Hacked - Hotline Hacked Vol. 15 | The $500k Server Room Mistake

Episode Date: September 15, 2026

We return to Hotline Hacked with a server rack that shuts down a factory, a college library ignoring a keylogger risk, Claude unexpectedly finding its way into a recruitment backend, and a few hacking... stories that spiral in very different directions. Hacked is presented by NordLayer. NordLayer is a network security platform for modern teams. NordLayer gives companies centralized control over who can access their systems, keeps every connection fast and encrypted, and requires no additional hardware or complex infrastructure. nordlayer.com/hackedpodcast   Learn more about your ad choices. Visit podcastchoices.com/adchoices

Transcript
Discussion (0)
Starting point is 00:00:00 Thank you for calling Hotline Hacked. Welcome to Hotline Hacked. It's a call-in show where you can share your strange tale of technology, true hack or computer confession. Let's get to the first call. My name is Andre, and this is the story of how I accidentally shut down an industrial manufacturer for over 48 hours. It all started when we were scouting a new warehouse for processing. We found a suitable location in a massive industrial park, and a visit was arranged.
Starting point is 00:00:30 It was the usual corporate parade managers in crisp suits, looking as important as possible. I was there as the local IT guy, with my IT manager on the phone. While the delegation marched into the offices, I wandered off to check out the server room. To my surprise, there was a full rack of networking equipment, quietly humming alone. That was odd. The previous tenants had already left and, as far as we knew, taken everything with them. I turned to the landlord and asked, Hey, what's this for?
Starting point is 00:01:03 He squinted at it, shrugged, and said, I don't know. Not exactly reassuring. I can only imagine I would have just thought it was a Bitcoin, like an illegal crypto farm. That's what I would have thought. Somebody stealing some power and network connection from an abandoned building. Oh, yeah, I don't know what that is.
Starting point is 00:01:20 That's crazy. That's weird. I doubt that's what it is, given that he says he takes down a facility, but that's what have been the first thing through my head is like, oh, somebody's just like, mining crypto on somebody else's infrastructure. Crypto farm subterfuge in an industrial setting.
Starting point is 00:01:33 There's worse places. I think there's worse places to run that, not that we're recommending that you do that. Yeah, definitely not. Can you find out if it's being used for anything? I asked. A quick phone call later, he returned with, it's probably from the last tenants. It's not ours. So, you're okay with us removing it?
Starting point is 00:01:56 Absolutely. Do what you want. A few days later, we got to work. I had an excellent contractor from an MSP with me, and together we carefully unplugged and removed every last piece of equipment from the rack. We coiled up the cables, laid everything out neatly in an office, and patted ourselves on the back for a job well done. Fast forward to 9 p.m. that evening.
Starting point is 00:02:20 My phone ring. It's our general manager, and he is not happy. What the hell did you do? The landlord is blowing up my phone. Turns out, the warehouse next door was piggybacking off our server room for their antenna internet connection. And they weren't just any business, they were running heavy machinery processing. When we pulled the plug, their entire operation ground to a halt. No network, no processing.
Starting point is 00:02:49 By the time their IT team managed to Frankenstein it back together, they had racked up about half a million dollars in losses. At this point, I was sure. sweating bullets. I called my boss, fully expecting to be eviscerated, but he just sighed and said, Don't worry, we'll figure it out. A couple of days later, during a smoke break, I overheard that the landlord's company decided to pay for the damages out of pocket. They just wanted to keep the piece, and, as a cherry on top, they even gave us a little subsidy to cover the power requirements for the other company's server rack. So, in the end, everything was fine. But I did walk away with one very important lesson.
Starting point is 00:03:28 Question everything you see. And definitely, definitely question everything you hear. I got to say if I'm in charge of the IT infrastructure for a heavy manufacturing facility that requires internet to run. Uh-huh. Why would I not have an internet redundancy
Starting point is 00:03:49 plan? Uh-huh. Like the world exists now where for $50 a month, you can buy a cellular redundancy for your network. You can get a starlink for a little bit more money. You can get dual lines. The fact that you're piggybacking a half a million dollars a day, give or take, I'm assuming in lost revenues, a facility that makes that much money off of a piggybacked internet connection that you borrowed from your neighbors is shocking. Yeah, there's that you don't have a redundancy. It's that you're running it off of a piggybacked setup that's physically
Starting point is 00:04:27 located in your neighbor and that the people at your neighbor don't seem to really know that. Because this all starts with the people there being like, yeah, we don't even know what that is. It's probably a subterfuge crypto setup. You should definitely spend a whole day unplugging and getting it out of here. It's like there's, there's, it's like a real Swiss cheese thing of just a problem falling through the holes one after the other after the other except all of the holes are kind of dumb like totally the thing for me they're really like that that just seems insane like if you if you're if you require internet to operate like say they're running i don't know plasma cutters or something that needs yeah i want to know what these machines are continue continue
Starting point is 00:05:13 if internet is a requirement you should have a redundancy backup plan to not draw like for something that's like a hundred dollar a month patched to save a half a million dollars a day in revenue seems like whoever is in charge of your IT systems or the chief information officer, whoever the person at the top of that pyramid is, just give them a bit of budget and let them do their job. Because the fact that you guys didn't even have your own primary line that you were using like microwave connection to the building next to you is madness already, let alone not having multiple connections to ensure that if something does happen, your entire facility doesn't stop. working. There's like a thing people say, I'm not an IT, but with any like mission critical tech, like if you're going filming the memory cards, if you're recording something, the cables and the mics and the computer is two is one and one is none.
Starting point is 00:06:09 That's the sacred rule for that kind of stuff. Yeah, yeah. You only have one of it. It's like you have none of them. And if you have two, that's kind of like you have one. So how many should you have? Probably three. Oh, I'm, I'm the worst for that.
Starting point is 00:06:21 When I think of an internet connection for a machine that's like those plasma cutters chug through gigabytes every day or whatever this equipment was, that's a real two is one and one is none type situation. And I even mean like a cheat backup. I want one of those like undersea cables that connects play. Like it's just a fat fiber optic cable bolted into the side of the building with like an armed guard. And half a million dollars a day come on. And I guess another shock to me on this one is, is, is.
Starting point is 00:06:51 that the landlord agreed to pay for it. Like they're, they're essentially borrowing, like they had previous permission, I would assume, borrowing a previous entity's internet, that previous entity left. And they somehow think that they still have access and rights to it. Like they didn't start planning and fixing and build a redundancy and put in their own infrastructure after their neighbors who were kind enough to lend them internet left. Shocking. Shocking.
Starting point is 00:07:20 Did you watch Breaking Bad? Yeah, who didn't? Who didn't? Spoilers for like a decade old show. A big part of that is them trying to find Breaking Bad for the unfamiliar. There's a show about a high school teacher who cooks meth. And at one point in the show, they're trying to find a place to do it. And they end up in like the basement of, I can't remember what it was.
Starting point is 00:07:39 It wasn't a laundry map, but it was like the basement of an industrial setting. Yeah, I think they've made like soaps, like industrial cleaners or something like that. Some like that. I just remember a big like piece of machinery that got like till. it up and then they went downstairs. Anyway, what I'm trying to say is I wonder if this actually is the crypto version of that. Where it's like, yeah, we got industrial machines that need internet in the back and no one was like, what industrial machine? And it's just crypto farms.
Starting point is 00:08:04 It's just like a weird underground crypto farm stealing energy from something else. Yeah. Breaking bits. Breaking bod. Actually. Right. Oh, old term to refer to data transfer. over networks.
Starting point is 00:08:21 Okay. Okay. Deep cut. Welcome back to Hotline Hacked. We didn't do one of these for a long time. We did one recently. People loved it, so we're back to do another one. This is going to be the first one that's on video.
Starting point is 00:08:32 Welcome back. Welcome back to Hotline Hacked. Hallline Hacked is brought to you, as always, by our title sponsor, Nordlayer, the network security platform for modern teams. We're going to tell you more about them later in the show. Thanks to NordLayer. If you want to share your call, please do. You can submit audio via hotlinehack.com.
Starting point is 00:08:49 just goes to an email. If you want to be kind of old school about it, and we should think it's cool when people do, you can call. There's a phone number on the website, 18888-288-289. Go check the website in case I read that wrong. We'd love to hear your calls, text, audio.
Starting point is 00:09:07 You can also send us just text. We use AI voice to put any notes in email if you want us to obfuscate your voice, do anything like that. I think this next one up came in as a text entry, which we just cranked out with one of the AI voice agents and, you know, real easy to hide your identity. Hi Hacked. Big fan of the show here. Love your work. This hack happened some time ago. I was attending a small college in the Midwest and one day on a weekend I wandered into the library. I was looking
Starting point is 00:09:36 for a very specific book, the second book of the Mars trilogy by Kim Stanley Robinson, as I recall. and for reasons I can't remember, I had chosen a computer kiosk in the depths of the basement to conduct my search. I knew it was a long shot that the library would have this book, but when I had logged on to the kiosk with my school credentials and my search of all available databases proved fruitless, I was slightly irritated, all the same. Right about then a thought popped into my head. Might the city's public library have it? I reached up to the corner of the screen, but of course it was a kiosk. they weren't going to give unrestricted browser access on a library search computer. And right then, almost by force of habit, my fingers flicked out and pressed the fateful keys.
Starting point is 00:10:21 Control, shift, escape. If you're unfamiliar with Windows operating systems, this particular key sequence opens up task manager, a utility to view and kill any processes running on your computer. Way back when I was a kid, my dad had actually taught me this shortcut as a way to escape Minecraft, when the program was not responding. Sure enough, task manager popped up, and right there, I could see all the processes running on the computer, including the apps that were maintaining the kiosk. Now, I've been listening to your show since late high school when I first started getting into hacking.
Starting point is 00:10:56 You've told enough stories about credential theft and the hazards of unrestricted network access that I knew exactly how bad this was. You see, the computer itself, a Windows 11 system, was connected to the campus network via generic credentials rather than a student ID. Malware attacking the network internally from this computer would be completely anonymous. He's right. I'm wondering where we're going here, though. It started out so simple.
Starting point is 00:11:24 It was like I can terminate a process. I was like, chill. No fuss, no must. Let's just keep it simple. Now I'm like, okay, where are you digging? Now he's like, I got general network access and I can launch malware at this entire institution. from this terminal kiosk. Let's go and see where it takes us.
Starting point is 00:11:45 Moreover, the exploit I'd found gave internal network access to anyone who entered that library, not just students. And it gets worse. Remember that just earlier, I logged in, the library catalog itself had a basic search engine. But the library website also had a bunch of cool features
Starting point is 00:12:02 that would integrate your library search engine into J-Store and Iliad, big repositories of scholarly work that required credit. The school's tech department had solved this integration problem by having students themselves log in using their school credentials within the library kiosk. The same credentials that they used to access their school email, make tuition payments, the works. A key logger on this machine would be really, really bad. I knew I had to report this to someone, but there wasn't really an obvious place. I knew a guy who did audiovisual work for the tech department, so I reached out to him and asked the best place to report a cyber vulnerability.
Starting point is 00:12:39 ability. He told me to just email the help desk with the details. So I did. Well, I got an email back saying thank you very much, etc. And a few weeks later, I happened to be back in the library, and I tried it again. It still worked. So I followed up with the help desk. This time C-Cing the person in charge of library technology, and this is what they said. Thanks for bringing this to our attention. After conferring with other staff, we have concluded that the user logged in to the library search workstations is not a user with admin privileges. Therefore, although task manager is available, and while tasks running as that user could indeed be terminated, the overall operating system should be, barring some unknown vulnerability, protected from a bad actor by Windows privilege separation
Starting point is 00:13:25 measures. Please respond back if you have any questions. Well, you can imagine my response to that. I'm a pretty competent programmer, and I knew that I could bang together a decent keylogger on my own, just for the heck of it. Though, I decided to write the dumbest Trojan that ever was. I love the spite hack. Yeah, there's like a, you can hear knuckles kind of cracking in the background. It's like we, you get the email back being like, hey, we reviewed this. For reasons, A, B, and C, you're wrong.
Starting point is 00:13:55 The overall OS should be okay. And it's like there's already clacking in the background. I'm like, yeah, no, it's totally locked down and secure, as I'm sure we're about to hear in the last minute of this call. I copied some Python to log keys off of Medium.com, and I got ChatGPT to write me a Python script to email a string to a hard-coded Gmail address. I threw this all together, sloppy as Trojan you've ever seen in your life, just to prove my point. Then I compiled it into a binary, created a new, empty user profile on my PC, stuck the executable binary on a USB stick, and plugged it into my computer. No alarms. There's this directory on Windows, where
Starting point is 00:14:34 any executable placed in it gets run on startup. I clicked and drag my little Trojan in there and restarted the computer. Sure enough, as soon as I started typing, I started seeing my keystrokes appear in that Gmail account. I'd just prove that those privileged separation measures were just about useless. I reported this further back to the library tech guy, but he informed me that they'd already spoken to the tech department about the issue and that there was nothing further they could do.
Starting point is 00:15:02 This is classic. classic yeah just oh it's like it's like the we're okay like it's windows 11 it's logged in with an non-admin user it's no big deal and they don't see that like every student in the university logs in there with their private credentials and probably professors oh yeah and this person saw that and said it would be really easy for me to like bang together a quick key logger that like mirrors all key inputs into you know he sent it to gmail i probably would use something real time, like a messenger. But,
Starting point is 00:15:37 but, yeah. I just love the, it's the, it's like a tale of the old time. Thank you for your call. This is a good one. Yes, thank you. Great call. I, I love the like, hey, thank you for letting us know something is wrong. But no, it's not.
Starting point is 00:15:51 And then you're like, I'm pretty sure something's wrong. And they're like, no, we ask the guy who knows of stuff is wrong and it's not wrong. And then you're like, I'm pretty sure it's wrong. In fact, I, I, I kind of exploited the thing that is wrong. to prove that it's wrong. And they're like, as we've said before, nothing is wrong. And it's like, well, I guess this is just how these kind of things happen is a bunch of people very confidently say there's nothing wrong until someone that isn't just like trying to kind
Starting point is 00:16:17 of like blue team, like trying to like prove that there's a problem here. It's like all it takes is someone who's not a good actor to come along and really definitively prove it. Yeah, exactly. That's the thing for me. it's like the, I would have the same output as he did. Like, I would see that as a massive vulnerability. The fact that I can get system level access just gives me access to do all kinds of stuff,
Starting point is 00:16:43 even if it's not in a privileged account, even if I can just walk the network, even if I could just strip the credentials that allow me to walk the network from a, like a ghost device that I set up. Like, there would be a million ways to take something like that and turn it into a serious security vulnerability, let alone like, no, it's not a big deal. Like we don't care if somebody hacks into the non-administrator account on this computer. It's like, okay, great. It's still a computer that people are plugging their credentials into,
Starting point is 00:17:11 and those credentials lead to email inboxes and payment systems for the university and grades and like privileged private information. There should be like a big red button. So many of these calls we get are from like campuses and universities. And also it's really cool that you've been listening since high school. Yes. I'm a thousand-year-old. man.
Starting point is 00:17:30 It's, but it's really, really, like, there should just be a big red button that you can just go and press and, like, boop it and be like, it's a big IT problem. Like, all of these calls are just people trying to report IT problems on their campus and everyone being like, no, those keys scanners work great. And then someone just, like, does it with a credit card or something. It's like, we need, need a big, like, break in case of IT emergency protocol on, on university campuses. So I'm, uh, I think I might chase this with a little story of my. own in this regard. Welcome to Holland Hacked. Welcome to Holland Act.
Starting point is 00:18:05 Let me set the picture. It was about three months ago. I got a LinkedIn message, a recruiter out of New York. You know, I came up in a scouring of the internet of people that they might be interested in working at a frontier AI lab. Sends me this message says, hey, you know, if you have any interest, get back to me, blah, blah, blah. First thing I do, I grab the message. I throw it in Claude. And I'm just like, is this credible?
Starting point is 00:18:30 And if it is, look at their client lists and other job postings to figure out what Frontier lab they might be talking about. Is it anthropic? Is it an anthropic? Is it an A.I? What is it? So I just pipe it into Claude. I go away and cook lunch.
Starting point is 00:18:45 I come back and Claude has, I don't want to say hacked their entire system because it didn't, I guess you would call it a modern hack. but their vibe-coded recruitment system had left their super base, like their database and authentication backend service, cloud service, had left a key for accessing their entire database in the source code. And Claude picked this key up and literally went into their back end, found the exact job that they were emailing me about, pulled the client file for it,
Starting point is 00:19:24 and was like, it is anthropic. This is the role. Here's the things. Here's the comp values. Like it gave me all of the details. And I was like, whoa. Like I just asked you to do a little bit of like.
Starting point is 00:19:38 Robot. I went to go make a sandwich. Yeah. What did you do? Yeah. I asked you to do a little soft research and like see if they had any other frontier labs in their job postings and their active postings. And instead, you found your way into the back end of their system. And then it started telling me it's like, well, I'm looking at the applicants table.
Starting point is 00:19:55 but I probably shouldn't share it because it has a lot of like personal protected information in it. And I was like, yeah, don't share that with me. Yeah, don't share that with me. I literally screenshot it and just sent it back to the guy who owned the recruiting company who had message me, never heard back. So if you're listening to this and you're that person, but yeah. Fix that shit up. Whoa. Fix that shit up.
Starting point is 00:20:19 So an inadvertent hack. Yeah, it's kind of interesting to be sending a. It's like, what does it mean to send an email to a person that will probably have an agentic system review your email and climb up the ladder of vulnerabilities that may or may not exist? Totally. Be really careful sending that email. Well, the other thing, too, like, I didn't dig into it because I was like, I don't need to get into this. Like your hands are literally. Yeah, my hands were like this.
Starting point is 00:20:46 You're like, dog, I didn't, I didn't do. I don't know anything about hugging face. I had nothing to do with it. This was not the intention. But I was like fired on the message. And I was thinking to myself, I was like, you know what? Like the fact that I haven't heard back is bad because it probably means that they haven't fixed it. Because anybody in their right mind would be like, oh my God.
Starting point is 00:21:09 Like especially because it came from the CEO. And like we had had a few messages back and forth. So it's like if the first thing I would have done when I saw that is like freaked out, told my IT team and had it sealed up immediately. Because I could probably go into the applicants table, bump myself up to a priority, whatever. A applicant, pushed me to the top of the recommended list. Like, I could do all kinds of stuff. I could delete other people that were applying for the job. Like, it had full back-end control of their recruitment platform.
Starting point is 00:21:35 And I'm just like, I don't understand how you get here in today's world. Like, if, if Claude, I'm not talking like Claude, look at the source code for vulnerabilities here. Yeah, yeah, yeah. I'm not talking about doing like a like a red team exercise. I just simply ask Claude to figure out who the, who the front, which frontier lab it might be. And it literally, like, took control of the entire back end of their company. And that was just, like, $19 a month, Claude. You gave it one of those, like, monkey paw, like, well, technically there's some ambiguity in your question of what you've asked.
Starting point is 00:22:07 You didn't say how to do it. So what I'm going to do is. And then, like, the CEO's, like, smart home fridge doors being thrown open or something. Like, a smart fact is cooking across the floor in another building. Totally. There is something funny about people. if you had done that and bumped yourself up the queue, there's something funny about like,
Starting point is 00:22:27 oh, how'd you get this job? And it's like, well, funny story. Yeah. The, I do have one more knock on to this because kiosks are always a boatload of fun for people that think in a cyber secure way because none of them are ever secured. Traveling, Jordan, you travel, I travel.
Starting point is 00:22:46 I traveled in an era where there was like internet cafes that you didn't have cell phones on you full time. like you had to go use computers. There were, you know, backpacker hostels would have like a computer that had like, you know, a fixed internet connection, but it wouldn't let you off of anything other than like their hostel networks booking page or something like that. Sure. And I used to just rip through these computers because often they would have some form of search
Starting point is 00:23:13 functionality and you would just feed it a search for essentially a local file system file like Explorer.E. it will return you like we couldn't find anything, but it would turn it into a hotlink or if it couldn't, you would just go in and inspect it and then turn it into a hot link. And then when you could click on it, it would literally like launch file colon slash slash,
Starting point is 00:23:34 you know, C Windows, explorer. It would just open Explorer, which gave you full computer control. So even if they had task manager locked down, you could like bypass it that way and then open up your own instance of Internet Explorer or like do whatever you wanted really at that point.
Starting point is 00:23:50 And it just kind of kiosks are just maybe one of the most security vulnerable things ever because I don't think anybody thinks about security when they set them up. They think about like the idea of security, but they're never secure. It's like it's not security. It's like a it's not a door. It's like you know like the gate arm that goes up and down to stop a car from driving through. Yeah, the rubber one. It's like the rubber one that goes up and down and you're like, I can. go around that or under that or over that. It's only because I'm in a car and I don't want to
Starting point is 00:24:25 just drive right through it. It is only in that way that it is gesturing towards security. It's a polite request. It's a polite request. It's like, please don't drive through me. And it's like that's what those systems kind of are. I think for people. It's also fun. I'm assuming you were doing it quite casually, but you can imagine someone having that moment in a backpacker hostel in the 2000s or 2010s kind of hacking into the thing and meanwhile there's the like hungover Australian manning
Starting point is 00:24:54 the front booth being like that Canadians hacking the computer again and I simply couldn't give a shit that is precisely correct Hey guys so I got a hack story for you I guess wouldn't really call it hacking the program VLC obviously used to connect to other people's computers
Starting point is 00:25:12 typically with their permission as long as you have the password and the IP address you should be able to connect and log in. So I helped my girlfriend at times with her computer, and I wasn't living in the same city, and I had installed the LC. It was a Friday, and I was on my way to go visit for the weekend. So before I left, I wrote a little note on her computer
Starting point is 00:25:32 so that when she got home from school and opened up her computer, she would know that I was on my way. And I don't know, I didn't think there would be a big deal, really. So I wrote the note and then made my commute, which was about two or three hours. In that time, I guess she got home, and saw this note and was pretty panicked. Both her and her roommate had a guy living down the street
Starting point is 00:25:51 in a house who was, I guess, a little bit creepy at times. And so they thought maybe this guy broke into their window in the bedroom, got onto the computer and left this note behind. What the note said was, this is your friendly neighborhood Spider-Man. I'm watching you, and I'll see you soon. Something like that anyways. Maybe I even said XO. I can't remember. But they ended up calling the police and made a report
Starting point is 00:26:15 accusations that I guess this guy probably broke in, so maybe they, police talked to this guy as well. And then I arrived after this point, I guess maybe an hour later, so I show up and start hearing about all this news of commotion. Someone broke into the computer and left a note, and I was like, oh my God, what are you talking about? So yeah, I almost got criminal charges. The police didn't charge, you know, once they found out the real situation. But they were tempted to press some type of charges against me. So lesson learned, even if you have access on VLC, you may not want to leave a note from Spider-Man.
Starting point is 00:26:54 I think he might have mistaken VLC is like a media player. I think he's talking about VNC, which is kind of a remote access system. So I think just a small clarification, but I think that's it. I was so that whole time, like partway through when he was like, anyway, I was leaving and I had access to my girlfriend's computer. I'm like, is this a good call or a bad call? Like I was really worried this was going into like, I accidentally invented stalkerware direction.
Starting point is 00:27:23 And to your credit call with that is not at all what was going on. This was a very human, normal, reasonable error. Except for maybe the phrasing of your note. If I give polite feedback, I'll be seeing you. I'll be seeing you in the night when you don't know I'm there. He's just trying to be cute. He's being cute.
Starting point is 00:27:44 He was being cute. And Spider-Man maybe was like a cute. I'm guessing it wasn't a cute nod, but I totally get it. I was tense this whole time because that's the kind of thing I would do. And it inadvertently scare someone where you just, you're not even thinking of it. Like I really relate to you on that one caller. I'm like, oh, I could totally see accidentally leaving something very cryptic. Jordan's very cute so I can see him doing this.
Starting point is 00:28:08 I'm adorable. What can I say? Um, I want to know what the cops would have. have charged you with because it's like what did you do wrong? Yeah. There was confusion. But you didn't and you didn't frame the neighbor.
Starting point is 00:28:24 You weren't like exo, exo, your creepy neighbor. Like there was no, none of that going on. No. Yeah, I don't know what they would have charged him with. Like, because he, if he had access and permission to have access. Yeah. That's not. Totally.
Starting point is 00:28:39 Like they would charge it. Like, I guess it all comes from the hysteria of the random note, which. I guess when you're trying to be cute and it comes across. Well, I guess it probably all spawns from an anxiety about this unknown entity that lives down the road that they don't like. Yeah. Because I'm sure if they didn't have that in the back of their mind, they wouldn't have compounded so quickly and turned into like a phone to the police being like, oh my God, we're being stalked. Totally. And like to her credit, it's like that would be stressful.
Starting point is 00:29:05 If you were having a thing with like this like weird dude down the road and the vibe is bad, like empathy for that. That would suck. and then you get this note and you don't immediately connect. You're going to want to really put like a cute pet name or like an inside joke or something like that in that note to clarify. But in the absence of that, they just sort of like put two and two together and go, oh my gosh, oh no, he's in the house. What are we going to do?
Starting point is 00:29:33 Call the cops. Crazy call. Interesting call. Thank you for sharing it with us. Anything else? I should we jump into the next one? I think maybe we take a little break. A little water slide.
Starting point is 00:29:47 We're going to rip down the water slide. It's going to have twists and turns. It's a little lads. We're going to change clothes. And when we come back, some more calls. This episode is brought to you by our title sponsor Nordlayer. The reality of running a modern team, your people are working from different devices, different locations, different networks.
Starting point is 00:30:09 and most businesses have no real visibility into what that looks like from a security standpoint. Nordlare is a network security platform that fixes that. It gives you centralized control over who can access your company's systems, lets you grant and revoke access in seconds, keeps everything connected, fast, and encrypted, and does all of that without any additional hardware or complex infrastructure. You can verify users by identity and device, you can block malicious sites and risky domains,
Starting point is 00:30:37 and you can stay compliant without slowing anyone down. It's built for the way the teams actually work now. So check it out at Nordlayer.com slash hacked podcast. That's Nordlayer.com slash hacked podcast. Thanks again to Nordlayer for their support. Hi, Jordan and Scott. My name is Vincent, and I'm by no means a hacker, but let me tell you about the time when my dad, of all people,
Starting point is 00:31:07 nerds sniked me into doing some harmless hacking. My dad would play Counter Strike all the time. This is early 2000s, and at the time, Counter Strike was not even its own game yet. It was a mod of half-life. My dad would host his own games, and he would partly fill the room with bots until people would join in.
Starting point is 00:31:30 This way, the room would not look empty. Buts were not common at the time, so you had to use a separate mod to run counter strike bots. Each time a player would join the game, the mod would send a message saying that bots in this room are from name of programmer. And this message was bothering my dad, because first, it would immediately tip off players
Starting point is 00:31:55 that there were bots in the room, and second, it was explaining somebody else's name, not his. At the time, I was still at university. I was doing computer engineering. So my dad asked me, can you change that string of text displayed when people joined the game? What good is it to go to uni in computer engineering
Starting point is 00:32:17 if you can't even change a string of text? And there you have it, I'd been nerds knifed. While the moral of it bothered me, I thought it would be a quick and easy job. Just tweak the string by editing the DLL directly. So I located the DLL, used by the mud for the bots and I opened it in a hex editor. There I could see all the compiled machine code, but also all the strings of text used by the
Starting point is 00:32:47 mud. I thought a simple search should do it, right? So I search for the welcome string and I don't find it. I skim through the DLL contents trying to find blocks of text and I finally find something. The author of the mod had intentionally, intentionally left a string in the DLL for people like me missing around with it. It was some profanity, basically nice try, you jerk. That's when I thought, challenge accepted. My first thought was, that guy has probably encrypted the welcome string with some basic encryption scheme.
Starting point is 00:33:25 I bet it is a simple substitution cipher, where each letter is always replaced by the same one. Since I know the string I'm looking for, it makes it way easier to break. For example, if I search for the word welcome, there are two E's in there at positions 1 and 6. So I should be looking for a sequence of bytes where those at positions 1 and 6 are equal. You can always tell a real programmer by the fact that they consider the first letter 0, because like array indexes begin at 0. So when he says positions 1 and 6, he knows that the W is 0.
Starting point is 00:34:00 It's just a small thing. Like if you talk to somebody that's an engineer, you can pick that up right away. start counting from zero in a character string. That's good. Exactly. Imagine now that I have a full sentence. There will be many, many more repeated letters and so many, many more constraints on possible sequences of bytes that could represent the welcome string. I then proceed to write a C++ program that would sift through the DLL machine code looking for a sequence of bytes that would satisfy all those constraints. I run the program and there are only three spots in the DL that could match. Very promising.
Starting point is 00:34:38 I then change one byte randomly in the first spot and launch the game. Nothing happens. I try again with the second spot. The game crashes. Okay. Finally, I tried the third spot and one letter of the welcome string has changed. Success! So it was a substitution cipher after all.
Starting point is 00:35:00 I then manually associate each encrypted letter with the corresponding decrypted letter, which allows me to change. the message to whatever I want, as long as the string stays the same linked, because it cannot shift things around and compile code. And there you have it. My dad was happy. I felt good to have solved the puzzle, but also kind of bad, especially when I saw my dad lie about being the creator of the bot in the new welcome message. Oh well. So that was my harmless hacking story. Love the show, and greetings from Montreal. That's hilarious.
Starting point is 00:35:40 Greetings from the West Coast. Greetings from Western Canada, our fellow Canadian. Thank you for calling. That was a good one. I like that. That's a good story. Mostly,
Starting point is 00:35:50 I want to talk about the tech of this because I think, Scott, you were probably following it a little more closely than I was. Sure was. I got the simple substitution ciphers side of things,
Starting point is 00:35:58 but I just, it makes me happy anytime I hear someone say nerd sniping. I think that's such a great phrase. Like I think I know a lot of people where it's just like, if we just dangle this really interesting technical challenge in front of you, like your knuckles crack, you're off. And it's like both a it's a useful thing and a like liability where it's like we're going to lose them for 45 minutes. Yeah, or 45 hours. 45 hours if it's a hard enough challenge.
Starting point is 00:36:26 So I like that. Thank you for putting that back into my brain. The couple things here for me. Well, I know you want to dig into the tech, but I just want to talk about how great Counterstrike was. Sure. Great game. When it launched the mod, we used to play it all the time. And multiplayer had our own servers.
Starting point is 00:36:45 I never really played competitively, but considered it. Killed Olfmeister a few times in ranked matches. And if you know anything, you know that. If you know, you know. I don't know. So what's that? What is that? Olivmeister was like one of the top.
Starting point is 00:37:02 CS pros in the world. I felt we found ourselves in a rank game once. And the first, I just was like, is that the real Olfmeister? And somebody was like, yes. And I was like, and then I just killed him and I saw on the hill feed that I'd killed him and I was like screenshot.
Starting point is 00:37:19 And then I'd like, the next round came out, killed him again, screenshot. And I was like, and then he left the server. And I was like, that's insane. Like I, uh, yeah. Anyway, that's my counterstrike tale for the day. Get that printed. Yeah, exactly. Get that framed put next to the, the Guinness World Record.
Starting point is 00:37:36 The United States is going to say you put it in next to that. You put it on the bathroom wall if you're like me. Yeah, exactly. That's awesome. Uh, text side. Dig in. Text side. I just want to understand like what exactly the other.
Starting point is 00:37:48 So this, whoever had made this bot mod for Counterstrike had set it up so that whoever deployed it, their name was associated with it and the little message popped up for everyone. Apparently the name thing wasn't quite even working, but. basic idea was there was a little alert to everyone who joined and the caller's dad didn't want that alert to come through. So they nerd snipe their own son, cool, into helping them out. Love it. And what is the like, what is the tech of what he did here in order to get into it? It was like there was a little bit of security, but it seemed like it was really simple encryption.
Starting point is 00:38:26 Yeah. Well, so let's back it up. So that sounds like the bot came as a precompiled DLL.L. which means that you don't have source code. It's been generated. It's been compiled. It's put into binary. So essentially, you get a compiled executable.
Starting point is 00:38:41 A DLL is like a library that can be like side loaded into a Windows application that essentially is pre-compiled for speed performance, etc. It's not interpreted like a Python script or something like that. It's been compiled. You can open up compiled things. So to jump back to the Miko interview, Miko and I both have like similar origin stories because one of the first things that got me into computing was like bypassing security keys and product activations in software.
Starting point is 00:39:07 Like you download a video game off the internet and you'd need either a key gen. And if there wasn't a key available, what you would do is you would open up the software in a hex editor, which would allow you to essentially look for any kind of strings, stay strings inside of compiled code. So you would find a place where it asked for the product key. And then you would kind of source out where the authorization occurs. So there's usually a challenge. So when you hit like activate, it calls a function which then returns true if it is activated or false if it doesn't.
Starting point is 00:39:45 And essentially you find that instruction that says jump to this to either like jump never. So it auto approves or like you can do small changes. You can reroute it there towards the, yeah, this guy bought the software outcome. So this guy did the same thing. So they opened up the DLL and he looked for the string, couldn't find it and was shot by it. So then he was smart. But he did find the like, you know, go F yourself string. So he knew that the person probably knew that somebody was going to do this.
Starting point is 00:40:18 And what they did was apply some form of cheap encryption, which isn't really encryption, like a substitution cipher. Like rot 13 is the biggest one, right? like in the in our alphabet there's 26 letters so if you just take one and jump it 13 places you kind of can encrypt things in a very easily unencryptable way that's probably what this person did they might not use rot 13 but they use some other form of substitution cipher so they took the welcome message and applied some cheap substitution for it the hardest thing that this person did was write a piece of C++ code that goes through the binary to look for any of the spots inside of the binary that this string could exist, probably just based on string length, number of characters, et cetera, et cetera. And then, yeah, so then once he found the right string, and the fact that there was three places, I wonder if two of the strings were the same, because what they might have done was written an authorization or like a test, like make sure that this string is this string.
Starting point is 00:41:25 so they have it in there twice and like a bit of a back end. So when it crashed on them the ones, it could have been failing some internal check. Because if he went to the limits of applying a substitution cipher, writing a PFO message inside of the code, there's a good chance that he then also doubled down and wrote like a check to make sure that that string never gets checked. So you would have to change it in two places.
Starting point is 00:41:53 So that would be my guess. So I don't know if you understood that if you have any, if you didn't. No, I got the bones of it. It's interesting. Yeah. Huh. And so also his dad could, I wonder if he removed the message or if he changed it to something. Yeah, it sounds like he changed it to his dad's name, which is like, I like that.
Starting point is 00:42:14 A copyright infringement. Yeah. Why not? It's a bot in a counterstrike lobby. The stakes couldn't be lower. Totally. It's very, it's the, it's the, it's the, are you winning? Sun meme.
Starting point is 00:42:26 You know which one I'm talking about? Like with the dad's saying the door of the movie. But it's like it's kind of flipped a little bit and be like, am I winning and it's like hacker's something like moment moment? Momentarily. Yeah, give me one moment. I'll make you win. That was good.
Starting point is 00:42:38 Violent threats against executives are growing at an alarming rate. When a company experiences backlash, executives are the first people blamed. When their address and other personal details are sitting online, this backlash can lead right to their front door. The team at Ironwall knows it's better than anyone. They protected some of the most targeted executives and individuals on the planet for almost two decades is a white glove enterprise security service. They protect your people with continuous personal data removal, proactive prevention tools, and human-led emergency support.
Starting point is 00:43:13 So when someone goes looking for your executives, Ironwall ensures they hit a dead end. Here's what to do. Go to ironwall.com slash hacked. Fill in the quick form and request your free risk assessment. Their team will show you just how exposed your executive. are and how to lock it down before a threat reaches their front door. That's ironwall.com slash hacked. Learn how to stop online threats before they become real world attacks.
Starting point is 00:43:39 Links in the show notes. Teams using Notion move faster, cut friction and costs by consolidating tools and staying aligned. In Notion, your docs, meetings, projects, and more all live in one connected database system, where AI has the context it needs to help you do your best work. It's seamlessly integrated, infinitely flexible, and beautifully easy to use. Because everything lives together, Notion has the context it needs to answer questions instantly, automate busy work and keep work moving. It's AI designed to strengthen teamwork, not replace it. With over 100 million users, Notion is trusted by 98% of the Forbes Cloud, 195% of the top 50 AI companies, including OpenAI, Cursor, lovable, and more.
Starting point is 00:44:26 Learn more about how Notion can support your business. at notion.com slash hacked. That's all overcase, notion.com slash hacked. Try Notion today, and when you use our link, you're supporting the show. Spotify, it's Jay Shetty. Are you one of those media strategy people? scrolling through spreadsheets, searching for an audience that pays twice as much attention to your ads than they do on social?
Starting point is 00:44:54 Let me introduce you to fans. And they're here with me on Spotify. Trust me, I know fans. They don't skip, they stay for hours. They don't move on, they manifest. They're not a demographic group. They're fans. Spotify advertising.
Starting point is 00:45:11 You're among fans. Hey guys, my name's Robbie. I live in Australia. Absolutely love the pod. And especially the hotline hacked episodes. I get so much excitement when a new episode dropped and saddened when I've completed listening to each as I sit feverishly refreshing my podcast app.
Starting point is 00:45:33 awaiting the next episode. That's far too kind. That's really sweet. Thank you. It is, though. Yeah. That means a lot to us. Anyway, I've been wanting to call into your hotline hacked for a while now,
Starting point is 00:45:44 finally got the time to do it. I don't really need to obfuscate my voice, but thought I would have a play with AI voices anyway. I've always been interested in everything tech since I was a kid, always messing around with computers and seeing what other things they could do, other than the conventional word processing and internet browsing, I'd also always have a side hustle growing up, whether it be building and selling PCs,
Starting point is 00:46:09 a bit of web design in the mid-90s with horrendous gifts and crazy colours, or creating and selling polyphonic ringtones and operator logos for Nokia's at school. And it was a side hustle that I thought would be a good story to send through to you guys at Hacked. Having grown up alongside technology, I was also very much into the games consoles that were released throughout the 80s, 90s and early 2000s. As with all tech, I wanted to see what else they were capable of, so I learned how to hack or chip almost every console I've ever owned. I remember spending my electronics classes at secondary school,
Starting point is 00:46:47 equivalent to high school in the US, soldering chips for the PS1, and then installing them as another side hustle. Anyway, fast forward to the late 2000s, where I had been travelling around Southeast Asia and Australia for the best part of a year after finishing uni. I liked Australia so much that I wanted to live there, so I was working back in the UK to get the money together
Starting point is 00:47:10 to head back over on a more permanent basis. At the same time, I had acquired, and was playing my way through various games on, a Sony PSP. In true Robbie style, I was intrigued as to how difficult it would be to hack the PSP and what it was capable of. Unfortunately, there wasn't a great deal of info online at the time, and certainly not a complete guide. So using what I could find, I managed to stumble my way through,
Starting point is 00:47:37 firstly having to identify the model of PSP I had, as well as the firmware it was running and which motherboard was inside it, before downgrading the firmware and then successfully hacking it. Once hacked, it could boot into any firmware version of my choice and run home brew software. It could also play copies of games from the memory, memory card that were of course, hmm, hmm, backups of games I owned. Once I had worked my way through this,
Starting point is 00:48:04 I thought I would be a good Samaritan and document the whole process, so others could do the same. So I wrote a pretty comprehensive guide on how to identify your PSP's firmware and motherboard model, and then how to downgrade the firmware and install devhook. I called it an e-book and put it on sale for five pounds on eBay. It kept getting pulled down.
Starting point is 00:48:26 by eBay for breaching their T's and Cs, but I kept putting it back up. I sold enough copies to pay for my first visa to Australia, which I have since turned into Australian citizenship. I've now got a lovely Aussie wife and two little Vegemites, which I suppose in a roundabout way is thanks to hacking. P.S. I have attached receipts. So can't confirm. He did attach the entire guide to how to attack or hack your PSP. So that is here. I am looking at it right now.
Starting point is 00:49:00 We've gotten a lot of great calls and this isn't to malign any of them. Like truly. That just on like an emotional level, that one might be one of my faves because it hits this trifecta of, like it's a cute, sweet, nostalgic story at the end and then honestly
Starting point is 00:49:16 like hacking these types of game consoles to hear someone use chipped as an adjective like warmed my heart. I haven't heard that, you know, a minute. I remember that. I remember the friend that had the chipped Xbox where you could go by like archive data disks of like just a bunch of ROMs. Or like I had a buddy that had a PS2 that was chipped and he had a hard drive with a bunch of backups of games on it. I miss that era. I get why it's moved on, but that's pretty cool. And that you were doing that on a PSP while backpacking around Asia trying to save,
Starting point is 00:49:52 up money and you cook this up is very, very good. I had a chip PS1. Did you? Yeah. Nice. I had to go to a grocery store to get it chipped. I won't say the name of it. Yeah.
Starting point is 00:50:08 Yeah. Like a central, a city center kind of grocery store. Yeah, sure was. Heck, yeah. You go to the service desk, get your PS1 chipped. Yeah, I think I know what you're talking about. Yeah, I'm sure you do. I love the story from a different thing because I feel like this is an origin story for an entire industry now.
Starting point is 00:50:28 Like if we look at Anbernik and Retroids and all these new consoles. Retro emulators. Yeah, but they all now have new operating systems. Like you can buy one of these devices and if you don't like the OS that it comes default with. You can like Ambernicks are famous for like you'll buy one and they kind of come with this OS that's kind of good. but it's like there's much better ones. So like one of the best ways to get onion running on it. Yeah, exactly.
Starting point is 00:50:52 Yeah. Totally. So you were the entry point for what is now, I would say, like a social norm in people that use these retro game emulators. So that's really cool. It is the coolest part about it. I like that a lot. As a fellow Australian, which I am, a citizen, welcome to Australia. I don't live there.
Starting point is 00:51:14 I would love to. It's beautiful. I love to come and visit family there. might be coming there in the next 12 months. So if I'm in town, if you play golf, we should go get a round in. But, but yeah, welcome to Australia as an Australian that doesn't live there. Welcome to Australia from the west side of Canada. Canada, exactly.
Starting point is 00:51:36 Your constellation of interest is great. You got chipped consul. You've got polyphonic ringtones. I've been like working on a private. Polyphany has been a project, part of a project I'm working on. So like my ears lit up when you were talking about that. That's a lot. That's very, very fun.
Starting point is 00:51:48 And it also reminded me of like, this was such an underground weird thing to have to do. It's the same point that you already made, Scott, of like, you'd have to go to the like kind of janky grocer. Let's liberally call it that with it. Well, they'll like, they'll like, yeah, we'll take your PSP and you get it back and who knows. To like buying a PDF on eBay that was sold as an ebook all the way through to like, there's just companies that make this product now when retro emulation is not only common, but like. an increasingly important thing, I would say in gaming. Like it is, it's the preservation. Like it's,
Starting point is 00:52:24 there's this event horizon past which the big game companies won't typically pursue people for copyright infringement and everything on the other side of that line. The way you play these games is either on a computer, which is fine, but or through these physical emulators. Like, I'm really excited about that as like a product category. I think it's really cool because it's, it's archiving games. Like it's, it's important for a medium to have longevity. So that's going bigger than this, but I'm like, I'm, I'm staunchly in favor.
Starting point is 00:52:54 I think it's pretty cool. I'm, I'm here for that chat because that there is such a, now that everything is going digital first, you essentially don't own it. They have the right to revoke license in real time. Archivism of, you know, our childhoods has become a real thing. Really. Yeah. Like the, the physical cartridge-based video game consoles, much easier to archive. But now that we're going to a world where literally like the PS5 is probably going to be one of the last shit.
Starting point is 00:53:23 Well, actually, that's not true. Didn't PS6 said they were going to do no? I think it was Sony that announced that the PS6 was going to be digital only. And now everyone's looking to see what Microsoft does in response. They already sell a digital only console. And digital only consoles are very popular. It's, it's nuance to this. Like a steambox flew off the shelf.
Starting point is 00:53:42 It's digital only. But it's, it's taking something away from people that they already had. it hits a different emotional register. We're seeing like this is the the throwback mentality. Like I've got another friend that collects DVDs like crazy. Sure. And not only because they want to physically own the video asset, but they are a license to it,
Starting point is 00:54:06 I guess it would be a better way to put it. But the quality difference. Like people have kind of forgotten what things that aren't streamed and hyper compressed and one gigabyte an hour look like. A Blu-ray through an HTML to a really good television is like there is a quality. It's good. It looks good.
Starting point is 00:54:25 Like it's visible. Even if you're not a big pixel peeping person, you can tell. Yeah. Yeah. I hear there's like scenes in Star Wars and stuff where if you watch it Blu-ray on like an 85, 90-inch 4K upres, you can kind of see the styrofoam jank of the set construction.
Starting point is 00:54:43 And things like that. Like if you watch it in that level of quality, but we just we just kind of sold to the streaming life. Interesting. Well, I think those devices are cool and it's very cool that your story positions you kind of at the at the start of that whole thing. And that you've you've got this document that you published out into the world. And it's like, I don't know, there's this like tick in the history timeline of those devices. And you're like, that's my little tick.
Starting point is 00:55:08 And then it then led to you, your personal story of like, and not for nothing, but it paid for a visa that led to a citizenship. ship and now I'm married and have the two little vegima. That's just really, that's cool. It's a good, good, good call. I love the, I love the fact that you might be the origin story for the entire, like, mobile operating system, open source community, which is phenomenal. When we make the hack boy, the hacked official retro game emulator, we'll give you a shout out in the OS or something.
Starting point is 00:55:38 Totally. An Easter egg. Yeah, a little Easter egg. That's good fun. That was a fun batch of calls. Thank you to everyone to submit it. please share your strange tale of technology, uh,
Starting point is 00:55:49 true hack, computer confession. You can go to hotlinehacked.com. We got an email. We got a phone line. We, you get submitted as text. Tell us if you wanted anonymized,
Starting point is 00:56:00 um, we're here to make sure that you feel comfortable submitting your story, but we're going to do more of these types of episodes. We really get a kick out of it. So please submit your story. Uh, hacked as always is brought to you by our title sponsor, Nord layer.
Starting point is 00:56:13 They are the network security platform. for modern teams. Big thanks to North for sponsoring the show. Yeah, check them out at Nordler.com slash hack podcast. Means a lot, everybody. Excited for another one of these in the future. We'll catch you in the next one. Take care.

There aren't comments yet for this episode. Click on any sentence in the transcript to leave a comment.