Hacked - Hotline Hacked Vol 14
Episode Date: July 16, 2026We're so back. Another call in episode featuring strange tales of listeners hacking laundry machines, video games, 90's home computers and so much more. Share your strange tale of tech at hotlinehacke...d.com Hacked is presented by NordLayer. NordLayer is a network security platform for modern teams. NordLayer gives companies centralized control over who can access their systems, keeps every connection fast and encrypted, and requires no additional hardware or complex infrastructure. nordlayer.com/hackedpodcast Learn more about your ad choices. Visit podcastchoices.com/adchoices
Transcript
Discussion (0)
Thank you for calling Hotline Hacked.
Share your strange tale of technology, true hack, or computer confession after the beep.
Hey, guys, so this isn't the most technically sophisticated story, but I thought you might enjoy it anyways.
So this happened back in the 2000s, and I would have been 11 years old, and I was playing a game called Guild Wars.
and for those that don't know, that's kind of in the same vein as like World of Warcraft.
And my parents thought that I was planning way too much, rightfully so,
as I was waking up after they had gone to bed and sneaking downstairs to play for like an extra two or three hours.
Come on. Who hasn't done that?
I feel a nostalgic right now.
Let me just sneak on down the stairs to that family computer.
that makes like a jet engine sound when you turn it on.
And you're like, they don't know.
It's like they knew.
They knew.
It was terrible for you.
You knew your sleep.
Yeah.
Let's get back into it.
In this episode, brought you as always by our title sponsor, Nordlaer, the network
security platform for modern teams.
Tell you more about them later in the show.
Definitely not good for me.
So the first thing they did was they just started taking the power cord out of the computer.
and easy solution
just pull the power cord out
and I'll let them turn it on
the only problem is that the power cords are super easy to get
I wonder if that's where this is going
it's like I rapidly figured out that the like blender
that we use has the exact same power cord
that didn't last
that's very long because I would just dig through old computer stuff
find a spare power cable and then hide it in my room
to play when I wanted to
so then after that we
our house didn't have
Ethernet.
So we had a
Wi-Fi adapter for the desktop
and it was basically just
a little USB that plugged
into the back of the computer.
Poor kid had to play on like a
USB Wi-Fi adapter, the latency.
Oh my God. I feel like
they're about to take away the USB dongle
and you've gotten into a like, so
we had rats so we got a snake
and then we had snakes so we got a
mongoose problem type situation.
I'm really hoping it goes deeper and what he does is like runs Ethernet cable through the vent ducting in his house and like hardlines his computer.
And my parents would just unplug it and then hide it somewhere.
And I would always find it in closets, drawers, desks, cabinets all over the place.
So it was starting to become a big headache for my parents because it's like they have to limit me.
but at the same time, it's like, if somebody needed to use the computer, they needed to get the USB.
So if they hit it too well, it would kind of become a huge pain.
So one day, my dad comes to me and he hands me a login, and he's like, here's your login for the computer.
And I'm like, okay, head downstairs, turn it on.
And I'm greeted with the login for a program called NetNanny.
NetNanny, I believe, still exists today.
it is a program that it is used by parents to monitor online activity and also limit time.
So I log in and I'm like, okay, realize that I have a two-hour time limit and I'm like, yeah, okay, go to uninstall it.
Obviously, they thought of that.
Couldn't uninstall it.
Couldn't manually delete the files either.
So I'm like, all right, I'll play and see what happens.
two-hour time limit hits, obviously I'm booted off.
So I can't do anything on the computer anymore.
But I can still access the Nanny UI, so I'm going through it.
And I can basically, you can see the entire control panel, everything that the admin can do.
But if you click on it, the login pops up, says you need to be an admin, ask you to log in.
So I basically prodded, poke the program as much as I could.
I was like, okay, I'll just try to guess the password.
And every day for like a month or two,
I would literally just try to physically brute force the password.
A month or two.
So this is the beauty is like this is how hackers are born.
You face adversity, you figure out how to overcome it,
and then that just becomes habit to you.
Just sitting there banging your head against the desk,
trying to guess your parents' password to the net nanny software
so you can play guild wars.
This kid's going through withdrawal at this point because if he was playing 10 to 12 hours,
he was playing 10 to 12 hours a day and now he's being like a month and a half of two hours a day.
He's, I can't believe he has a stolen another computer at this point.
He's jones and at this point.
Yeah, I guess what?
I get why you'd be sitting there guessing passwords.
So without any luck, obviously.
And eventually I was like, damn, they got me.
like, I don't know what to do.
I can't get around this.
And then I was talking with one of my online friends.
We were talking about one of our friends that had gotten his account packed.
And they were like, oh, somebody installed a key logger on his computer.
That's how they got him.
They got his password and his email.
And, you know, I quickly start to connect the dots.
I'm like, hey.
I didn't see it coming.
I didn't see it coming.
It's a great solution of the problem that he's currently facing.
As long as Nettnanny's not going to stop him from installing a key logger.
Can you imagine being this kid's parents?
You're like, okay, we got the power cable.
And they're like, he figured out other stuff has the same power cable.
Fuck, okay.
The Ethernet.
Okay, he got around that.
We got a Wi-Fi dongle.
He found the Wi-Fi don't go.
Okay, we installed NetNanny.
The kid got a key logger to find our admin login.
Yep.
I think you just don't own a computer.
No, I think you just celebrate the kid and you support them in their journey.
You get them, you say, you know what's more fun than Guild Wars?
Writing code.
And we're going to put you in online courses and you're going to have a Roblox store where you
make millions. Yeah, truly. Where's this go? Let's find out. Keylogger steal passwords. I need a
password. Maybe this will work. So I, you know, Googled online, installed the key logger,
tested it out. It worked. So I'm like, okay, cool. Now the only problem is now that Net and Annie is
set up on the computer, there's not really any reason for my dad to log in again. Like it just,
it runs itself.
So I waited until a Saturday.
And then I ran the time down a bit.
And then I went to my dad and I was like,
Dad, I start this dungeon as soon as I logged on.
I thought it was only going to take two hours,
but it turns out it's going to take longer than that.
Could you give me some extra time?
And he's like, you know what?
You've been good this week.
Sure, you can have an extra 30 minutes.
So he goes, gives me the extra time.
I open up my key logger and just kind of in disbelief, I'm like, there it is.
There's the password.
Log in.
I'm like, oh my God, I did it.
You did it.
You did it.
You did it.
And no one can take that away from you.
Little social engineering, get dad to log in and give you a bit more time.
Pop up.
Key logger running.
Popper.
just want to game a little more.
This dungeon, daddy.
Gotcha, motherfucker.
Like it.
I love it. I love it.
Oh, it's great.
The big thing for me on that one is just like, that's how, like, that's just where the,
where the skill comes from.
You know, you get put in a situation where you're facing adversity.
You need to overcome challenges.
And then next thing you know, you're got a key logger on your family computer and you're
hacking your parents net in any account.
Is there any more to the call or was at the end?
That's the end.
Okay.
Yeah, I mean, I wonder when this would have been because that that Guild Wars came out in
2005.
So we're kind of in the heyday of like the MMO cultural moment where it's like people
are playing World of Warcraft for 10 hours a day.
Like that was a real moment.
Yes.
But like so which we didn't get back to until like the pandemic.
It felt like.
I don't know if that's statistically true,
but that's the vibe I get.
There was two big spikes of online gaming,
and it was those two moments.
I remember,
and this is like going a bit off topic,
but you bring up World of Warcraft,
and I remember just sitting down like 2006, 7-ish,
and just running the numbers
because it was a monthly subscription-based game,
so everybody's paying whatever it was,
$29, $39, $39 a month.
And then you've got like tens of millions,
hundreds of millions of players globally,
and I was like,
this game is just a cash machine.
Yeah, and Guild Wars was,
Guild Wars didn't have a monthly subscription.
It was one of the,
it was a weird one that you bought it cash.
If I'm remembering my 2000s,
MMOs, it was a cash game.
And I was like, that, that's a great way of doing that.
And then we weirdly kind of like looped all the way back around to like,
not only do you not pay a monthly subscription,
not only do you not buy it cash.
we're going to advertise the shit out of this thing for free to get you to play it for free
so that like 1% of you get addicted to, I don't know, pants in the game.
It's just a totally different economic model.
But at the time, that was really, really cool that they were like, no, you just buy it once
and you get to play it forever.
I don't play any games on my cell phone, but I had some flights recently.
And I was like, maybe I'll just take a peek and see what games exist.
There is nothing that's not free to play anymore.
like if you look at all of the top charts they're all free downloads with in-app purchases and you like every single game is built on that like that cash machine model now so the other day I bought it was a game from like 2013 I want to say I bought a copy of the game journey by that game company which is like an iconic game it's like beautiful it's a little piece of art it's the game people talk about when they want to make the case of games as art it's like that and shadow of it's like that and shadow of
the Colossus always comes up.
And I went to the app store and it was like, I wanted to play it on an iPad with a
controller.
I thought that sounded nice.
And it was like 799.
It was like, just press a button, give us $8 and here's a video game.
And I was like, chef's kiss.
Beautiful.
That's exactly what I want.
I was so happy to see that.
I think the biggest shock in that statement is the journey is from 2012.
That is so long ago.
It feels like that game kind of just came out.
I think that's when it's.
from i might be talking out of my ass it is no no i just looked it up
interesting i feel like anyway we shouldn't we shouldn't meander too much let's
get to more stories we'll get some more stories uh thank you for that call is it's a very cute
use of a key logger we've talked about key loggers on this show it's like the zeus hack like all
trojan like all of these different crazy big cyber crimes that turn around key loggers
and you just wanted it to game so thank you for calling appreciate it
I think a key logger is one of the most, like, under-discussed super powerful hacking tools.
Yeah, yeah.
Like, just the ability.
And, like, they're super easy to get onto computers.
Like, Bad USB was like a classic keylogger deployment.
There's so many ways to get a key logger on.
And once you have a key logger on a computer, especially, like, I remember, how do I frame this?
Allegedly, not me.
University computer labs, you know, you could often sneak a key logger into active memory.
And you could get access to other people's accounts.
Like it was just, like, they're such a powerful utility because they just literally give you in a,
in a challenge response security world that we're moving away from.
I'll say that.
But in the classic challenge response username password world, they were just, they're titans,
Titans of the exploit world.
I feel like the clipboard
has become a much more interesting surface
than the keyboard in the age of password managers.
It's like I never,
most people aren't typing passwords.
They're copy and pasting passwords.
So there's been like an interesting shift there.
It's like I wonder if this,
I don't know would work the same way in 2026
as it did whenever this happened.
But sure shit worked and whenever this happened.
Well, just to hang on that.
for a second. True password manager usage is the password gets auto filled directly into the
input box on a web page or whatever. Oh, it's not even a clipboard. You're not supposed to,
but so many people use it by going in and copying the password out and then pasting it.
And the other crazy thing is that you can access live data in the clipboard from JavaScript
in a web page. So if you had a major web page like New York Times.com and you have,
had a JavaScript injection on it that literally just copied the active clipboard components,
you would probably actually get a decent amount of passwords just coming out of people's
clipboards.
You probably wouldn't get the email credit.
We're getting into the weeds at this point.
But it's like, it's interesting.
Next call.
Next call.
Next call.
Hey guys, here's a few stories, starting from the late 90s narrated by Scott's better looking twin.
Ooh, better looking twin.
Ooh, I do appreciate your voice.
I feel like we come from the same nasly camp.
Yeah, I can't tell as of right now.
I'm going to hold out judgment.
Keep playing.
Back in the days, during the last two, three grades of primary school,
I started my career by hacking an online computer store
and moved the number delimiters one position on all items
to give myself a nice discount,
but still having prices that didn't stick out too much.
Kind of a brilliant move.
Number delimiter.
Delimiter.
So the period between sense.
$1,000. So if you were $100.99, it would become $10.00 and $9.0.10.
The $3,000 gaming PC becomes a $300 gaming PC.
The $6,900 GPU becomes a $690 GPU.
Okay. Exactly. Smart. Smart.
I feel like he's going somewhere else with this story, but I'd be interested to hear how he did that.
My thought was that if things are automated, their system would probably print a package list,
which some youth employee would grab and pack without inspecting it a lot.
I am from Denmark, so the currency was Danish crowns.
So, for example, I bought a disk burner, which I think cost it around 3,800 Danish crowns,
which equals to about 600 USD.
After the delimiter was moved one position, the price was instead 380 Danish crowns.
I also bought a bunch of burnable discs, a top-notch graphics card, and some other stuff.
the level of tech and security back then was laughable.
The web shop sent the product price as an URL query parameter when adding it to the card.
Whoa.
URL query parameter.
Help this make this make this sense.
Help this make this sense to me.
So, urals have question marks in them sometimes as like an end like you'll see like, you know, Google.com question mark.
Sure.
U equals something.
So those are parameters being sent to the web server via the URL that are then parsed.
So if the price is coming, like when you click on a product on an online store and it's like, you know, microtech.
dot net slash GPU slash 5090, quite like question mark, P equals 36,000 chrome.
Like the price is a variable in the query.
and you can just modify the query parameter, that would be very, very easy to do in the insane security flaw in whatever online store they were using.
Sure.
Does that make sense?
I think so.
Yeah.
I'm curious how that translates through into like payment and all that other stuff.
Yeah.
It must like overwrote it or something.
Or rather than referencing a product ID and pulling the details by that.
So you had to simply copy the link on the.
add to cart button, paste it into the Earl bar, changed the price, and hit enter.
Surprisingly, the order went through.
A few days later, the goods was delivered, and I never heard anything from the shop.
I tried to make another order a few months later, but it got canceled due to system errors.
So I guess it's good that they found it.
It's good that you managed to somehow snake a deal, but.
Yeah, your deal is probably how they found it.
Like, they probably were like, ah, ass.
We just sold this disk burner for $19 or whatever.
Like, okay, what happened?
A little month end reconciliation.
And they're like, how did we sell this for $20?
Yeah, who gave out the coupon code and then you go digging?
Huh.
That's a pretty good one.
I guess they introduced some manual order confirmation.
Smart.
Now, with one of the best disc burners available on hand,
I started raping my 56 key modem downloading MP3 music from Napster.
This is also making me feel.
Like a nostalgic.
Interesting.
Just a dial-up modem downloading MP3s, burning yourself CDs.
I found my, this is a tangent, I found my CD binder from when I was a high schooler.
Oh my God.
Just just felonies and not like just piracy.
Like just.
But felonies worth the volume.
Oh my goodness.
You would have thought I was like a prepper.
Like I was archiving for the end of the world.
If you really think about it, like as it, like Canadians are a bit different.
So we were thankfully, we had a different copyright law.
But we sure shit did.
I sure shit did.
The iPod, like literally everybody that had Gen 1, Gen 2, Gen 3, up to like the 80 gig, 160 gig, like classic iPods, like 160 gigs of almost exclusively pirated music was in the pocket of like 60% of society.
just a massive block of like provable felonies.
Oh yeah.
The sticker value.
Like you remember those commercials that like you wouldn't download a car like anti-piracy commercials?
Yes, FBI.
Just whole fleets of vehicles worth of music by sticker price.
Like I downloaded cars, brother.
Like there was a lot on that thing.
Even before the iPod, it was like I remember figuring out I never had a bougie enough CD player that it was an MP3 CD player that could
reap the files. You had to burn it to the timeline version. Yeah, yeah, yeah, yeah.
But figuring out that you could back up MP3s and still use them on a computer computer,
I was like, oh, we're off to the races. That means I can just have like records and records and records
saved a one CD. Very exciting. Car, a fleet worth of theft. Okay. Let's see where it's going.
At the time, the Absolute Music Albums was popular. They came out frequently and had the most popular
tent 20 songs of the period. So I copied the songs of these and found the disc album covers online
and printed them on the school's color printer. I now had a pretty good copy of the original.
I then started selling them on my school for 50 crowns each. Whoa. Okay, we just went.
We just crossed from like joking about felonies to actual felonies. Yeah, but like cute.
Like he's still in high school. Like come on. Like a kid like selling some like pop albums.
Yeah, he's like the nerdy kid that has the CD burner and the inkjet print.
and is just like, I don't know what Absolute is.
I'm guessing it's like we had those here.
I think it was called now music.
But it's the thing where they just take like the top charting songs,
license them, put them on a new CD, put the year next to it.
And you're a parent being like, I don't know what to get this kid.
50 corona is about $8 American now.
I'm not sure what it was back when this was going on, but just a little context.
There you go.
Probably substantially under what the store, because I remember like even when I was a kid
buying a CD of music was like a $20 purchase.
And that was back when $20 was worth like what $50 is now.
Yeah.
In stores the price was about $150, 200 crowns.
They became popular pretty quick and I sold like one to three copies a day.
My profit was at least 40 crowns out of the price of 50.
Pretty good business at that age.
And it was before no one really knew what it was.
and before the music industry set in towards piracy and so on.
Even the teachers didn't say anything against it.
I think I even sold some to the teachers as well.
A few years later, now with an ADSL connection,
I was playing Diablo 2, a lot.
After accomplishing several level 99 characters
and often being in the top 50 Europe ladder,
I started becoming a bit bored and wanted to explore what else I could do.
I started being active in blizzhackers in similar forums
and played around with various exploits and tools
that could manipulate the game,
for example, giving you a fully visible map always,
which would optimize your magic find runs a lot,
item duplication, and much more.
Unfortunately, Blizzard started becoming aware of this stuff
and began banning account or perform account rollback
so that, for example, duplicated items was removed.
Therefore, I was wondering how I could up my game.
This is an interesting thing.
I always find this interesting,
is when a game company knows that you're cheating
and their response is like the slap on the wrist equivalent,
of being like, well, you know, you shouldn't have got that win or that item.
So we're just going to take that away.
But like, you know, don't cheat again, please instead of being like full account ban.
Like I always find that interesting when it happens.
To me, it tells a story of like the scale of the problem.
Totally.
Listen.
If we went nuclear, we built the tool.
We figured out how to figure out that you're doing this.
And by the numbers, if we come down really, really harsh on everyone doing this,
that's a lot of people that we're going to kick out of this game.
So we're going to play ball.
Like I have to think there's a little bit of a like, wow, that would be a lot of people.
The jail is going to be real full if we start throwing all of y'all in jail for this kind of situation.
See, but as a game, so this is like this, I run into this and we've talked about this before with like online first person shooters and stuff is the cheating group is actually relatively small, I think.
but they're just so invasive and they cheat so hard.
They have like hundreds of accounts.
And if you're not hardware banning instantly,
it's like,
what are you doing?
Like the second somebody's caught cheating,
they're probably a prolific cheater.
Just hardware ban them instantly.
If they want to go buy a new GPU to like play it again,
then fine.
It's like they,
if the cost of entry of cheating is like five grand,
then rock and roll,
but like,
for the love of God,
like please i don't know i'm of the camp that like if you if you the second you start showing you're cheating
you should just be banned because you're ruining the gameplay for everybody else and i know that
the investment side of it like daily active users being able to show that like jordan in canada
has 1100 active accounts is like great for shareholder reports i was gonna say there's a reason to keep
that number yeah but it but it just causes people like me to just stop playing your game because
When Scott runs his MMO, it will offer no quarter.
Exactly.
Hardware bans instantly.
Spoofers will be busted and caught.
Everybody to the gulog.
It was still in the era of clueless people on the internet.
So I got a free.
DotK domain and uploaded a file to the server.
Wildly enough, it was a straightforward Windows executable file,
which was named as variants of, for example,
new working D-2 to Dupa tool, XA.
In reality, it was a Netbus Trojan.
I then spammed the file, Earl, and all-in-game lobby channels
and quickly started receiving emails with IP addresses of victims who had opened the file.
I would then...
Okay, the AI voice is butchering some of these acronyms.
Can we explain this?
He spams a URL with some kind of...
He registers a garbage domain, throws up a single executable file,
says that it's a great Diablo hack
and then spams it across all of the
all of the Diablo
what would be discords now
but Diablo web forums and stuff like that
for all the hackers
they all promptly go download this
blind to executable and run it
and it turns out it's just a Trojan
that just throws like a remote control
exploit on their computers
next to their computers
and have full access to everything.
I could even get live stream from their webcam
without, I think, the light indicator of the webcam turned on.
I had some great fun looking around in people's stuff
or watch their face on webcam.
When I randomly opened and closed their disk driver
swapped left and right mouse button,
after having fun with this, I started using it for my original goal
to see if I could steal some Diablo 2 accounts.
The issue, though, was that screen capture stream
wasn't a feature available
due to the connection speeds at the time, I guess.
And when starting Diablo, your username was saved on the login screen,
so you would only enter your password.
So if I activated key logging,
I would only get random passwords without knowing which user it was associated with.
There's a solution to every creative mind, though.
I found out that if I opened the victim's registration keys database,
there was an entry for Diablo.
It had a value of the last used username,
which is where the login screen would read from two.
So I copied the username to my local Teaks file and then I crashed their running Diablo game.
The victim would then start the game again and with key logger activated.
I now got the password for the username.
Any questions?
It's the first call, but bigger and scarier.
I just want to loop back to there's such a wild like reverse jump scare in that where like this guy has this software running on all of these people's systems.
has, if we're just sort of believing the stories it's presented, like webcam access and complete
system control, very spooky situation. And then the quote I wrote down was, I got back to my
original goal stealing Diablo accounts. And I was like, thank God. Thank God that's all you were
trying to do was this. Because there's a much spookier ceiling with like, anyway, I was basically
in their living room unbeknownst to them, watching them in the night.
night like the invisible man. I'm like, thank God you just wanted a game. Yeah, there's there's some
dark stories about people doing things with this kind of access and people, you know, doing things
to themselves. But we don't have to go there. The only thing that I think we touch on here is
so he couldn't see the screen, so he couldn't see their username or their like email address that
they were using to log in, but he could steal their password through the key logger. So,
he went into the Windows registry, which if you don't know, there's like a massive database in Windows that kind of stores all kinds of stuff, parameters, settings, you know, control, like it has everything in Windows. Like, lots of things can be tweaked and twisted in the registry. And it's a place where programs like Diablo can save like a cache of like what was the last username, like a cookie essentially to be like, when I open this up, pull this registry key and populate this field.
So he figured that out, figured out how to grab that last down username, would then crash their game, causing them to re-logging when he had the key logger on.
He would get their password.
A lot of big, but a boom.
He has their account.
Understood.
I then made my own game ready at the login screen with the username and password filled in.
I then crashed their game again, logged in, and changed the password.
No two-factor authentication existed back then.
Jobs done, you would think.
But good players has multiple accounts because of.
character limits or for security reasons.
So I left the key logger on and waited.
I could see the victim entering his password again and again trying to log in.
After realizing it doesn't work, they had the thought.
What about my other accounts?
They would now go through all of their accounts, typing usernames and passwords for each,
and everything ended up in my little account collection.
Some people was also kind enough to have a textie file on their desktop with all their account credentials.
To give myself some time, I would shut down their account.
computer and then log into each of the accounts and change the password. I quickly collected a
huge amount of accounts and moved all valuable items to my own mule accounts. I had several accounts
packed with, for example, Stone of Jordan Rings, probably the best item in the game as it was
mandatory for all character types. And a great item name for this specific podcast, too. I had hundreds
of all the best items in the game and started making a decent profit by selling them on eBay.
land parties was also a thing at the time, and I would have all expenses covered easily by swapping an item for a pizza and so on.
That's it for now. I can probably dig up some more stories, but that'll be another day.
Today I'm working as a senior software developer, which I probably wouldn't be if it wasn't for all the interesting computer stuff that caught me in the early days.
Sorry, but not sorry to all the victims.
Hopefully you learned a lesson and only had your Diablo account stolen and not your nudes, and not your bank accounts,
either. Well, maybe. But as I said, another day, another story. Thanks for a great podcast.
Oh, thank you. And maybe Stone of Jordan will be the name of this episode.
Oh, Stone of Jordan. Stone of Jordan.
I got to say that this, I think this is a classic tale. Like kids that get interested in this
shit get interested in this shit and they become kids like me and kids like my better looking
twin.
Yeah. I mean.
It's like, what more do you want at that age, right?
I think this call is cool because it's like that call took us from CD piracy of the 2000s through blizzhacks and a big escalation of like compromising accounts.
Totally.
But it's just like a person.
Remote access trojans.
Relentlessly to the point that they're deploying remote access trojans to like crack other people's Diablo accounts.
And it's interesting because it's like this guy now works in security and like no, it's like, oh, there's extremely valuable stuff on these systems.
that I had access to.
It's like it's a minor miracle that nothing worse happened given that people were just
deploying XCs.
They downloaded off of a hacking the video game forum.
Like it's a, that's an interesting one.
Oh, this still, this still happens, you know, like everybody's looking for some edge and
especially in games where they're not maybe as good at as other people.
And they're willing to do silly things like download random files from random places and run
them on their computer. And then next thing you know, their Bitcoin is gone. And it's like, well,
that's kind of the price you pay for doing dumb things. It's just very briefly. That was, I get why
you would use a, you know, text to speech and then an AI voice on that makes total sense.
Classic hacked, hotline hacked move to train the AI on some cocktail of our voices and have it
read back to us in our own voices. Funny thing about how.
this show is that people will regularly bring up the thing about computers. They find
weirdest or strangest or most interesting. When they find out you host a strange technology
tales show. And one of the most common ones is, did you know that people can fake your voice?
And I always have to resist the ears to be like, do I know? I have an email inbox that is just
not but people sharing their strangest secrets often in my voice. And that's just good fun.
and I appreciate it.
Yep.
And once again, this episode is brought to you by our title sponsor, Nordlayer, the reality
of running a modern team.
You know, your people are working from different devices, different locations, different networks,
and most businesses have no real visibility into what that looks like from a security
standpoint.
Nordlayer is a network security platform.
This goes ahead and fixes all that.
It gives you centralized control over who can access your company's system, lets you grant
or revoke access and set.
seconds, keeps every connection fast and encrypted, and does all of that without any additional
hardware or complex infrastructure.
You can verify users by identity, device, block malicious sites and risky domains, and stay
compliant without slowing anyone down.
It's built for the way teams actually work today.
Check it out at Nordlayer.com slash hacked podcast.
That's Nordlayer.com slash hacked podcast.
Thank you again to Nordlayer for their support.
Hey, Jordan and Scott. So first of all, obligatory, I really love the show. I discovered it about two years or so ago.
We love you too, buddy. We love you too.
And since then, I've been listening to every single episode available in my podcast player, starting at the beginning and working my way forwards.
So hopefully, no one else has had this story in the past year because I'm about a year behind.
But I guess I'll find out sometime in 2026 when I get fully caught up.
So I recently listened to a hotline hacked episode in which an Australian caller told the tale about how.
how they had gotten free payphone use by tricking pay phones into thinking that they had input a coin,
basically making a cha-ching sound and the payphone thought that it had been paid and connected the line.
That reminded me of how I used to get free laundry in college through a sort of similar but not quite the same trick.
So when I was in university, my last two years of university, I spent in off-campus housing,
living in an apartment building with some friends.
and this apartment building had multiple apartments in it.
And it also had a communal laundry room on the first floor for anyone in the building to use.
Of course, this laundry room did not have free machines.
You had to pay each machine for every single load you put through it,
because that's just how things are, at least here in the States.
There were two ways to pay for these machines.
You could either pay with quarters by cash or with a mobile app on your smartphone.
And if you use the smartphone, the way it would work is you would load money onto your account,
so the phone would have to be connected to the internet,
and you'd add it to credit or debit card,
load money onto the account,
and then you could use that account to pay every single time you ran a washer or dryer.
And what you do is you'd bring your phone into the laundry room with you.
Once you had your machine set up the way you wanted it and had your clothes in it,
you would select which machine to use in the app,
and you'd set the settings on the machine.
You'd hit a start button in the app.
It would connect with the machine.
You'd hit start on the machine.
The machine would talk to the app,
and then the machine would start,
and money would deduct from your account.
What I found was that if you hit start on the machine
and then immediately threw your phone into airplane mode
and disconnected from all internet,
the machine would still start,
but the money would never deduct from your app.
So what you could do then is completely close out of the app
and reconnect to the internet, turn off airplane mode,
and the money that you had supposedly spent would still be there.
I used this trick for about two years.
I loaded my phone maybe once or twice,
spent $5 or $10 or so,
and just use that $5 or $10 the entire.
entire time I was in that apartment building.
A shocking fault in the development of the app, but a brilliant bypass.
I'm slow clapping over here, brother.
I lived in an apartment building with a pay laundry system.
There's nothing you can do to those machines that I won't be in favor of.
I found that so annoying.
I was like, I pay to live here and I got to pay for my life.
I hated it.
The debit charging machine that you had to,
mine worked with a card.
You had to charge a card using a credit card machine.
You had to send money to this card and then tap the card.
I resented it every single time I did it.
I probably didn't do laundry as often as I should have.
They kept ratcheting the price up the entire time that I lived there.
If I could have done this,
I would have done this every day.
Like I'm so on side with you.
right now. The next part of the story could be horrific and I would probably have just so much
goodwill from me. Yes. Hell yeah, dude. I'm going to go. Actually, I'm going to save it for the
end. Let's hear what he's got to say. Okay, okay. It worked out great. Told some friends about it,
some friends who had already lived there before I moved in. We're a little bit upset about
they had a little bit upset about how much money they had spent on laundry, but at the end of the
day, they were grateful for this trick. I'm not sure if it's still able to be used today.
soon after that I moved into another apartment building in another city that had a similar system.
I don't remember if it was the exact same app or not.
I tried the same trick and it didn't work.
The machine just didn't start when I threw my phone into airplane mode.
So it was a little bit of stuff about that, but I guess at the end of the day, two years worth of laundry is good enough.
I'm content with that.
So I hope you all have a great holiday season and happy new year and look forward to listen more to the show next year.
Someone obviously came in at the end of last year.
we've got a like truthfully we have hundreds of submission sitting in an inbox so we're going to be
working our way through these yes but here here's my uh here's my old man analog to this being okay
theft is wrong even if it's laundry you wouldn't download a car go off king that's not at all
what i was going to say i was going to say that the back in my day back back in the day um so quarters
right?
Like laundry machines used to be a dollar in quarters or $1.50 or whatever and you had to put
quarters in.
Like a nickel, but more.
I'm familiar.
The in electrical boxes.
So those little boxes that are inside of your drywall that hold the hold your power plugs.
There's little round rings in them that used to be exactly the same size as a quarter.
Talk of like a washer.
Yeah.
Well, kind of.
They were like a plug that was like cut out of the side.
of these boxes, so you'd have to knock them out to run in conduit into the boxes.
Okay, understood.
So those plugs were the exact same size as a quarter.
They weren't the same weight, so any kind of like complicated vending machine system
wouldn't take them.
Phones wouldn't take them, anything that had any kind of control mechanism, but these
dumb washers just looked for things that were the right height to slide in.
Often, you could get them that were plugged out.
So they actually had a hole in the middle of them.
I was going to say, if you have a hole in the middle, you got a
string situation on your hands now.
So you take a little bit of dental floss and you tie our fishing line and you create essentially
four like yo-yo's essentially with the size of a quarter.
And when you slide it in, it clicks the triggers to say, yes, I've been paid.
And instead of the money falling down over the shoot into the bin, you just keep tension on it.
And when it slides back out, you take your fake quarters back out, but the laundry machine's
running.
But there's the old analog of it.
pretty good I never figured out a hack for my crappy pay washer situation I just like overfilled
it I think was probably where I ended up right it just like well probably just messed up my clothes and
my sheets and stuff because I think it's more damaging to the stuff you put in it um so I'm I
adore this I think that's good fun I think Jordan's all in I'm like free laundry laundry
Laundry is a human right.
We're pretty careful about like allegedlys and couching stuff for like, we're not that we're recommending you do this.
And I'm like, I'm on the verge of being like, get free laundry.
I don't get free laundry.
Maybe like a mom and pop laundromat type situation.
That's a small business.
I'm like, yeah, if you're going to go there.
But if there's one of these things in your building, go off.
Like do what you got to do, live your life.
A quick word from Nordler.
Right now they're running their summer sale with new customers getting up to 20% off annual plans through August 31st.
Why does it matter?
Threats are never out of office.
When your team is traveling, logging into work accounts from hotels, airports, you know, conference Wi-Fi,
the risk of your business access being intercepted or exposed goes way up.
That's the window fishing attacks and unauthorized logins is what they're waiting for.
Nordlayer is a network security platform that keeps your team protected wherever work.
happens. It encrypts every connection and gives you control over who can access that and
flags unusual activity across your network, all without any hardware set up.
Use the code NL Summer, 26 at checkout, or go to Nordlaer.com slash hacked podcast. That's code
NL Summer 26 at checkout, or go to Nordlayer.com slash hacked podcast.
running a small business is tough.
When it's time to get a loan,
it can feel almost impossible to find a lender you actually trust.
Big banks say no,
and the internet's full of sketchy offers
with sky high rates and fine print you can barely read.
Whether you need help covering payroll,
managing cash flow,
or investing in growth,
you deserve better.
That's why we recommend the small business marketplace,
Fondera, powered by NerdWallet.
It is a free, easy-to-use platform
that lets you compare
real financing offers from trusted lenders, all in one place. You don't need perfect credit to
get started. No spam, no bait-and-switch. There's personalized options that fit your business needs.
And here's the best part for a limited time when you visit nerdwollet.com slash hacked and fill out
the no-obligation form. You'll get VIP treatment and talk with a real person who moves all the
ins and outs of small business lending. Don't risk your business on unreliable lenders. Go to nerdwollet.com.
slash hacked to find the funding you deserve.
Fundera Inc. NMLS ID number 124.0038.
I'm super excited to tell you guys about one of our new sponsors.
We got a new sponsor and they're called Even Realties and they make AI smart glasses,
which sounds crazy, but they're actually real.
They showed up last week.
I got a friend that's had these.
They had the first version of these and he uses them for teleprompter when he does presentations.
I got these ones to do coding.
They have a full terminal integration into AI coding apps.
There's also an entire ecosystem of people that have made custom plugins of which you can control AI assistance, sports scores, news, weather.
There's a whole pile of uses for these things.
Even G2, our productivity smart glass is designed to keep real-time support right in your view.
With teleprompting, conversation support, real-time translation,
AI assistance and more, they help you stay on top of the work and daily life.
And unlike most spark glasses, they're designed to look and feel like premium I wear.
There's no camera.
They have a lightweight, 36 gram design that you can wear all day.
The more context you give, the smarter they get.
And they adapt to how you work and what you need.
If you want to learn more about even G2s, go to even realities.com
and see how everyday smart glasses keep helpful information in sight.
so you can stay productive and hands-free throughout the day.
And for our listeners, use promo code hacked at even realities.com to get 10% off the even ring one
and or the even clip when you add them to your even G2 order.
That's even realities.com promo code hacked.
Okay, so the next one we've got has a, has a tail to it.
Okay.
We were sent a story.
Oh, yeah.
Then we were immediately sent a thing being like, please delete what I just said.
didn't you? So we did. You're welcome. And then we finally got a resubmission that had undoxed
themselves in it, apparently. Apparently that was the concern because we didn't listen to the
original one. I haven't heard this at all. Yeah. Neither of us have heard this. This might not even
make the show. We'll see. Let's find out together. Let's find out together.
I'm going to take you for a trip. Let's go. So back in about. That is unlistenable.
That is unlistenable.
2011, 2012.
I was working at a one hosting company.
I can hear it, but do we want to do it?
Because it is madness.
Like they have put multiple filters on this.
It's very hard to tell.
Let's roll it for a second.
Roll it for a second and see if we could do this.
Yeah.
All right.
I'm going to see you for a trip.
Let's go.
So back in about 2011, 2012, I was working at a web hosting company.
So I feel like I'm going to do.
jump in to summarize.
Works at a web host, a lot of e-commerce sites, some WordPress-based ones.
The most popular one was Magento.
They dealt with it a lot on the customer service side.
They got pretty good with it.
Okay.
Was this before or after they worked for the Decepticons trying to topple Optimus Prime?
I'm just going to keep pausing and doing summaries so that if we have the option of just
not playing this entire audio file, but still to translate the story.
It will just sort of fade it down in the background as a talk.
I really, really genuinely do appreciate a person calling and doing a recording with their own voice.
I really appreciate that.
And I totally appreciate the need for anonymity.
And boy, did you achieve that?
Well, in the email thread, or the follow-up email thread, they mentioned that their boss had gone to jail and was in prison and stuff.
So this is, well, now I'm intrigued.
Yes, this has a tangible outcome.
Okay.
That they probably are still desiring that out of it.
for us. So let's see. Keep summarizing it, Scott. Keep summarizing it.
Do something really disastrous. One guy had to spend a lot of time on that one. That was a pretty
ridiculous stunt. But we got really good to seeing how a layout of a gentle really looks like
with the layer navigation and whatnot. And one day I was just chilling. So one day is sitting at work.
He opens Pirate Bay. Interesting website to go to at work. And on the top bar, there's a link to a
free something.
I think he said free Burma.
It was Burma, free Burma.
Yeah, free Burma.
I caught that, yeah.
Yeah, yeah.
Myanmar, for those of you who aren't living past 96 or whenever Burma became Myanmar.
The, and it turns out it's an e-commerce store selling hacks and T-shirts and a bunch of stuff.
So that's where we're at.
So he figures out that the store that he's looking at,
is Magento. He starts querying the directory structure as he's very familiar with it and determines
that the Mage file, which sounds like the site config file, is fully exposed. Just for my own purpose,
is Magento is an e-commerce platform. Yes, correct. Yes. Okay. So he is looking in this
mage file, sees that there's a ton of exposed database login information, all of the, all of the
access information is in there, some SSO.
configurations. And he notices that the database username is Root, which is classic database admin
super user, but also a Linux admin super user. He also has all the IP addresses for the database
server, the web host, everything. Is this for the entire e-commerce platform or just for the one
website being hosted on being directed to by Pirate Bay? The one website being directed by Pirate Bay,
not for Magento entirely.
Cool.
I say that that's not actually the root password of a server.
I'm just going to guess.
So he has the natural curiosity of if your username and password for the database is root and then a password,
then what are the likelihoods that the username and password for the server,
the host, the Linux host, is the same.
So now it sounds like he's roped in a colleague and has sent it to one of his colleagues
across the office saying, hey, here's the username and password.
to see if you can root this server quick, which is, you know, let's see.
And he says I'm in.
Yes, he is.
He says I'm in.
He says I'm in.
Who's in that server with you?
He said, there's just some dude from Romania.
He just said out, who is on his IP?
Okay.
So apparently it was the Pirate Bay's server, not just some e-com shop.
It was hosted on the Pirate Bay server.
and they just managed to backdoor their way into the Pirate Bay server.
They ran a Hu on the Linux box to see who else was in it.
And there was one other user from Romania.
And the guy who logged into the admin account didn't even know who it was.
I didn't even know what the server was.
It just got this instruction from somebody in his office being like, okay, can you get in here?
And apparently they've just rooted Pirate Bay.
And without getting into how you feel about that, the high five part was cute.
Really awesome
But being like
You know
Respectable as we are
We took a look at their lack of an HG access file
And rather than fix the problem for them
And have them never know
We simply open VIM or VI
And let a note in the root home director
Saying hey guys look at this
You should really put an HGT access here
Blah blah blah blah that's not you're in
So instead of
So once they're in
They realize what they've done
And instead of doing anything bad, it sounds like instead of fixing the bug that allowed them to get access to it,
they left a note in the rooted, root user directory explaining how to fix the hole that they came through.
Maybe we left them notes on how to do it in EngineX as well so they can hide these directories.
Anyway, the end of the story is like we were able to root into something that the fire may either owned or sanctioned almost instantly through shopping cart software.
and if we had gone any further, who knows what we could have found.
And we didn't care.
We don't want to get shanked by anybody on the dark web.
That's the story, and I'm telling it for two,
and I hope that somebody out there recognizes this.
And if you know anything about Wings,
you'll know exactly who you're listening to,
because Wings is a very, very peculiar word for.
a lot of us.
Hi.
Yes.
Okay.
Okay.
A mystery.
Do you say wings?
Yeah.
It said the wings.
It must be some code acronym for something.
So he was kind of like him doxing himself at the end, letting if somebody knows the story or worked
in the same place or was a part of the Pirate Bay at the time, maybe he picks it up.
Sounds like they were really gentle.
They hacked in.
They left the note being like, yo, your Magento install is vulnerable in these ways.
It led us to essentially rooting your box.
Here's how you should fix it.
Add an HD access here, ban, you know, access to these folders, et cetera, et cetera.
Which I think is the sweetest thing one can do when they hack a server.
Well, let's also think about the specific server they hacked.
I think it's probably our last call.
So let's dig into it a little bit here.
My mind goes back to the second or third call where they were like,
I'm on a forum, a blizzhacks forum where people are even inclined to download something to try it.
Meanwhile, this person has hacked the Pirate Bay, the website where you go to just manically download files that you probably shouldn't have and hope it's the thing that you're looking for.
So there's a world in which this person could have gone up to some real, real chaotic shit.
Not just at the people that run the Pirate Bay, but of like, what have just ever.
Everyone trying to download a torrent instead downloaded this.
A remote access Trojan.
Even if that runs for nine minutes or something before someone figures out what's going on,
that's probably a lot of compromises, I would bet.
Yes.
Yes.
You are not wrong.
Yeah.
Yeah.
Interesting.
I don't know.
It's got to be scary.
I understand why his back and forth and delete all this stuff now because.
Of course.
I don't want to get shanked by anybody on the dark web was his thing.
And that is probably the case.
You don't want to mess with people above your pay grade in that space.
But yeah, interesting, just classic, hey, we downloaded a new platform and we set it up so we could sell this stuff to raise money for Burma.
And we don't know anything about the configuration of the system.
And now, boom, we've just left a big, wide open hole in our security.
and now some random web service customer support people who sounded pretty technical.
Yeah.
Just walked into our server and are now like, hey, you guys have rooted your own box
and left your admin password exposed in a web file accessible by anybody in the world.
I wonder how often, that's not the first time we've had that narrative beat where someone leaves
the note behind.
Like we've made jokes about this before of like the night fox from Oceans 12, the little,
thing that the sleuth leaves behind sitting on the shelf as like a calling card.
I just, I want to get some calls from people that have been on the other side of that
where they got the polite note.
They were the recipient of it.
They're like, anyway, then I went in and I checked.
And there was the little text file being like, hey, we were in your house last night,
metaphorically speaking.
You have a lot of nice stuff in here.
And we could have stolen all of it.
So we got in through the dog.
door, you're going to want to go ahead and secure that somehow.
I want to hear the other side of that.
Is it classic, like they're back in the, back and back in the day.
Back in the day.
Back in the day.
We need to get onto a Unix box.
Like one of the first commands you run is like who, like who else is in here.
Is there other other usernames logged in?
Because you're all terminal, right?
You've come in through like terminals.
Yeah.
So you're like, oh, there's like a few admin accounts and a few user accounts.
Like if you were to be a part of like a university computer lab and log in
one of the Unix servers.
You run Hugh and you'll get like 100 people logged in.
But there's also another Unix command called Right.
So one of the OG things is like you jump onto a server, you do who's on it,
and then you just send them a message.
And it just pops up in their terminal.
Like root at this TTY says this.
And you're just like, it's like, hey.
It's just like, like, just, hey, I'm not supposed to be here.
And people are like, eh.
So, yeah.
It's like there's a note in your in the home directory for me for root go take a look at it.
Oh, that's like and then you're out.
Poof.
Poof.
Oh, that was a good call.
I'm glad we stuck with that one.
The voice was like, sorry if you were listening.
I don't know how we're going to chop this up.
If we'll play the whole thing or if we'll fade it down and have have Scott summarized it.
But I'm glad we've stuck with it.
That's a good story.
That is a good story.
I think that the big thing is is thanks to all the callers and people that have sent stories in.
Like I mentioned, we've got like another hundred.
to 250 to 200.
We miss doing Hotline Hacks.
We just haven't had the time.
We've had other interviews and stuff booked
where we've been kind of focused on that.
So today was just a great chance for us to do one,
so we're happy to do one.
And yeah, I think we're going to try and do one
a little bit more regularly because they are super fun.
So if you have an interesting tale story,
hotlinehack.com,
you have the ability to dial the 1-800 number
and leave us an up to five minutes.
repeat this up to five-minute message lots of people get cut off halfway and we can't use your
stories yes so so make sure that like you're not calling in with a massive like a novel for us we need a
sub five-minute tale should have a good start and an ending please do that for us and maybe your
your story will make it on the show or you can email in text and we can just you know uh run through
11 labs and turn you into an old British woman or one of us or one of us or one of us
I'm excited to be doing these again.
It's been like close to a year since we did it.
We did them kind of once a month.
It's really fun to be back.
And again, a big thanks to Nordlayer for their sponsorship of hacked.
Check them out at Nordlayer.com slash hacked podcast.
We got people doing CD MP3 piracy.
We got crazy pirate bay hacks.
We got a lot of good stuff this episode.
Thank you again so much for listening.
And we'll catch you in the next one.
Catch you the next one.
Hey, y'all.
It's Kelly Clarkson with Wayfair.
Ever order furniture online and wonder what if?
Like, what if it doesn't hold up?
That sofa was four days old.
You should have ordered from Wayfair.
With Wayfair, there's no what if.
Just style you love and quality you can trust.
Visit Wayfair.ca.
Wayfair, every style, every home.
