Hotline Hacked Vol. 5
TL;DRA web developer hacked a band's album promotion scavenger hunt by inspecting JavaScript source code, uncovering a hidden endpoint and blurred image to reveal the unreleased album cover early — and got banned for it.
It's a five-alarm fire in the fifth instalment of our call in show. We hear from a caller who accidentally won a naval war-game by unplugging a radio, a person whose company hired someone who clearly lied about their technical background, a very wholesome story about Counterstrike, and a person who decided to do a scavenger hunt by scavenging online instead of the real world.
Transcript
Machine-generated transcript; may contain errors.
Speaker 1: Thank you for calling Hotline Hacked. Share your strange tale of technology, true hack, or computer confession after the bee.
Speaker 2: Hey, guys. Big fan of the show. I really like the Hotline Hacked episodes you guys do. I'm glad to hear you guys will be making more of those. I was listening to the most recent episode, which was volume four, I believe. And it reminded me of this time about a year ago. I just graduated college. I was working as a web developer, and one of my favorite bands was promoting their new album. And the way they had decided to promote this album was they made a scavenger hunt, and they set up these codes all around venues in The US that they liked to perform at. And if you're in the area, you could go to the venue and look for the codes that were hidden. And once you found a code, you could go to their web site and input the code. And once all 20 codes were found, they were going to release some surprise to the website. So it was really cool way of promoting it. Me and my friends were all following it pretty closely. I was checking the website every day to see what codes were left, how many have been found. And there was one code in particular nobody could seemingly find, and it was the last one left. And it had been about a week, and I started to get impatient. And so looking at the website, it just looked, you know, just poorly made. And you get that itch of, like, I bet if I start looking around here, I could probably find something I shouldn't find. So I got onto the website, pulled up the Chrome developer tools, started looking at the network responses, what would happen if I tried to input a fake code and submit it, what response would I get. I started looking at the source code, seeing if there were any hidden pages anywhere. And at the bottom of the source code, I found these scripts, and one of them had some JavaScript code that just had an if statement in it. And it just said, if number of codes equals 20, run this endpoint. So I grabbed that endpoint, and I ran it in my console, and it responded with a audio file and a random string of letters and numbers. So I downloaded the audio file and listened to it, and it was actually a snippet of one of their new songs. So that was really cool. And then I just saved the string of random numbers and letters because I figured it was important somehow. So I started looking around the website some more, and I found that there was an image being hidden in the source code. So I removed the hidden attribute that was set, and it popped up on the page. And it was this blurred image, so you couldn't see it. So I started looking at the source of the image, and I noticed that in the source, there was a string of random numbers and letters that was exactly the same as the one I found with the endpoint that I ran. So I started looking some more at the, source of the image, and I noticed there was a dash blurred at the end of the string. So I just removed the dash blurred and ran the page again, and it popped up the unblurred image, which was the album cover of their new album that was coming out. So those were the two surprises that were supposed to be released once all the codes were found was a snippet in their album cover. So, of course, I sent the audio file and the album cover to my friends, and they all thought I was some hacking genius because, they don't really have technical background. So I got some nice street cred for that. I also tried to log back onto the website a few days later to see if that one code ever was found, and my account had actually been banned from the website. I don't know if they were able to log that I ran that endpoint somehow or what had happened, but I got banned from the website. Luckily, I have multiple emails, so I was able just to make a new account and get back on there. But, yes, that's
Speaker 3: the story of how I was able to look around and find some information about my favorite band that I was not supposed
Speaker 2: to find. Anyway, big fan of the show. You guys are awesome. Doing great. Love the new episodes coming out. And, yeah. Keep up the good work.
Speaker 4: Man, I love a scavenger hunt.
Speaker 5: I love a scavenger hunt that can be hacked. I love that. It's like I have a theory about that. This work, or I could just go to the website, dig through the JavaScript, find the callback, make the call, you know, dig into some of the some of the source code and and and solve it all for myself.
Speaker 4: Yeah. I think that every scavenger hunt that uses computers is secretly two scavenger hunts. There's the scavenger hunt, and then there's the armchair scavenger hunt version of it that just involves hacking apart whatever web portal they use to try and make it. Also, welcome to Hotline Hacked. It's a call in show where you can share your strange tale of technology, true hack, or computer confession. If you wanna share a story, go to Hotline Hacked. And if you wanna know who brings you this show, it's it's it's DeleteMe.
Speaker 5: Yeah. Check out DeleteMe. Join deleteme.com/hack. They're the people that sponsor the hotline hack series, and they're the reason why we're making more of these. And we love this show concept, and we love that they came aboard to make sure that we made more of them. So if you've got time, check them out. Join deleteme.com/hacked. But more on that later. Yeah. Let's let's dive into this a bit. I love the the part of the story here that's the real twist for me is the fact that they banned his account. So they must have been looking for people that are reaching the endpoint without the endpoint being reached. They still he still got the payout, but they they banned his account for it. And it it surprises me that in a, you know, what using his words as close as I can remember them, like a kind of a shoddy built website
Speaker 3: Mhmm.
Speaker 5: That that they had the ability to detect when somebody, you know, breached it. So that's surprising to me. That was the twist that was the big twist for me. Kudos to you for Yeah. For getting through it. I'm sure you broke some terms of service and stuff, but but, like, had your own scavenger hunt technical scavenger hunt.
Speaker 4: Always be breaking terms of service. I, there is about a decade ago. There was this trend in marketing and it was the gorilla marketing scavenger hunt. And just based on the timelines about this, I feel like this is when this would have happened. I remember there was a boards of Canada one. They did a a scavenger hunt to promote their record. I'm now starting to wonder if one of these I remember is the band that the caller was calling about. The famous one was Nine Inch Nails. They did a big Internet scavenger hunt that was a pretty big deal, like, I wanna say, like, 2008, 2009, maybe.
Speaker 5: Mhmm.
Speaker 4: That alternate reality game era of guerilla marketing. I always thought it was gonna go somewhere. I always thought maybe marketers were gonna be the first through the breach and that over the years, these things were gonna slip more into the mainstream, and we were just gonna have a puzzle solving culture. And everyone was gonna be, like, taking part in the puzzle same way as we all sit down to watch the episode every week. And it didn't really shake out like that. And this just makes me yearn yearn for what could have been. You know? Because I I don't know if I've said this. I love a scavenger hunt.
Speaker 5: Well, I know this was big in recruitment too. Like, I remember Google Oh, yeah. Got super popular and famous. Well, they were obviously already were super popular and famous, but their recruitment campaign And they posted just a billboard on the road to Silicon Valley that was like a puzzle. And it was like
Speaker 4: Mhmm.
Speaker 5: Some I can't remember. It was like a mathematicalequation.com, and you had to solve for this mathematical equation. So you had to write code and solve for it, and then you got to that website, and that website presented you with another puzzle. And then it was like Mhmm. Once you got through all the puzzles, it was literally like a, hey. Google might wanna hire you. Click this link, fill this information out. And, yeah, I remember this remember this marketing trend. Do you remember and this is a bit of a digression, not technical at all, but there was, like, a company that was doing, like, actual treasure hunts. Like, they would bury $50,000 in gold in the city, and then you would pay, you know, a couple $100 for the first clue.
Speaker 4: Mhmm. And
Speaker 5: their their anticipation was, like, if we could get enough people to buy the first clue, it would cover the prize, the logistics headaches, as well as a bunch of the other things. So there was, like, teams of people, like, running around cities trying to find this buried gold.
Speaker 4: That's a great idea.
Speaker 5: Treasure hunt.
Speaker 4: A a lottery with, like, more steps. And I that sounds like I'm dunking on it, but I'm not. I think those steps are fun. I remember for a long time, Cicada three three zero one was the, like, go to reference for weird Internet puzzle mysteries, which is a thing because of this show I spend a lot of time Googling. And it was online kinda in like the early twenty tens into the mid twenty tens. And it was this thing, I think it started on April. It was a lot of these, for example, the callers, involve going to a venue and looking for a code and maybe communicating with other people online to try and share it. This one was like deep cryptography, steganography, like you had to really be putting a lot of time and energy into it and the speculation was as you mentioned with Google that this was for NSA, CIA. One of these big orgs must be putting this on because it is far too involved. The other alternative being that this was sort of just another evolution in an earlier trend of like cipher punk type Internet culture. No one really, I think, ever totally cracked what it was. And I wonder if it was just promoting an album from, like, a late two thousands indie rock band. Can you imagine? Can you imagine how mad you would be? You spent years of your life trying to solve the greatest Internet mystery, and it's just like
Speaker 5: At the album art for a new album?
Speaker 4: Totally. I'd be furious.
Speaker 5: That's been out for, like, fifteen years. The Totally.
Speaker 4: Edward Sharp or something. You're like, God damn it.
Speaker 5: I do. I do. I do love this. This is like showcasing how far a fundamental set of technical skills can take you. Like, this reminds me of last, last Hotline Hack, the person that figured out how to call a JavaScript endpoint to come autocomplete their, like, training modules. Same thing. Like, a little bit of technical savvy in today's Internet based world goes so far. Mhmm. And it's It's
Speaker 4: that if statement. Totally. You you can do a lot with an if statement.
Speaker 5: Yeah. If if x equals 20, execute this. It's like, well, what if I just executed it now?
Speaker 4: Here's here's the new Gorillaz album cover or whatever it was.
Speaker 5: Yeah. Yeah.
Speaker 4: That's a great one. Thank you for calling in. We appreciate that one.
Speaker 5: And remember, if you have your own tails, visit hotlinehacks.com. You can actually call a real phone number. We have an actual phone number that you can call and leave voice mails then. Or you can send us an email with text and we can convert it to audio, or you can record something and just email us the recording files like that caller did.
Speaker 4: When this started, I thought it was gonna be someone confessing to the July of this year ticket master hack. They're like, I was trying to go to a concert. Anyway, 560,000,000 ticket master customers data leaked later. I found the album art. I was like, I thought for a brief moment, I thought it was going that way.
Speaker 5: I I suspect at some point, we're gonna get one of those phone calls, and we're gonna have a big discussion about whether we can run it. Being like, yeah. So when I took down the Las Vegas casino networks and it's like
Speaker 4: This feels evidence y. Yeah, the line between a call in show about hacking and just an evidence portal, is pretty blurry. Maybe never unblur it.
Speaker 5: And remember, if you'd like to disguise your voice, please do so prior to sending us the files. We do occasionally do it on the tail end, but, don't have that as an expectation. So Yeah. So please, if you're gonna send in something incriminating, take steps to disguise it so that we don't get forced into some evidence loop. Thank you.
Speaker 4: But don't hesitate to send us something incriminating. Yeah. For for for the stories. Like, we we're we're here we're in the story collecting and transmission business here. If you got a good one, I don't know, pitch shift your voice and send it in. We do wanna hear it.
Speaker 6: Hey. Love the show. I wanted to share a simple hack that's pretty basic, but something I'm still proud of. Back in 2002, I was in a computer systems networking program at a community college in Southwestern Ontario. We spent most of our time playing Counter Strike day and night in the student center. The only problem, we couldn't access online servers, and the local servers kept going up and down, leaving the community fractured, plus whoever hosted had to sacrifice their laptop's performance.
Speaker 5: As you do in college, you spend all the time using university resources and the high broadband Internet connection that the university has to play competitive for search and shooters.
Speaker 3: Mhmm.
Speaker 5: I identify with this.
Speaker 4: And the terrible truth is that whatever this caller is about to do to circumvent that system probably gonna prove to be almost as valuable as anything you've learned in a class when it comes to the real world.
Speaker 5: Yeah. I feel like he should have got an a in his program given what he's probably about to tell us he did. So let's I
Speaker 4: think we don't even know what he's done. This guy just said I liked Counter Strike. We're like, this motherfucker's up to no good.
Speaker 5: Well, he's been firewalled in by the university, so I imagine he's about to go around said firewall. But let's let's let's hear it from him.
Speaker 6: I came up with a pretty simple solution. The campus had a lab full of Windows 2,000 computers. And while IT had locked down the USB ports, they hadn't restricted the CD ROM drives. I burned the necessary files to a CD, copied them over to a lab computer, and set up a scheduled task to run the server on boot up in the background, completely unnoticed. We called it Mee Edumacation, and it gave us a stable, always on Counter Strike server that brought the whole community together. It was a simple hack, but it unified us and made for some of my best memories from that time. Anyway, you guys do a fantastic job with this podcast. It makes my long commute fly by. Keep up the awesome work.
Speaker 5: Well, I was wrong. I was wrong. Didn't didn't circumvent the firewall. You know, use a proxy or something to to bypass it or, you know, any of the other ways that you get around it. They just hacked one of the local massive computer towers and turned it into a dedicated Counter Strike server. Another great solution.
Speaker 4: Another great solution. I just wanna dwell on the name for a sec second edumacation. It's a perfectly cromulent word, which if you know if you know, you know. I I thought that was a Simpsons reference, and I'm googling it. Apparently, there are instances of that being used in early Popeye cartoons. There's instances of that being used. Yeah. I I thought that was purely, I I think it might have been in the Beverly Hillbillies. I thought that was a Simpsons goof. I think a lot of people probably thought that that's a Simpsons goof, and it's not. So I I learned something today.
Speaker 5: Then one of the parts that really stands out in this story for me is is how much he talks about the betterment of the community. Oh, I love it. It bringing it bringing them together. It's like he's hacking for good. He's he's he's made a bootable disk drive or disk and and essentially rooted one of the servers, and he's done that to bring the people together. You know, this is the Robinhood story, and I I I I respect and appreciate it. Thanks for calling in.
Speaker 4: Yeah. I really like that. The USB ports are locked. The CD ROM is not. You just wanna play some Counter Strike with the boys. I think this is community building. Yeah. I think that's what this is.
Speaker 5: Yeah. I think and and as a fellow Canadian, Southern Ontario University,
Speaker 4: you know Yes. Yes.
Speaker 5: Need one of us.
Speaker 4: The Canadian education system is is truly world class.
Speaker 3: Hey, y'all. So I've literally just found y'all today and found out about this hotline hack thing.
Speaker 5: Welcome to the show. Yeah.
Speaker 4: We're happy to have you.
Speaker 3: And I've got kind of a unique story of something I did whenever I was in the navy that I didn't really fully appreciate until I started telling some, other nerdy friends about it. One especially is a guy that just absolutely loves Linux, and he really appreciated this. So I figured I'd let y'all know too. So I was in Japan for four years. Not gonna say what boat I was on. It's not over there anymore, but, you know, just keeping it kind of anonymous.
Speaker 5: I just wanna jump in because when I was living in Honolulu and the first time I went to Asia, I flew from Honolulu to Japan, and I was seated next to two navy electronic technicians. And I'm wondering if this is not one of them, and they were an absolute blast. We had the best time on our flight. I've never seen the American respect for the military and how it gets you around certain rules. Interesting. Yeah. Oh, yeah. Like we sat down. We made introductions. I found out they were nerds. We immediately hit it off. They bowled out a crib board and a bunch of cards. Then they reached up into the overhead and started taking out their duty free booze and just ripped it out of the duty free bags. They they buzzed the airline stewardess, and they were like, bring us a six pack of Coke and a bucket of ice and some glasses. And they were like, sure, sir.
Speaker 7: Goddamn.
Speaker 5: And they came back with a bucket of ice and a bunch of glasses, and they just literally started making cocktails. And we just sat and played crib and drank from Honolulu to Tokyo. And it was they were awesome. It was it's like one of my one of the best flight memories I've ever had was sitting with these two electronics technicians for the Navy flying from Honolulu to Tokyo. So the second he he said he was stationed in Japan, I was like, could it be? Could it be? Could it
Speaker 4: be? Did did one of them have a really good southern kind of drawl?
Speaker 5: Yes. Yes.
Speaker 4: Okay. It's all coming together.
Speaker 3: So I was an I guess I could say it. An electronics technician in the navy for a while. And one of the things that I was in charge of was a communications set of gear that utilized the HF, VHF, UHF, SHF, and EHF bands for communications. We go out on a regular patrol, And during that patrol, we got hit up saying that navy red and navy blue wanted to use our ship for a training exercise. Well, we we're about three hours in, and I'm hanging out in the, for lack of a better term, command center of the ship while underway. And the operator started mentioning how some random I don't know how to say it. I was in tracks for the gear was just randomly popping up and disappearing, and how the, SHF and EHF. Actually, it was just the SHF side of the house, was acting really weird because having people come in and drop out of the net. And I didn't really think a whole lot on it. I knew that it was a a network issue inside the gear itself. So I went down and just pulled the CAT five cable out of the gear, which we go down on SHF and EHF. But at that point, they weren't the the, the links that we needed to keep up. So we're still up on HF and UHF and still doing everything we need to do. About, let's say, five to ten minutes after that, the navy blue commander came over to us and asked which one of us, turned off the SHF and, EHF, band, for the gear. And I told him that, you know, that it was me. It's my gear. It was actually screwy, so I just disconnected it. So that way, we wouldn't have any issues and could keep going with the exercise. What I didn't realize is I didn't even know it was possible, but Navy Red had gained access to the IP service or to the IPs on the SHS side and was getting access to actually mess with our radar. I didn't really think too much about it. I mean, I knew I did a I did I fixed the gear, but I didn't really appreciate it until, I told my buddy that and, you know, came up with the our little thing that we say to each other that you can't have the network if there's no network anymore. Just thought thought y'all would get a kick out of that. I'm not in anymore, so, I don't care to tell that story. It doesn't really comp security wise.
Speaker 5: It's like a the oldest rule in cybersecurity. It's like if you wanna stop a network attack, you just disconnect from the network. And it sounds like
Speaker 4: Just unplug it.
Speaker 5: So so I'm just gonna just gonna kinda give a little summary to anybody that's been following as as the best I can tell what's happening. So he's in Japan. They're on a boat. Navy red, navy blue, I assume, are the red team and the blue team.
Speaker 3: Mhmm.
Speaker 5: And so they're they're attacking and defending the ship. And it sounds like the red team had hacked in through certain radio wave band systems into their network. And he just trying to fix and maintain the system that they were utilizing for the boat operations just disconnected that network, essentially just disconnecting the red team's, like access.
Speaker 4: You can't hack a network if there's no network. So do we think that the band that was giving them the trouble? Like, they're they're on this boat and suddenly one of them one of these bands is acting kind of screwy. So I think you described as acting kind of weird. Mhmm. Figures there's a network issue. Do you think that's a symptom of the fact that they are being hacked at that moment? Like, do you think that it's behaving oddly because they're being hacked and he goes, ah, well, we don't need it anyway. Unplug it inadvertently, preventing the hack.
Speaker 5: Yes. I think that's exactly what happened.
Speaker 4: Amazing.
Speaker 5: It sounds that What's great. They were trying to use it to do to adjust the radar pitch. So they're trying to essentially disconnect the the comms for the boat, I would have assumed. So they're probably adjusting the communications to the back to the satellites, maybe, radar pitch. I don't know. I'm not I'm by no means a sophisticated navy operator, but but and then they they noticed that they were having comms issues, so he just disconnected the the feed from those lines and and essentially stopped the red team's hack in its tracks, essentially acting as the the champion of the blue team by just disconnecting them.
Speaker 4: You know what kind of clever on your feet thinking that is? What? The same kind of clever on your feet thinking that would lead a person to skip ordering cocktails and just ask for a six pack of Coke and a bucket of ice on the airplane.
Speaker 5: Yeah. Like, why why get drinks? And here's the other funny thing is that the booze on the plane was free. Like, it was a Transpacific flight, but it was like, nah. It's like I got my own Johnny Walker. They were good southern boys. It was it was a good time. Anyway, that's a long story.
Speaker 4: That that that's really, really good. The other thing I like about this is the insight into how naval games work. Mhmm. It was we go out on regular patrol and navy red and navy blue, an ungoogleable term because of the color navy blue for context.
Speaker 1: Of course.
Speaker 4: Navy red and navy blue wanted to use our ships for training exercise. Is that how this works? Like, you're just out doing navy. You're out doing navy, and these, like, alternate reality game people show up and they're like, we we we wanna do a thing for a minute. Can we? Like, is that that seems like it's very loosey goosey.
Speaker 5: I hate you know what, though? Like, I would assume aside from the fact that they probably like in real wartime conditions, you would just expect that people would be trying to muck with you in today's world. Right. So it's like, why why wouldn't you be out doing my favorite verb, navy ing and then
Speaker 4: Navy ing.
Speaker 5: And then and then have, you know, hackers simulate a red team, blue team situation where, like, the the defensive blue team has to, like, deal with these adverse attacks coming from this, like, hidden red team.
Speaker 4: Mhmm.
Speaker 5: Because that's probably very realistic to real world conditions.
Speaker 4: Right.
Speaker 5: Like, now that we like, I would say that, you know, regular warfare is now augmented by cyber warfare.
Speaker 4: That's fascinating.
Speaker 5: Great call. I, like, love getting a little myopic views into these different worlds that are generally quite Yeah. Mysterious.
Speaker 4: Yeah. All of that, please. Call call in haulinghack.com. I wish I sometimes wish that there was a way in the real world that I could unplug the metaphorical radio connection that is my identity on the Internet. But since you can't really do that, we should probably just kick it over and talk about the sponsor of Hotline Hacked. Our pals delete me.
Speaker 5: You're getting great. You're getting great at these transitions.
Speaker 4: Thank you. I appreciate it. I should by now. That one took a minute. So I you're being generous. Thank you.
Speaker 5: The, yeah. So again, just to repeat, you know, delete me, joineddeleteme.com/hack came forward and said, Hey. We love the Hotline Hack Show concept. We'd love you guys to make more of them and we'd love to sponsor them. So we are we'd love to have them and we love to make these shows and we love the content. It's It's always a great time to listen to your guys stories and if you have those stories hotlinehack.com please send us more content as we love it. Some of you might not know who DeleteMe is but DeleteMe kind of scours internet databases that data brokers use. So we've talked about data brokers in some of our previous episodes. So if you're a fan of the show you would have heard us talking about them. These data brokers keep personal information on people and then sell it. You know, your name, your contact info, your socials, your addresses, things that you generally wanna keep personal exist in these databases. And DeleteMe kind of scours these things. You can set criteria as to what you'd like removed and they will kind of scour these data broker sites and request removals of your information from these databases.
Speaker 4: A really bummer amount of all of our personal data is out there on the out there on the Internet for everyone to see. Your name, your contact info, your social security number, home address, even information about people's family members. As Scott said, data brokers. They're compiling it and they're reselling it online and pretty much anyone with the wherewithal can go ahead and buy it. This can lead to identity theft. This can lead to phishing attempts. This can lead to harassment, unwanted spam calls. Now, thanks to our sponsor, you can protect your privacy with DeleteMe.
Speaker 5: That's why I personally use it and recommend it. You know, they send regular personalized reports to you about what they found, where they found it, and what they removed, which is great because you get to actually see how much of your stuff is out there. And the other thing is it's not just a one time you push the button, it does it once. It's it's a it's a kind of a constant service that's running and it's constantly perusing these data brokerage sets and looking for your information. And it flags it, throws it to you, says, hey, we removed you out of this thing. So so it's kind of like a I don't know, it's kind of like your own blue team.
Speaker 4: So Well, naval blue team that'll that'll that'll unplug the radio that is your identity on the Internet. You can take control of your data and keep your private life private by signing up for DeleteMe. Now, the special discount for our listeners. Today, you get 20% off your DeleteMe plan when you go to joindeleteme.com/hacked and use the promo code hacked at checkout. The only way you're gonna get 20% off, and you want 20% off, is to go join deleteme.com/hacked and enter the code word hacked at checkout. Scott, play it for the people one more time.
Speaker 5: That's join deleteme.com/hackedcodehacked at checkout. Check it out. Thanks for helping us put on this show.
Speaker 8: Hey, guys. This is just an all around good story that, comes full circle with a little bit of that justice you love to get from, quitting a, bad company. So, about a decade ago, I was a junior DBA for an ecommerce company.
Speaker 5: Database administrator. Mhmm. I'll be the acronym translator.
Speaker 4: It means the world.
Speaker 8: And it was just me and, the senior DBA, Mike, we'll call him. And, Mike was paid very well. I was just a junior with a baby salary. You know, Mike was making three three and a half times, my salary. And so, as it goes, a you know, in the in the tech world, a private equity company comes and takes over, and, they tell my they tell Mike that he's gonna be, let go in six months, and, you know, they're gonna hire another senior DBA to replace him. So, they end up hiring somebody, and we'll call him Ravi. And, Mike or I never got to interview this guy. I don't even know what the criteria was, how many interviews he got. I don't know anything about it, but I can just tell you that this guy lied hard on whatever his resume said. I won't go into that stuff, but, like, he all I will say is he did not know how to connect to MySQL from a terminal. He had never used the the MySQL client on the terminal, and I have no idea how you can be a DBA, without doing that one.
Speaker 5: That that is shocking. But I I just wanted to flag that we have not had a hotline hack call for somebody who faked a resume and got a job they shouldn't got. That's true. That would be a great story. So if you've got one of those, please call in.
Speaker 8: I was just like, you know what? This is bullshit. I'm not going to train this guy, and when I know more than him and have him be the, you know, the senior, that's gonna be, you know, paid a lot more than me. So I asked my director. I I tell him this guy lied on his resume. He doesn't care. And so I'm like, well, I want 10,000 more dollars a month. And that was it, and they said no. So I said okay. And, I got hired at another company and quit, put in my two weeks. And so, you know, Mike is still training Ravi. And on the the first day after I'm gone, I don't know what he's doing. Ravi drops a table in staging, not prod. It was staging. But all of a sudden, Mike is just getting hit up from all the devs saying that, you know, tons of the tests and things are broken.
Speaker 5: So I'll be the tech translator here.
Speaker 3: Mhmm.
Speaker 5: So databases are full of tables. Drop is a SQL command to essentially destroy it. So he destroyed a table in staging, not prod, so not the the production environment, but the staged production environment where you're kind of evaluating new changes and stuff to the system before you promote it to production.
Speaker 4: I
Speaker 5: feel like I'm gonna have to do a decent amount of translating in these last three minutes, so please bear with us.
Speaker 8: And so, Mike messages Ravi, and he's like, dude, stop whatever you're doing. And once he kinda figured out that this table is missing and what was going on, he was messaging Ravi, and he was like, alright. Well, you know, we need to meet up to fix this. And he didn't hear anything from Ravi, and it was just crickets. So he, you know, re restored the table and, you know, carried on.
Speaker 5: So when you break the staging database, everybody that's developing the application would be using the staging database for final touches before it goes to production, and most of the dev team would probably not be able to work once that database is broken. Got it.
Speaker 8: Well, I I don't know if it was days or weeks, but, no one ever heard from Ravi after that. He just dropped the table and was gone. And, like, HR was reaching out, and so it got to the point where they were actually concerned about his health and safety. So someone from the company lived, close enough to him that they could drive over there, to Ravi's house. And so they, knock on the door, and Ravi answers. So I don't know, what was all said in that conversation. All we heard was that, Ravi said, oh, I sent an email, on that day to HR that said that I quit, but, you know, that that wasn't true. No one ever heard from him. So, that's the end of Ravi. And, you know, so now the the company says, alright, Mike. You can, you know, definitely interview and hire the next guy. So, whatever recruiting company, that they were using, you know, gave Mike a stack of resumes, and one of them was Ravi. So, I don't believe he got another interview. So it just it was great. It ended up you know, Mike was there for, like, another two years, getting paid his, you know, incredibly, high salary, and all I asked for was $10,000, you know, and and they couldn't give me that. So, I like to think that they were, you know, regretting it. So, that's my story. Alright.
Speaker 5: I swear he said $10,000 a month in the first pass, but maybe that was a mistake because it seemed like a like a hot Rick raise request, like come in and be like, I'd like an extra $10 a month. It's like that's like, I know tech has high compensation, but to ask for a ask for a 120 lift in your salary is a pretty substantial pay bump. But an extra 10,000 a year seems much more. I thought it was honestly going to go full circle and the recruiter was going to reach back out to him and be like, Hey, do you want this job?
Speaker 4: Me too. That's exactly where I thought it was going. I was like that it was going to be closing the loop. Exactly. That he was gonna get recruited for a new opportunity at the same company that he started out the story by quitting. But as he said in the beginning, justice you love to get from quitting a bad company. Sounds like maybe not the place you wanted to be working after all. To your earlier comment about us getting more calls about people faking stuff on their resume, this seems not the worst it could go, but to have your first day go so cataclysmically wrong that you just ghost the business, stop replying to emails, and go back to your house and pretend none of it ever happened is like, maybe that's why you don't lie about your resume on technical jobs. There's a lot of jobs you can lie about your resume for, but technical ones, they're gonna figure it out really, really, really fast.
Speaker 5: Yeah. Like the like like databases are complicated, but they're not like, you know, they're not like black magic. They are if you tried to build your own, like, from scratch, But just managing them and administrating them is, like, it's technical. But even then, if you can't even connect to a database from a console line, you should be nowhere near a DBA job, let alone a senior DBA job taking over for, like, the leader of the DBA team, from what it sounds like. Yeah, I can't believe. I can't I just can't believe, like, could you imagine, like, you know, there's a lot of talk about mental health and anxiety these days, and it's like, could you imagine the anxiety of being
Speaker 7: in a
Speaker 5: senior technical position and having none of the skills to do any of it? Even the junior role, you couldn't even have probably done.
Speaker 3: Mhmm.
Speaker 5: You lied your way into a senior position. And like, you're just like, I don't know what I'm doing. And I hit this button that says drop, and I don't understand what that means. And now it's gone. And I don't know how to get it back because it would be pretty easy to get it back potentially. But you just didn't know how to do that. So you just literally hit the log off button got in your car drove home and we're never to be seen from again.
Speaker 4: It's that it's that moment when he he drops the table in staging, and everyone, probably not knowing that that's what was happening, starts throwing up their hands saying, like, oh my god. Everything's broken. Nothing is working. People are running around on fire. Mike has to message you saying, for the love of God, stop whatever it is you're doing. That's the moment. Right? That's the moment you realize you you did fuck up. You maybe were eligible for, like, a junior job if that, and you managed to that. If that, and you managed to kinda, like, claw your way into a management role. You probably told yourself a nice story about, hey. It's management. I'll just be overseeing people. I'll I'll learn on the fly. Right?
Speaker 5: I learn I learn the language. I I read read the, like, database for dummies. Exactly. Like, I can I can talk about it?
Speaker 4: YouTube exists. I can stay one head, one step ahead. I can teach these piano lessons as long as I'm one piano lesson ahead of the student. It's not that kind of thing. It's not that kind of thing. And suddenly you're back at home, just ignoring calls from HR and, you know, answering wellness checks because you didn't show up to your job. It's, it's it's pretty great. Justice to borrow your term caller is is a pretty good term for it. They should have just just promote from within, guys. You know? It's, proven It's a tale as old as time.
Speaker 5: And, you know, speaking of promotion from within, we could talk about the new Nike CEO who started as an intern and is now the CEO. I saw that. Entire career promoted from within. There you go. Works for Nike. It can work for you. The the, yeah. Amazing. And and the fact that he's still out there looking like he didn't learn his lesson, obviously, if the recruiter's still sending his resumes out as part of the hunt for another senior DBA, like, is he just doing incremental training at the cost of companies?
Speaker 4: Right.
Speaker 5: Like that, it just seems like such a like, okay. I'm gonna go to this one. Mike's gonna teach me for a few weeks. I'm gonna destroy something. I'm gonna go, like, ghost out the back door, then Then I'll get another job somewhere else.
Speaker 4: I'll take
Speaker 5: the three weeks of knowledge that Mike gave me, and it'll make me a little bit more productive until I destroy something. And then I'll ghost out the back door. And just like doing this, like, passive, you know, technical diploma in database admin via, like, taking senior roles and working in them until he destroys something.
Speaker 4: This is how he does professional development. It's like some people learn by doing. Some people learn by being taught. Some people learn by destroying from on high and organization from within. It's like, wow. That's a very that's a very intense way of learning, Ravi. How is it working out for you? He's like, I'm I get two weeks severance every time I go into one of these places. It's going okay.
Speaker 5: Well, to the to the caller, like, congrats on getting a new job. Hopefully, you got a nice promotion. It sounds like you deserved it over Ravi. And it sounds like Mike, I think it was Mike was his name, his his manager, the senior DBA that was making all the money. It sounds like he probably got a really sweet deal out of it because I'm sure after you get your termination notice and then they're like, hey, actually we need you to stay around for two more years. I'm sure you get to even negotiate at that point. Now that they put themselves in such a pickle So you can take your extraneous salary and make it bigger. So
Speaker 4: nothing shows the value of a loyal Mike than a drive by Ravi. And if you have a story, a strange tale of technology, a true hack, a computer confession, a naval war game gone amok, we would love it if you'd share it with us at hotlinehack.com. You'll find the actual phone number you can call. You'll find the email address where you can submit text or an audio file. It's anonymous as you make it, but it would mean the world to us. We love hearing your stories. We love making these episodes. And as always, thank you to DeleteMe for for helping us do it. I think that I think that puts a puts a pin in another one, doesn't it, Scott?
Speaker 5: Yeah. I think so. I think that's that's it. So, yeah. Thanks DeleteMe. Join deleteme.com/hacked. Code word hacked. Check it out. And, yeah. We'll catch you next time. Please, again, hotline hack dot com. Send us some stories. We need these stories to make the show. We get a lot of great content. And if you've got a great one, we'd love to hear it.
Speaker 4: Catch you in the next one.
Speaker 9: Take this as your sign to go. Just get out there and go. This summer at Best Western, get 1,000 bonus points and a chance to win 250,000 bonus points. Life's a trip. Make the most of it at bestwestern.com. No additional purchase necessary for sweeps. See bonus point t's and c's and sweeps rules for details.
Speaker 10: You're great at protecting your data, but lots of places could still expose you to identity theft.
Speaker 5: I thought it was safe.
Speaker 10: If that happens, LifeLock gives you a US based restoration agent who will stick by your side from start to finish. Phone calls, filing documentation, preparing insurance claims, your agent handles it all. In fact, we're so confident restoration is guaranteed. Pour your money back. Isn't it nice to have someone like that on your side? Save up to 30% your first year at lifelock.com/podcast. Terms apply.
Speaker 7: You can't reason with the sun. Trust us. We've tried. This summer, it's time to put that angry ball of fire on mute. Columbia's OmniShade technology is engineered to protect you from the sun's harsh rays that can burn and damage your skin. The sun is relentless, but so is our gear. Level up your summer at columbia.com to spend more time outside and less time slathering on aloe lotion. You're welcome. Columbia, engineered for whatever.