Like, they're that's

Speaker 4: Whole thing.

Speaker 3: They're tuned into that world. And, like, hot leads, like, if you could imagine, like, say you're in, like, a, like, a decent real estate market where, you know, say the average house is 700 plus, you know, your commission, your realtor commission on that's gonna be tens of thousands of dollars. So, like, what is the value to you as a realtor to get a hot lead? Somebody that's actively wants to buy a house. Like, would you spend a thousand dollars to make 10,000?

Speaker 1: Yeah. Or

Speaker 3: spend $2,000 to make 10,000? Would you spend $5,000?

Speaker 4: If it was a sure thing, you'd spend 9,000. Like, you would it's Exactly. Yeah. No. It makes a ton of sense, especially for something like real estate where the potential margins are massive. You know, for a tech company trying to get a new customer at $9.99 a month, the scale shift a little bit. But for a an individual salesperson going after an individual buyer that has the potential to put 5 figures in their pocket, how do you not turn these sort of repos of information? I get it. I really get it. This is a this is a

Speaker 6: good one.

Speaker 3: Yeah. Yeah. Yeah. Yeah.

Speaker 4: Why don't we kick it over to we I think we need a name for for where we read ads. I'm calling it.

Speaker 3: You're calling it? K. You name it then. You call it.

Speaker 4: I didn't say I didn't say I had a name. I'm saying I think we need one. A a podcast I love calls it going to the money zone, and I just really like that. There's something something nice about that. So, we're gonna workshop that. For now let's go read some ads. Starting something new isn't just hard. It can be downright terrifying. You put a lot of work into a thing. You're not entirely sure it's gonna work out. You're taking a huge leap of faith. I've started a few things. Now I know I was right for believing in, you know, the idea, the product, despite all of those fears and hesitations, but boy, does it sure help when you have a partner like Shopify on your side. Shopify is the commerce platform behind millions of businesses around the world and 10% of all e commerce in The US. From household names like, well, hacked podcasts merch, to brands just getting started, you can get started with your own design studio with hundreds of ready to use templates. Shopify helps you build a beautiful online store that matches your brand style. Did I mention that that iconic purple shop pay button is used by millions of businesses around the world? I don't know why I wouldn't. I should. It's why Shopify has the best converting checkout on the planet. It also helps boost conversions, meaning less carts, sort of getting abandoned in the parking lot and more sales for you. It's time to turn those what ifs into sign up for your $1 per month trial at shopify.com/hacked. Go to shopify.com/hacked. One more time, that's shopify.com/hacked.

Speaker 9: When you need to build up your team to handle the growing chaos at work, use Indeed sponsor jobs. It gives your job post the boost it needs to be seen and helps reach people with the right skills, certifications, and more. Spend less time searching and more time actually interviewing candidates who check all your boxes. Listeners of this show will get a $75 sponsored job credit at indeed.com/podcast. That's indeed.com/podcast. Terms and conditions apply. Need a hiring hero? This is a job for Indeed sponsored jobs.

Speaker 5: Sierra has all the best active and outdoor brands you need. From athletic stuff, like a full court pickup game, swish, to athletic ish stuff, like a half mile stroll. Get those steps in. And for morning hikes up the mountain trail, good pace to nighttime ghost stories from the camping chair. What a twist. Whatever level of active, Sierra loves it all. Head to Sierra or sierra.com for the brands you want at the prices that let you do it all. From athletic to athletic ish, Sierra's got it.

Speaker 10: No one goes to Hank's for his spreadsheets. They go for a darn good pizza. Lately though, the shop's been quiet, so Hank decides to bring back the $1 slice. He asks Copilot in Microsoft Excel to look at his sales and costs and help him see if he can afford it. Copilot shows Hank where the money's going and which little extras make the dollar extras make the dollar slice work. Now Hanks has a line out the door. Hank makes the pizza. CoPilot handles the spreadsheets. Learn more at m365copilot.com/work.

Speaker 3: Thanks for listening to Hack podcast. Yeah. This is an episode format that we have called Hotline Hacks. You can visit hotlinehack.com. You can email in an audio clip, email in text clips. You can, call into our call in number and leave us a voice mail, which we get as an audio file and we will include. I will note that if you want to disguise your voice, we prefer that you do that on your side Yes. Rather than supplying it over to us and making us do it.

Speaker 4: There's also an email if you wanna send us a file. Like Scott said, if you'd like your voice concealed, please do it yourself because, we we run the audio as we get it unless you explicitly ask us to. Some folks have found awesome ways of concealing their audio, so, feel free to have fun with it.

Speaker 3: Well, the next story was actually sent in in text, and it has so we get this lovely AI voice.

Speaker 9: Brilliant. While working at an ISP in Australia, we had a cloud storage server used for clients to store data, and I wanted to export the list of accounts. I connected to the Linux box via SSH using PuTTY, logged in as root, yes, this is bad, I know, ran the command to display the list of active user accounts on the system, highlighted the complete list of usernames, and out of habit, right clicked on the list to copy.

Speaker 3: K. I'm just gonna chop this one up in my own way. PuTTY is a Windows based SSH client.

Speaker 4: Okay.

Speaker 3: So, SSH is like a UNIX command and like a UNIX daemon that runs on UNIX servers so you can connect to do it via text, like command lines. So when you're on Windows back in the day, which this story sounds like it was, there was no Linux core running inside of Windows. So, like, now you have full kind of Unix integration on the command line. Now you back then, you didn't. So if you wanted to connect over SSH to, you know, Unix based servers, you had to use PuTTY. Or PuTTY was the most common. And running anything as root is bad. So that's why she flags that or they flag that. I guess I'm just using the gender of the AI, which is probably incorrect.

Speaker 9: Those of you that use PuTTY know that by selecting text, it automatically goes to the clipboard, and PuTTY has right click to paste enabled by default. Suddenly, my entire clipboard is being dumped into the server's terminal, then my SSH session drops. Connection lost. I stared blankly at the screen for a moment trying to work out what just happened. I pasted my clipboard into notepad and reviewed the list of names and found a user account called shutdown. That's the day I learned that r h e l slash CentOS has a default user account called shutdown, and a simple click of the mouse took down the cloud storage server briefly.

Speaker 3: So it's pretty common to have a user called shutdown and pasting just a bunch of garbage into the command line, sadly executed the command shutdown, which truthfully surprising that it actually shut it down because I think typically you need, like, a hyphen now or something after that to actually make it shut it down instantly.

Speaker 4: Right. Sure.

Speaker 3: But, yeah. Just a little little user error.

Speaker 4: Just a little user.

Speaker 3: It's a little user error. Take down an entire cloud server.

Speaker 4: I I really liked my favorite point in this is and I know part of this is the AI's read adding the comedic timing, but I think it was in the story is I logged in as root. Yes. This is bad. I know. Like the immediate awareness of an error as it is occurring is, a timeless

Speaker 3: feeling. A timeless, timeless feeling.

Speaker 4: Right click to pace enabled by default seems like this story is so above my head technically, but right click to paste enabled by default feels like a weird feature to include in anything like that. I I have, I've just never heard of that. That might just be my non familiarity with this kind of sysadmin type stuff, but that feels like, a lot of potential bad stuff could happen by having a mouse one mouse button queued to paste.

Speaker 3: Yeah. I think that the the gist is is, like, when you work on command lines, typically, you only use the mouse to select things.

Speaker 4: Right. Right. Okay.

Speaker 3: So PuTTY was like so PuTTY was like, hey. Like, why don't we just fast track this? If you select something, we're just gonna auto copy it, which is, like, a brilliant little user interaction.

Speaker 4: That actually does make sense. You're never using your mouse.

Speaker 3: Granted, it violates all user interactions you've learned your entire life, but but but but it is kind of an optimal workflow. And then, right click to paste. Again, same thing. Like, if you're just copying things by selecting them, if you wanted to paste something, like, say, you wanted to redo a command or, you know, you're building out some large auth query or something and you copy something and you wanna paste it in, like, right click, it's like a nice little quick paste button.

Speaker 4: Sure.

Speaker 3: But when you copy, like, you know, your bash history by accident, which maybe you don't know what that is, but your command line history, and then you paste that in, like, that would be brutal.

Speaker 4: My favorite one of my favorite things of working with, Commsi people, account you amongst this, but like devs and computer engineer, any of that type of person is all of the genuinely smart, but humanly unintuitive solutions that slowly become part of a workflow. Like, the idea of, like, we never use the mouse, why not make one of these buttons something we do all the time that requires a key command? It's like, that's very, very clever until you inadvertently press the button you otherwise use all the time for something else and paste something. It reminds me of Dvorak where it's like, this is technically a better way to lay out a keyboard until someone who isn't used to this tries it or until you try and go use a computer that isn't laid out in Dvorak, an alternative to QWERTY, and your brain explodes trying to translate these different keyboard layouts into one another. Yes. I love those those those computer engineer workarounds.

Speaker 3: Good stuff. I I think we're both know who you're talking about when you're talking about Dvorak.

Speaker 4: We sure do.

Speaker 3: And and One

Speaker 4: of my favorite human beings.

Speaker 3: Yeah. Great guy. Love him. Hate sitting down at his computer

Speaker 4: Hate Dvorak.

Speaker 3: Trying to type something on his keyboard and immediately, like, feeling like I'm having a stroke where it's like I'm looking at characters showing up on the screen. I'm like, I don't know what's going on.

Speaker 4: I have to back

Speaker 3: away from the situation.

Speaker 4: Hate the Dvorak love the sinner kinda situation there. Totally. It's just I I can't believe that you did this. Can you turn

Speaker 3: it off?

Speaker 4: It's a pain in the ass to turn it off. Okay. Can you type for me? Yep. Definitely been there.

Speaker 3: Speaking of keyboards Shoot. I got my new one built last night. Oh. Yeah. I'm not sure how relevant it is to the podcast, but we're

Speaker 4: not gonna be swayed. But it is fun color commentary for everyone that doesn't know Scott's, Swanky Mechanical keyboard got broken, and he was building out a new one. That's very exciting. I mean, while I'm still operating my, lightning port Mac keyboard that I loathe.

Speaker 3: Do you have the number pad one?

Speaker 4: No. I don't. I'm not a I'm not a num pad guy. I I know. It I know. God.

Speaker 3: I miss a miss a good num pad.

Speaker 4: Yeah. You're a big num pad guy. No. I'm I'm the standard chiclet Apple keyboard and it's bad. Mhmm. You can hear all about it on our consumer tech show. Let's let's keep it let's keep let's keep this bad boy going.

Speaker 7: I'm submitting my audio with an AI since my speaking English is not great. I got an accent and also so people cannot identify me. So I got a very powerful command and control, c two c, that is able to shut down and slow any websites and servers, etcetera. It's only built with Raspberry PI four model b plus and a plus 170 m e b fiber Internet speed and an open source software, etcetera. To test it out during the pre war October 7 in Israel, I saw the Hamas website is still up even though there are news that other hackers' countries shutting it down. Even though it changed its Internet protocol since the attack, I was too able to shut it down in minutes. I also tried to join a bounty program for denial of service in Hackerone for PlayStation website, my.account.sony.com. I was able to make it into 404, unresponsive, but of course I didn't receive any rewards since they don't accept full shutdown disruption and also no distributed denial of service, dDOS, but only denial of service, d o s. Also, whenever I receive a message from a scammer redirecting me to their websites or link, I just get the domain they are redirecting me and shutting it down for myself, asterisk smiley face asterisk. This c two c botnet is very dangerous and powerful since I test it out in Live Layer seven massive in d state ECC. It sends out over 17,000,000 requests in just minutes, etcetera. So I got a hand into a Pandora box.

Speaker 4: Got a hand into a Pandora box.

Speaker 3: Yeah. What a way to end a recording. I've got a hand into a Pandora box.

Speaker 4: And end call.

Speaker 3: This is maybe the less least lighthearted of the of the classics. So this is somebody that's got control of a botnet for doing DDoS, so distributed dial denial service.

Speaker 4: Yeah.

Speaker 3: And, you know, tried to go kinda white hatty, join a join a thing with PlayStation, but, apparently, they were only looking for, you know, DOS, like, just denial of service, not distributed denial of service as, you know, obviously, that's hard to combat. But but, yeah, interesting.

Speaker 4: Command and control with a with a Raspberry Pi. Can you make sense of that for me?

Speaker 3: Yeah. So command and control. So there's a there wasn't enough detail in there to fully understand what the botnet is, like, what's actually what the bots are.

Speaker 4: Right.

Speaker 3: But it sounds like they've set up a Raspberry Pi, like, essentially a invisible computer that they can kind of carry around. That is the control unit for a massive botnet. At least that's the way I took it so that they can kind of fire it up and point it at things whenever they feel the need to.

Speaker 4: Right.

Speaker 3: Does that make sense?

Speaker 4: I think so. You're just using it as essentially a little server for this Yeah. Command and control operation.

Speaker 3: Like, if you if you remember command and control, it's like the how it's like a hub and spoke kinda model where you've got, you know what did he say? 17,000,000 requests a minute. Mhmm. So he'd have just a flurry of bots living in the world, and then he'd have a single unit to control them all. So, like, a lot of those DDoS for hire services are set up like this where they have a control unit, and then they have, you know, millions of bots or whatever, you know, smart fridges around the world that have been compromised.

Speaker 4: Sure.

Speaker 3: And then they they can send a command to all those smart fridges to make requests on a specific data, you know, IP address or web protocol or something, and they could just shut the server down. So it sounds like he was successful at shutting down PlayStation. So and and, you know, Hamas and a few other things. So so it sounds like they've got a substantial little botnet. I I can see the I've got my hand in a Pandora bot because

Speaker 4: Right. K. That makes more sense.

Speaker 3: You've just got, like, all this power in your hands to be like, I just pointed things on the Internet and they go away. It's like, what do I feel like pointing at today? I I you know, I don't hate the idea, like, the especially given the amount of phishing requests I've got lately. It's like a lot of them point back to these, like, weird server farms in, like, Russia and Bulgaria and things like that. So it'd be having the power to just be like, I don't I'm not gonna click on your bad link, but I'm gonna take the server IP address and just knock it off the Internet. I can I can understand that motivation?

Speaker 4: I found a a Reddit thread with someone asking a question somewhat tangibly related to this asking using a Raspberry Pi three as a command and control server.

Speaker 3: Oh, yeah. One of

Speaker 4: the first comments says, you know, it's a server. You can use it as any other server. Since you're asking this question and seem like you intend to use it at home, maybe don't unless you like prison food, which is it was a great comment. Proper amount of snark. The thread then goes, here's where you assume too much. They could just connect it to any network and walk away, see mister robot to which someone else replied, and then they find your Reddit post. And if we go back up to the top of the Reddit post, we see the user deleted their account.

Speaker 3: So it's

Speaker 4: a nice little closed loop. I doubt it was this caller, but, an interesting question with some good feedback from the from the hive mind.

Speaker 3: But but like the the like the Raspberry Pi, like the micro PC trend, I think is like Mhmm. Like, when being a young hacker, when you wanted to do something with computers was, like, difficult. Like, laptops were

Speaker 4: Sure.

Speaker 3: You know, expensive and hard to come by and often underpowered. And now it's like you can build like you could build a tiny little microcomputer and, like, turn it into an ARP spoofing device and walk into an office and jack it in.

Speaker 4: Right.

Speaker 3: And people won't even notice it's there. Like, it could be very tiny or disguised to look like something else. And so it's like the Yeah. I don't know. There's there's a whole whole cool alley of, like, custom little microcomputer hacking device things that is out there that would be fun to pursue.

Speaker 4: Yeah. It's a that's an interesting world of tiny, like a raspberry PI three is about $50. And so it the idea of there being a thing that can function as a server, but is $50 isn't disposable and no tech should be regarded as disposable for a bunch of other reasons. But the fact that there's a thing that you could theoretically just sort of leave behind somewhere, without a fingerprint on it is, oh, there's a reason mister Robot made a whole bunch of subplots based on that very premise.

Speaker 3: Yeah.

Speaker 4: It's because it's it's interesting and compelling and is as this caller referred to it, quite the Pandora's box.

Speaker 3: Yeah. Totally. Like like, in twenty years ago, if you wanted to build something like that, it would be you'd be building a small computer, and then you'd have to, like, have a power supply and walk in and plug it in. Or it's like nowadays with USB power, like, you pretty much if you really wanted to and you were like a big hardware engineer, you could probably build something that you just slide into a USB slot that was a fully functioning computer with radio antennas and, like, yeah. I don't know. Totally. Like, look at the Flipper Zero, and it's like a tiny little $100 device or a $150 device.

Speaker 4: Yeah. I think that world of little hacker computers, and you got me on the cyber decks, that fascinating compute community of people building from scratch, little, computers. And it's I I think there's a for as much as we're pushing the the boundary of, you know, what a $3,000 computer can get you and what a $1,500 smartphone can get you the floor to raises. And we start figuring out, well, what's the most, a $50 thing can do. And that's at just as interesting, a question. I I mean, I think of game emulators too, those tiny little devices that, you know, can suddenly for $45, look what they can do.

Speaker 3: Well, I was about to say the the the micro device world is is a, you know Yeah. Fired up. You know, you've got, like, the tiny little Android devices, like, so many things. Like, I just got a new bike computer for cycling, and it is a full Android phone, essentially. It's just a dedicated Android device. And, you know, we were talking about the Rabbit r one, which has gotten more press.

Speaker 4: Yeah. But then Yeah. We're gonna talk about that. But

Speaker 3: but but the 15. The Rabbit r one is essentially just a micro Android device. Yeah. And it's like all of these things, and and, like, they're cheap. You know? They're they're tiny little pieces of hardware. Like, the game emulators are great because, like, one of my game emulators is literally a Linux computer. And if you think about that, like, that's a full blown Unix computer. Like, I could just plug a keyboard into it. Mhmm. And I have essentially it has Wi Fi chips. It has everything. And it's essentially a microcomputer, and it cost me, like, $39.

Speaker 4: So

Speaker 3: Has a screen. Has, like, a full color, like, screen. Like, I have another one that has an OLED in it. Like, it's I don't know. Crazy. The the the micro device market is very cool. Maybe a bit wasteful, if we wanna talk about waste, but I think I think very, very cool. And, especially from a hacking perspective, like, just the amount of things that you can do with these things now. Now they like, you can have a like, if you talk to 17 year old me and ask me if I would love to have a Linux computer that was in my pocket, I would've I would've loved that. Mhmm. Especially something with the battery life that some of these, like, small emulators have. Like, they have eight hours, ten hours of battery. Like, you know, when I was a kid, the best battery life you'd hope for on a computer was, like, forty five minutes on a laptop, maybe an hour and a half.

Speaker 4: I imagine if we could talk to 17 year old you right now at time of recording, you would be trying to play Schools Out for summer, somewhere where you're not supposed to be.

Speaker 3: No. No. No. I was I was white glove service. I never

Speaker 4: White gloves service. Too many things. That's pretty good.

Speaker 3: I just went yeah. I was more of a, more of an explorer than I was a disruptor.

Speaker 4: Well, I was, those flipping power breakers and getting dragged into the dragged in the old office. But that's a story for another time. And if you wanna hear us

Speaker 3: Power breakers.

Speaker 4: You, Batman. The thing they were most mad about was that our school had a vending machine with those weird, milkshakes, like bottled milkshake y type drinks.

Speaker 3: Oh, no. And you soiled a bunch of them.

Speaker 4: And we didn't. That was the funny part is that they're shelf stable.

Speaker 3: Oh my god.

Speaker 4: But they do have refrigeration in the thing. And I remember a police officer yelling at me, do you know what could have happened to the milkshake vending machine? Like, that line, can you imagine what would have happened to the milkshake vending machine? It's like, like, barked at me by a guy in in in a cop uniform. Well, he's forever burned into my mind. If you wanna hear us tell more stories like that, you know, feel free to support the show however you can. Hackpodcast.com redirects towards our Patreon. If you go towards our store, pick up some merch, buy a hat. That that that helps us that helps us out. Anything else? Anything I'm missing?

Speaker 3: I don't know. No. I don't think so. Store.hackpodcast.com, hackpodcast.com, patreon, hotline hack.com, submit your story. I think that's it. I think that's it. Is that it for us? School's out for summer?

Speaker 4: Schools school is in fact out for oh, I don't know how fair I don't know enough about fair use to know if we can end this episode with that song. So, but we'll find out before the episode goes live. So if you don't hear that right now, it means it's because you can't use it. And if you do, it's because school's out for summer.

Speaker 3: Well, it is Memorial Day weekend. We're recording this on Memorial Day weekend. We are. And Memorial Day is the demarcation for summer. So

Speaker 4: It it is. Oh, that's fun.

Speaker 3: Good good timing.

Speaker 4: Good timing. School's out for summer. Call in with your story. Hotline hack .com. That's another one in the bucket. Thanks for listening everybody.

Speaker 3: Take care.