Hacked - Hotline Hacked Vol. 6

Episode Date: October 30, 2024

The whole second half of this one is one long call but trust us it's worth it. A call in show with tales of hackers getting hacked back, spoofed emails, and operating system vulnerabilities. Hotline ...Hacked is brought to you by DeleteMe. Take control of your data and keep your private life private by signing up for DeleteMe. Now at a special discount for our listeners: Today get 20% off your DeleteMe plan when you go to joindeleteme.com/HACKED and use promo code HACKED at checkout. Learn more about your ad choices. Visit podcastchoices.com/adchoices

Transcript
Discussion (0)
Starting point is 00:00:00 Thank you for calling Hotline Hacked. Share your strange tale of technology, true hack, or computer confession. After the beep. Hello fellow Canadians. Love the show. Funny story about email spoofing. Having grown up in the early days of email, hacking on open relay SMTP servers was great fun, freaking your friends out by sending them emails from someone famous or from each other.
Starting point is 00:00:24 Fast forward to around 2012. I'm at work and get a call from my wife saying our internet's. stopped working. We used a cable internet service provider at the time, gave her the usual fix, power cycle modem and then utterer, but to no avail. When I got home that night, I confirmed that something external was blocking our internet, so I called the ISP and explained the situation. The young support tech advised me that my wife's email address was sending thousands and thousands of spam email messages, and so they blocked our internet in an attempt to stop it. At the time, My wife had a very basic email address, first name at isp.com, so was often being spoofed by
Starting point is 00:01:02 spammers, and thus this did not surprise me at all. I had previously investigated the ISPs SMTP server, and knew they were open relay servers, and had actually reported it to them. But of course they hadn't done anything about it. Anyway, I explained this to the tech support dude, and he had never heard of email spoofing, and really didn't believe me that anyone could do this, so I decided to educate him. I asked him first to restore my internet service, and then I could prove to him that this type of spoofing was possible. He did, and then I asked him for any email address of someone he knows in his own email address,
Starting point is 00:01:36 and that I could pretty much instantly email from one to the other. He complied, being anxious to see if my claim was true, and I opened a telnet session to Port 25 on the ISPs MX. And about 30 seconds later, he received the email, He was completely floored, excited even, and desperately wanted to know how I did it, although I didn't give him all the details. I said just Google SMTP and Telman. He was quite ostrich and thankful, so I ended the call by saying, Don't ever cut our internet service again.
Starting point is 00:02:06 What's even funnier, or perhaps scary, is that a year or so later, I checked in those same SMTP servers were still open relay servers. No doubt they can still be found out there, even today. Cheers. Cheers. Cheers. Gotta love the AI voice. Welcome back to Hotline Hacked. It's a call-in show where you can share your strange tale of technology, true hack or computer confession. We always appreciate your calls.
Starting point is 00:02:35 This is a fun one to kick it off with. Well, this one kicks off this episode similar to the first episode of Hacked podcast, taking it off. I believe we were talking about Open Relay SMTP servers back in the day. And email spoofing. That's totally true. Yeah. This is a throwback.
Starting point is 00:02:51 And this was set in 2012. So this IT support, tech support, man, couldn't have even learned of it from even some of the earliest episodes of Hacked before the big break. For anyone that doesn't know, not that I don't, what's SMTP servers? What does it mean for them to be open? And what exactly happened here? Well, I would refer you to episode one of this podcast. but SMTP simple mail transfer protocol it's the way that email moves between servers so like when I build an email and like my Outlook client let's pretend I use Outlook and I hit Send it literally
Starting point is 00:03:33 creates a socket to port 25 if unencrypted now most of them are encrypted but passes the email information over the server which then in the background looks up what the receiving server needs to be, makes the connection, and delivers it for you. Since 2012, there's been, let's just call it a million updates to the security of this. It's very less, or it's considerably less common these days than it used to be, that's for sure. Especially with Google now banning so many different, you know, adding so many more restrictions to authenticate and verify email senders to make sure that this stuff doesn't happen. Because back in the day, it used to run rampant. Like, I remember doing a case study in university in, like, the early 2000s, mid-2000s, about the cost of spam, because the lost time, the data usage, all the rest of it was massive.
Starting point is 00:04:25 So spam is kind of a thing in the past. I still get added to mailing lists, probably from data brokers, which is a great transition to the sponsor of the show. Delete me. Talk about delete me. Talk about delete me. Delete me has come aboard. they love the Hotline Hack concept and they wanted to sponsor it. So the Delete Me offers the service that kind of can cleanse your information from the data brokers of the internet to the bad personal information sellers.
Starting point is 00:04:54 But we'll talk about that in a bit. But as long as your email exists in some of these data broker things, it seems like I get signed up for mailing lists that I have no idea about pretty much constantly. So let's hope that Delete Me does his job and I get removed from a ton of those things. but back to the story. Back to this story. So this guy's wife, it's 2012, their internet goes down, it's not working, calls up tech support at the ISP and gets explained to him. His wife's email is sending thousands of spam emails and apparently had a very, very good, very old email, first name at domain.com, which as a like appreciator of really, really good usernames, kudos to her. but it's clear that someone is spoofing this email.
Starting point is 00:05:44 Someone is sending emails even though they don't control the actual email address. And tech support had never heard of this, which I find surprising. I feel like by 2012, if you're in tech support, especially in an ISP, you might have bumped into this. Is that a bad assumption I'm carrying around? Yeah, a bit. I think the difference between like a customer service tech support person and somebody that's in the technical infrastructure side are very different people. often tech support people have scripts and you know etc they're not they're I wouldn't say that they're like infrastructure grade IT staff so that's a good point yeah but the but the fact that
Starting point is 00:06:22 you're running an ISP in 2012 and you don't know about and it's not closed your SMTP servers are open relay and have no controls on them is wild especially because you're paying for the throughput of all the data for all the spammers using your mail server to send emails which is also wild. So just bad business question mark. Yeah sure and a year later I think the call ends with the caller saying that the servers were still open probably not anymore but
Starting point is 00:06:53 shortly after they hadn't shut it down basically is the way the call ends. Yeah yeah that's again probably just an internal disconnect between the IT staff the actual infrastructure staff and the tech support people so he probably unlocked the person's account and thought it was neat, did some research on their own, and never reported it to the infrastructure team for fixing. Or maybe they did, and the infrastructure team decided not to fix it because it would create more headaches for their user base than they'd have to deal with because I'm sure a lot of them didn't set up their mail clients properly.
Starting point is 00:07:26 And if you have hundreds of thousands of people that use it, then do you really want to upset the Apple cart that much? So anyway. I remember back in that first episode, and I summed up a couple of the notes here. But the story I think that we kick off one of those earliest episodes about talking about email spoofing takes place in 2013. If I've got the right story here, which is funny because it was after this and concerned a Swedish company. Someone sent out a blast to a bunch of news agencies that the Swedish company called fingerprint cards was going to be purchased by Samsung. And it caused the price of the company's stock to surge by like 50%. It was one of these first instances of email spoofing being used in kind of a fraudulent social engineering type scam.
Starting point is 00:08:16 And it's funny that it happened after this. So the idea that maybe someone at an internet company wouldn't have heard of email spoofing makes a lot more sense to me because it hadn't broken out yet. It was a thing you could do if these things were open, but it wasn't a thing that a lot of people maybe knew about. So that makes more sense to me. Well, it's like being somebody that was in that spoofing. space, it was something that I'd note about since, you know, the early 90s. You know, I'd been mucking about with it. So, like, I remember when you and I had the first conversation on the first episode of Hacked,
Starting point is 00:08:47 I can't remember the year. But I remember it kind of blew your mind a bit. And it was just like it's, it's, it used to be like a common tool in the toolbox. You know, it was pretty easy to, to send fake emails. I still get a lot of them now. And there's a lot of people now that spend more time obfuscating emails to make it look like it's coming from you. Like our accounts payable department at the company gets emails for me all the time
Starting point is 00:09:13 to pay invoices that I have no knowledge of from a person whose email looks just about the same as mine and has the same email structure as me. And spammers will spam and con men will con and grifters will grift. So such is life. Creep on creeping on. On to the next one. Jordan and Scott, my name is Dana, and I discovered what I thought was a vulnerability in Apple back in 2020. I reported it to them.
Starting point is 00:09:48 They said, this is not a vulnerability. So I'm sharing it with you all, and I'm curious as to your take on it. In 2020, during COVID, cowork and I discovered that you can put a period in front of a username at the new user setup screen. If you were to take a brand new Mac out of the box and go through the setup process, you could create a user beginning with a period. And if you created that user beginning with a period, that user would be hidden from system preferences. It would also be hidden from even the DSCL command line utility in Mac OS or OS 10,
Starting point is 00:10:31 even going back even further. And you would not be able to. able to see this user in your user lists on this device. The concern is that if you couple this with by setting up this hidden user on a brand new computer out of the box, brand new Mac, out of the box, then you load your malicious software on there. By the way, you would have to change the UID of the user because you'll get a collision next on the next user you create. It doesn't iterate properly. So I think it's a thing. like 501. So then you would change that user from 501 to like 599 or something.
Starting point is 00:11:13 And you load malicious software on that computer. You can then reboot the computer into single user mode or recovery mode, whatever, get to the terminal. Remove the Apple setup done file. And when that computer is rebooted the next time, that that computer will look like it's brand new out of the box. Then that new user, they could set up the computer exactly how they want. They could enable disk encryption, any of the security features, security profiles, anything like that, post-attack. And because this attack would happen in the, could attack, could happen in the supply chain, this computer could be compromised anywhere between leaving the factory and arriving at a person's doorstep.
Starting point is 00:12:10 Could be resealed. You know, you can reseal a box, whatever, an Apple box and make it look like it's brand new. Deliver it to your CEO with malicious software on it. That was not a good idea, but I'm just saying that's what a malicious person would think. I'm curious as your thoughts on this. It sure seems like Apple would want to fix this, and it's funny that they say it's not a vulnerability
Starting point is 00:12:35 when they have indeed corrected this in the latest iteration of Mac OS. But my concern is that for more than 20 years, Apple has ignored fixing this problem. And there could be devices out there with these dot hidden accounts on them out in the wild. I'm not sure of that. I haven't been able to get enough information to discover that,
Starting point is 00:13:04 but I'm curious as to your thoughts. What do you think about this? You think this is a vulnerability or not? What do you think, Jordan? Deliver it to your CEO. It's not a good idea, but you could do it. You could really hear a person reaching the end of a thought of what could be done with this potential vulnerability
Starting point is 00:13:25 we're hearing about. If this vulnerability is true, and we haven't purchased Macs from this period of time and gone through the process of testing this for full disclosure, as pretty bad vulnerability if that was lurking around in MacOS for a couple years, if not decades. What do you think, Scott? I think, yes, it is a vulnerability,
Starting point is 00:13:50 and it was right of you to report it and it was right of them to fix it, even though they claimed it wasn't a vulnerability. Yeah, crazy to think, like, it's crazy to think about what you could do with that. Like, IT staff generally have an elevated level of transparency into organizations. You know, you can often see emails. You can go through stuff. So, like, delivering into the CEO to me is not the big one. The bigger scare to me would be, like, reselling a laptop, reselling a Mac.
Starting point is 00:14:21 That happens all the time. And imagine you got it. It looked like it was fresh and cleaned and reset. And you set it up yourself. And boom, there was a backdoor entrance and do it pre-set up by the previous owner. In organizations that have like a firewall between departments and things like that, like mergers and acquisitions, one I love to talk about because a place. And same with the reporting, as we did in the last story, artificial information about a company to manipulate its stock.
Starting point is 00:14:53 price. Having eyes into details that you're not supposed to would be, could be very lucrative. So there'd be tons of attack, you know, potentials for this. Wild that it existed. And the origins of it, I don't fully understand. Like dot at the beginning of a folder and stuff is like an old Unix. I was going to ask. Yeah. So like, why might that be relevant? Yeah. So any, any folders and things that start with a period? become invisible. So they're like hidden files and hidden folders. That's like an old Unix command or like an old Unix structure.
Starting point is 00:15:30 So applying it to users, you know, this is funny in like the 30 some years that I've been a Unix user. I've never actually tried this. So kudos to you for trying it. I wonder if it applies to other Unix systems would be my question and not just Apple, because chances are when they adopted the BSD kernel in the original OSX, they probably adopted a lot of those Unix structures. vulnerability still might exist in other Unix servers. So like when you're talking about if I hack into
Starting point is 00:15:59 a Unix server, I can set myself up an account that's essentially completely hidden unless you really go looking for it, which would be kind of crazy to leave yourself a beautiful backdoor that is just a full admin route access user. Yeah. When the CEO and I think the larger premise of delivering this to someone in a workplace came up, I do think about how many people are working every day on a laptop that was set up by an IT person at the company who set up to whatever the company's standards for security are delivered it. That end user, the employee might not have admin access to their own computer and that's for security reasons and there's pros and cons of that but I fully understand it. It doesn't strike me as where a vulnerability like this would be
Starting point is 00:16:42 relevant because your computer might already be vulnerable in that situation. It might already have monitoring software on it like you are not in control of that computer. Totally. You shouldn't assume you are. Someone buying a used computer is where this comes up. Because I can imagine cracking open a computer and it's sure looking like it's been factory reset, but it hasn't. Which is a good reminder that if you ever buy a used computer and it looks like it's been factory reset, you should factory reset it again just to be safe. So they set up a new user.
Starting point is 00:17:16 They put period at the beginning of the name. Apparently in Unix, this is not shorthand is the wrong word, but this is a way. to render something invisible. Thus creating one of these hidden users, you then go through a little bit of a process of removing the Apple setup done files. This is after you would have loaded whatever malicious software you want to, change the UID, get the computer looking brand new, even though this hidden user with the malicious software is still lurking in the background. And they can then go do whatever it is they want to do to lock down the computer, it won't matter because through this supply chain attack, you've kind of gotten under the hood already. Is that an accurate summary of
Starting point is 00:17:57 what this caller is describing? Yeah. Yeah. The supply chain attack piece is really interesting. Like, to me, the like internal IT supply chain, you know, they kind of already usually have super user access and access to a lot of confidential information. You know, their trusted employees. Like there would be a potential there for, I don't know. I don't know. I don't even want to theorize, like, cyberstocking and stuff like that. But, like, you would have the ability, like, that would grant, like, a much more personalized attack to be able to go into someone's computer personally. But at the same time, it's like the idea that, yeah, like, in a supply chain outside of IT, like, this could be something that happens. Like, you know, we're in a world now with nation state IT, you know, wars hacking or cybersecurity.
Starting point is 00:18:52 security wars. And we're seeing nations put themselves into supply chains for all kinds of things, like pagers, being one of them of note. So it's like the ability to distribute an entire, you know, bulk of IT hardware that has a perfect open backdoor in it with ease, because like I think in a lot of other major supply chain attacks, it's much more nefarious and much more refined in the sense that like maybe it's a small piece of malware that's living inside of another app, et cetera, et cetera. It's harder to detect where this is just a full backdoor account. So yeah, it's definitely a vulnerability.
Starting point is 00:19:33 Obviously they fixed it for a reason. So I say kudos to you for identifying it and sending it in. Not sure why they said it wasn't a vulnerability. Maybe that's just for a legal liability case. I was going to get to that next, that this feels like a tech support and someone called the lawyer's co-lab where we can't deny that this is the case, assuming this is all true. We can't deny that this is going on because you can go verify that this is a thing that you can do. But we do have to say it's not a vulnerability because we haven't fixed it yet and we don't
Starting point is 00:20:07 want a email thread where we admit to there being a very, very dire functionality, a very, very dire vulnerability in macOS. So we arrive at this weird, liminal, in between state where, yes, this thing that looks conspicuously like a vulnerability is in the computer, but you'd be mistaken for thinking it's a vulnerability. It's more like a fun trap door in the bottom of the tree house. It's a cool way of talking about it. We didn't fully know that it existed, but we're not surprised it exists and we're not mad at it, but we'll fix it. Don't worry. It's like, hey, you have shit on the bottom of your shoe. Be like, No, no.
Starting point is 00:20:48 That's how this shoe came. Yeah, anyway, if you have an interesting tale that you'd like to share with us, please let us know, hotlinehack.com. There's a phone number that you can dial in and leave us a voicemail. You can send us an email with the text. You can send us an email with an audio recording. If you want to obfuscate your voice, please do so. If you send us an email, we will use, as you heard in the first one, some mediocre AI to convert it to audio.
Starting point is 00:21:23 And as you're about to hear, we've done it again. I think you just threw some shade because that first one, they used AI. Oh. This one, we can say that we're using mediocre AI to do it. I personally think the AI in the first one was fantastic, Scott. Oh, yeah, really? Isp. Yes.
Starting point is 00:21:44 Let's hear how our mediocre AI compares. This was sent in by a German user. So we've used a German English voice. So we're in for a real treat to see how good AI is here. That's the commitment to quality you get when you send in a story. It's a hotline hacked. We're going to try our best to find the AI we think that matches your spirit, your energy, as closest as we can.
Starting point is 00:22:07 I used to study CS at a German university and landed a job at a chance. of one of the professors. We did some research project work mainly, but you also had to do some administrative stuff like updating schedules, updating lecture files, etc. For the purpose of the administrative things, we got API access to our university system, where you could upload files via an API endpoint, for example,
Starting point is 00:22:28 or upload the grades of an exam to the central server. However, it being Germany, the API was very old, so you had no identifying authentication in place. All we got was a generic API token, which was basically the same for every single. basically the same for every user for the whole semester. So as probably every university student had the same experience with deadlines, I had to submit a project for a subject,
Starting point is 00:22:49 had nothing to do with the chair I worked at. And of course, I was way too late and would have had to work a night shift to get it done by the deadline. Instead of getting on my arse and working I, of course, thought about how getting more time to finish it and got the brilliant idea to just DDoS, the central server, where I would have to submit my project to via the API access I have, had. Didn't think about any possible consequences and just started crafting huge files, set up a
Starting point is 00:23:16 small script that would send the files repeatedly and hoped for the server to crash. Even though I studied CS, it was still pretty early in my studies and I had no idea about dossing and other hacking things, so it was just a trial and error. It took several hours to get the script to work and submit a good chunk of files, but then out of nowhere, the connection erred out and the server was down, and I had an excuse to not submit the project. By that time, it was pretty late at night as well, so might have also finished the project in the first place, L-O-L. But yeah, that's my story. Brought the server to its knees with a night shift, instead of working on the project, never got caught, got a few more days to finish the project successfully and lived ever happily
Starting point is 00:23:54 after. I love that he, I should say they, I love that they themselves identify, that they could have just spent the time getting the project done, but instead they decided to learn how to dedos the server. Yep. That's kind of the thing about a lot of cheating. Is more often than not to cheat really, really good. That top drawer S-tier cheating is normally more work than just doing the thing that you're cheating at. Yeah. Yeah. Yeah. Yeah. I don't know what to say. So they got, they're doing some admin work at the university. And to do that admin work, they needed API access, which gives you access to these servers,
Starting point is 00:24:38 to be able to do things like upload grades. I sure thought that's where this was going, that they got access to upload grades and we're like A plus, A plus, whatever German for A plus is, not what happened. Everyone gets issued this generic API token. So it's pretty anonymous, I guess is maybe what I can intuit from that part of it,
Starting point is 00:24:58 which is what enables what's about to happen. meanwhile this person with this generic API token access to this university service has a urgent subject they would need to upload it to the server instead of doing the hard work of doing the assignment they got the idea to spend the entire night dedossing the server to have and this is the part that took me a second to get in order to have an excuse as to why they didn't submit the assignment is that correct you are correct so the the API key that went out it appeared that they gave everybody the same key. So instead of a key link to you, they gave it to everybody.
Starting point is 00:25:38 So the idea of being able to identify, based on the API key, who was uploading all this garbage that caused the server to crash, they couldn't do. They probably could have done it through network logs and figured out IP addresses and things like that. Cross-reference those IP addresses to previous logins and things like that. It shouldn't have been hard to track down who did this is what I'm saying.
Starting point is 00:26:02 They go, it sounds like they got away with it, which is good for them. The, I think the real lesson here is sometimes you just need to do the work. I don't know that that's the lesson from this. It seems like it went off without a, without a hitch. It's true. There is that lesson. It's a good lesson. It's not present in this story.
Starting point is 00:26:25 You're not wrong. The, the thing for me on this one is, is, I guess this is part of their tech journey. They figured out something. They figured out like they wrote a script to generate garbage files full of probably random information, just, you know, and just started uploading those in bulk. Whether they filled up the hard drive
Starting point is 00:26:46 or whether they actually crashed out the network, who knows. But they managed to DDoS or disconnect the server. I wouldn't call it a DDoS because it wasn't distributed. It would just be a denial of service, just a regular DOS. But they managed to get away with it. To me, I think the lesson that I would take away with it is maybe I should just do spend the time on the assignment. Because I also went through CS and none of the assignments were particularly lengthy, unless we're talking like an advanced, you know, massive project in the fourth year.
Starting point is 00:27:17 But most of the smaller things were just, you know, a few hours here and there. And if you're going to spend an evening or an all-nighter learning how to crash a server, you may as well to spend it knocking off the assignment and get it uploaded. At least that's my way to look at life. That's certainly true. However, I would say, then you wouldn't be doing a massive solid to all of the other students in that class that didn't get the assignment done. Because not only did you generate an excuse for you, you created an excuse that is sort of applied unilaterally to everybody. You cheated for the whole class, and that's punk rock. You're not wrong.
Starting point is 00:28:01 I might be. I might be wrong. The thing is that there was probably a bunch of other kids who were staying up all night actually working on the assignment that went to upload it in the morning and couldn't. Sure, nerds. Yeah. I'm one of those nerds, Jordan. Thanks.
Starting point is 00:28:17 I was one of those nerds too. But the, yeah, I guess for all of the other students that just were going to completely whiff on it and not submit anything for sure, for sure. Yeah, he's like the, he's the Robin Hood of. poor time management. Yeah. It's cool. I like it.
Starting point is 00:28:32 I've managed to do things like this on accident before. Like, yeah, I'm not even joking. Yeah, yeah, yeah. Like the ability to generate infinite information or spawn infinite processes in Unix. Like I once wrote a script, like just a bash shell script inside of Unix that called itself at one of the forks. And I managed to spawn an infinite amount of these. this process that was calling itself. And there's very little control if you have admin access and boom, the server's down.
Starting point is 00:29:07 Like I've crashed, I've accidentally crashed production servers with just like a small misstep before. So it's, it's a terrifying chain reaction, sort of Chernobyl gray goop, nanobot seating, everything moment where the computer just starts to esteem. Exactly. So it's easier than you think to crash, crash a basic server. so easier than you want sometimes. But did you use it for good?
Starting point is 00:29:36 This caller sure did. And we appreciate getting too heard about it. Why don't we? Okay, we have one more after this. It's a long one, which makes this about as good a time as any to talk about our dear, dear sponsor of Hotline Hacked, delete me.
Starting point is 00:29:53 Delete me. We've already mentioned them in talking about the vulnerabilities that exist with our information being inside of data brokers on the internet. And here they are. And here they are. Delete me. Delete me.
Starting point is 00:30:07 You know, if you ever wonder just how much of your personal information is on the internet for anybody to buy or see, it's more than you think. You know, your name, your contact info, your social, your addresses, and information about your family members. And this is all compiled and sold to whoever wants to buy it. And we all kind of turn a blind eye, except for delete. me. Anyone on the web that can buy your details. It leads to identity thefts, fishing attacks, harassment, spam calls, spam emails, which is how I was referencing it earlier. But now you can
Starting point is 00:30:39 protect yourself with delete me. As people who exist on the internet, as we all do, especially someone who shares their opinions about stuff. Scott and I are both pretty aware of our safety and security on the internet. It is regrettably very, very easy to find personal information about people online. It's just all hanging out there. People are buying it and selling it. There's an entire economy of it and that's why we choose to use Delete Me. Delete Me is a subscription service that removes your personal info from hundreds of different data brokers. If you sign up, you provide Delete Me with exactly what information you want deleted and their experts, take it from there. They send you regular personalized privacy reports showing what they found,
Starting point is 00:31:20 where they found it, and what they removed. And it's not just a one-time thing. It's always kind of running, constantly monitoring and removing that information as it goes. So to put it simply, Delete Me does all the hard work of wiping you, and notably your family's personal information from data broker websites. Take control of your data. Keep your private life private. Sign up for Delete Me.
Starting point is 00:31:42 Now we've got a special discount for hacked listeners. Today you can get 20% off your DeleteMe plan when you go join DeleteMe.com and use the promo code word hacked at checkout. The only way to get 20% off is to go to join DeletMe. delete me.com slash hacked and enter code word hacked at checkout. That's join delete me.com slash hacked code hack to checkout. Okay, before we get into this one, it's a little bit longer. We actually don't know quite where it goes. We know we want to give it a listen. We don't know where this roller coaster ride is taking us.
Starting point is 00:32:25 Just wanted to give you a little bit of a heads up. Yeah, we got this one. It's so long that we listened to the first minute each and decided that it's probably good, but we didn't want to ruin our hot takes. So we didn't listen to the entire thing. So here we go. Join us on this ride. Hey guys. Love your podcast. Love the hotline hacked stuff. I'm excited to share the story with you. It's a little exciting and nervous at the same time. So I'm also excited and nervous. So I'm with you on this ride. That makes three of us. Story takes place back in Let's see, back orifice was released in August of 1998. Back orifice.
Starting point is 00:33:09 One of the original kind of malware, like computer control, remote controls for computers. This is like an old cult of the dead cow thing came out in the 90s, which I think he just referenced, just so you know. That's what he's talking about when he mentions back orifice. Back orifice. B.O. B. B.O. from Call to the Dead Cow. CDC.
Starting point is 00:33:33 The dorm I was staying at during that time. So this was either in the fall of 98 or the spring of 1999. But let me give you just a little bit of backstory real quick. So I started going to college in like 1996. I didn't know anything about computers at all. Bodies and I, you know, kind of what we wanted to play some games and network. We didn't know how IPV4 worked, you know, Ethernet.
Starting point is 00:33:57 So we figured out. I love that he's talking about how he didn't know computers at all. back then and then starts referencing internet protocols based on versions. So I'm assuming his, is his, I'm assuming those skills have escalated since now. I'm going to bet that by the end of this story, he will have revealed himself to have known something about how computers worked back then.
Starting point is 00:34:19 I might be wrong about that. We'll find out together. 10 BX T cards could be hooked up with coax cable. And we use the IPX, SPX protocol and like things just worked so we could play games. And that's kind of like how we'd, got started into computers was just through video games. Didn't we all?
Starting point is 00:34:37 I also used. I used to have land parties where we used coax networks because they were super easy to spawn up and take down. So I did the same thing. Is it a GameShark hacking? Scott. Yes, it is. Hell yes.
Starting point is 00:34:51 Carmageddon, I think it was like MotoGP with some motorcycle game. Anyways, so wasn't going to class at all. We were just literally just hacking on stuff, learning how computers worked. And eventually, obviously, figuring out how IPV4 worked. And so through the next couple of years, you know, we advanced from Windows 95 to Windows NT. One point we were running like Windows 2000 beta, I think, at the time we did this. You know, on floppy disks, everything was dial-up. We had no, you know, no fast internet anywhere.
Starting point is 00:35:24 And MP3s had kind of just hit the scene. So, of course, being broke college kids, we ripped all of our CDs into MB3s. And then sold our CDs back to the, you know, resale shops so we can get some cash. And encoding back then was like, you know, 100% CPU max out. Like, don't touch your mouse because you're going to have like a skip in your song when you're encoding. Like it really sucked back then. This is, I remember all of this. This is really good.
Starting point is 00:35:52 This is a trip into the past for me here. This is just starting to bump into my actual experience with janky shit with computers, which was very like early 2000s music. and the sketchiest MP3s you've ever seen in your life. I'm seeing the dawn of my era here in this story, and I like it. I got to say, I never went as far as to rip all my CDs and resell them. It's a brilliant move right there. I just used, I allegedly just used straight piracy and down music that I didn't buy.
Starting point is 00:36:23 Yeah. Well, and specifically what he did was buy a CD, rip it, and then just return it to the store, which is like a weird kind of piracy. It was pre, you know, Kazah, LimeWire, Morpheus, Napster, but posts the popularization of CDs. It is like this tiny little window of time. You know, we have like a, I think we had Pentium 200 or something roughly right around then.
Starting point is 00:36:51 Like it was a lot, penny two, 200. Just kind of set the stage on like hardware specs. You know, we had our 56K modems and things like that. And so, yeah, so anyway, so MP3s, like, you know, I had my collection, my roommate kind of had his collection, like, you know, we'd try to, like, steal each other's MP3s, like, when you weren't looking, you know, if he goes to class, I would try to get into his machine, you know, like, I knew some of his passwords, and he knew some of mine. And then we started getting better at like, you know, better passwords and things like that. And then, you know, ultimately, we ended up kind of, you know, learning about, you know, file sharing and all that stuff. So we kind of ended up learning how to secure our stuff. And, you know, kind of culminated one night.
Starting point is 00:37:30 I had, for whatever reason, I had taken my, like, my snowboard goggles and put them on because it was kind of like, you know, my mask. And so, like, it was a null one night I wake up, I got my snowboard goggles on. Is he saying they use snowboard goggles as a sleep mask? Or, see, I read that as like a pre, like whenever I would go do hacking, prior to the popularization of the hoodie is the sort of iconic uniform costume of hacking. I would sort of pop on some snowboard goggles and just get my hack on. He wore them as a sleep mat. I actually don't know which one of those is weirder. I like them both.
Starting point is 00:38:09 I got the, you know, I got his PC, like the case was off, you know. And all my stuff was IDE. And his, he was, he had a little bit more means than I did. So he had like, you know, scuzzy ultra wide. And so I'm like, I've got his like, adapt tech, you know, 3940 scuzzy ultra wide card. I'm like, I've got that out. And I'm like in the middle of taking out his scuzzy drives to plug them into my computer. I wasn't very technically skilled.
Starting point is 00:38:38 But here I am disassembling. the computer pulling out scuzzy cards the scuzzy was a better hard drive like a connectivity like uh what's the right word i'm looking for here a way that the computer talks to the hard drives so id e was one and scuzzy is a different one scuzzy was a better one often used in enterprise grade stuff servers things like that where id was more of just like the classic you know when you see the classic hard drive and the classic connector that's what id was so just different ways of connecting the hard drives and different throughputs and things like that. So his buddy had better hard drives and better connections that his computer wasn't capable of.
Starting point is 00:39:16 So he's removing the scuzzy interface from his friend's computer to install it in his so that he can steal his music. I love the journey that we're going on here. It's like we started just as like playing games in our dorm rooms and now we're like literally tearing each other's computers apart to steal each other's music. And we're less than a quarter of the way into the, this odyssey. I have the feeling this guy's going to commit felonies by the end. This rules. Also, the
Starting point is 00:39:42 level of detail. Like, I was, uh, oh, I don't know, an adapt tech 3940. Yeah, yeah, yeah, yeah. It's like, this was 25 years ago. That's remarkable. You have an extremely good memory. Also, thanks for clarifying Scuzzy, because I assumed that he was just shit talking the other guy's gear. Like, Scuzzy, if you don't know that that's a
Starting point is 00:39:58 protocol or a standard. Interface, just sounds like it's bad. Yeah. No, better. Scuzzy was an interface and a better interface than the one that he had. He wasn't shit talking his friend's computer. He was being like, my friend was rich and had expensive shit. And I was mad about it.
Starting point is 00:40:14 So. You know, he wakes up. He's like, dude, what the fuck are you doing? I'm like, I do so, you know, totally busted. Okay, I got to, this is hard. It just keeps up. It's going to take an hour to get through this. So he just has snowboard goggles on.
Starting point is 00:40:29 He's ripping his friend's computer apart. And then his friend wakes up and it's like, what the fuck are you doing? I think I would say the same thing if I woke up. this confirms my theory that this was indeed his hacking uniform when you wake up and there's this like gremlin unscrewing your computer and you're like Ricky get out of my room again and so we kind of at that point we just we called the truth right we're like all right truth we're not gonna we're not gonna we're not gonna miss each other stuff anymore let's band together and you know go about this a different way so you know back then there was no line wire bear share Napster like none of that again existed. So the only means of getting a P3s were either, you know, borrowing CDs from people, ripping them and giving them back or, you know, on the internet. So we would find open FTP sites. And that's, that's kind of how this really started. I feel like we're about to go on a journey
Starting point is 00:41:25 into something that was called Wares, which was what stolen software used to be called. That's my gut read here is that we're about to enter a massive tale about stealing and distributing software. So we'll see if I'm right. Let's put on our goggles and find out. And then back orifice comes out. And this thing is, this is cool, right? So back orifice, for those I don't know,
Starting point is 00:41:51 it's a rat, a remote access Trojan, I guess you would call it. But at the time, it was just a really cool thing to play with. Right. So we had it installed on all of the lab computers, like in our dorm. on the main floor there was like probably 15 or 20 computers down there well he's into felonies at
Starting point is 00:42:12 four minutes and 18 seconds of a 15 minute story so you know it's see where this goes we had it installed on all up and down there and it wasn't really for anything nefarious it was actually to run distributed.net clients which back in the day distributed dot net was basically
Starting point is 00:42:30 but maybe still is I don't know it was a thing that you would use to try and crack encryption just to prove that the encryption algorithm could be cracked. And so you would download a little slice of a thing and work on it and you know, work on these chunks very similar to like Bitcoin pool mining where everyone kind of works on a little slice and then, you know, you kind of work together. That's what this was. So I had, I had this client installed on all the computers.
Starting point is 00:42:53 It was just kind of running. And that way I was kind of getting credit like under my username for like all these chunks that I was completing, you know, it was pretty cool. And then, you know, there was like a faster. internet connection down there. So like a lot of people would go on there and just, you know, they would use it for whatever. And so like our, our like dorm roommates would like go down there. They'd be on AOL and they'd be chatting to like girls, you know. And so like our one buddy came back up and he's like,
Starting point is 00:43:19 yeah, dude, I was just talking to this chick. And we're like, yeah, we heard long dong 42. And he's like, dude, bro, how do you know by using me? You know, like all the stuff. So we were kind of giving them crap about it. But so that was kind of, you know, it was fun. You know, we would open, close to CD ROMs and, you know, do stupid stuff like that, you know, freak people out. But then, you know, we're like, how do we, how do we get this out to other people? Like, how do we, let's do something cool with this. And we're going to have to obfuscate this guy's voice.
Starting point is 00:43:47 I think you might be right. Please continue. I'm so curious. That's circling back to sort of the MP3 thing. And here's where things kind of get wild. So on these FTP sites, a lot of them were set up as ratio. So like you would, like a one to ten ratios, you would upload one meg, and then you would be able to download 10 megs. And the idea there is to share, you know, to upload, upload a song, and then you could download some songs, right?
Starting point is 00:44:18 And uploading was super painful because we're on dial-up and it sucked. And we're like, man, it would be really cool if there was a way around this. Well, that was kind of the spark for this idea, is we're like, hey, we're going to release this back Orphus tool, and we're going to call it, QT FTP ratio cracker. Because QT FTP was the client that kind of a lot of people used back then. And we're going to call it, you know, QTFTP ratio cracker. People are going to download this and they're totally going to run it because people are idiots. And remember, like, back then, like, downloading executables off the internet was something you did like all the time.
Starting point is 00:44:53 Like, everybody was running, like, cracked copies of Photoshop, downloading, you know, serial number generators, cracks, things like that. Like, you would just download anything. It was like the Wild West, right? So here's what we did. So back orifice has a couple plugins. It has a lot of plugins, but the two that we used. One was called Silk Rope. And I hope I'm remembering this correctly, but to the best of my memory, here's what it was.
Starting point is 00:45:17 So Silk Rope lets you embed one executable into another. And so we took the Back Orifice executable, and we embedded it into this other EXE, which all it was, it was just an executable that had no icon, so it was clear. and when you when you rent it, it just deleted itself. That's all it did. Like, it was, I don't even know if I could find something like that today, but it was, I don't know how we found it back then. But, so we basically used this program. So when you, when you don't click on it, it would install back orifice,
Starting point is 00:45:45 and then it would just delete, like, the original executable. So you'd run it and you wouldn't really, you wouldn't, it just looked like nothing happened. And it would be gone. And you're like, what the hell was that? Like, that's, that was weird. But whatever, and you kind of go about your business. And so that's, that's what we did. and the other plugin we used was butt trumpet.
Starting point is 00:46:06 Yep, yep. And butt trumpet would make it so that when a computer got infected, it would send back orifice would send an email to an email address of your choice with some bits of information. I think it was, I think it had a little customizable templates. You could say, like, you know, here's the IP address or whatever it was. And so we had to send emails to an email address. That is really unbelievable in today's day and age.
Starting point is 00:46:34 But because the name But Trump, it just, we're like, hey, let's use, you know, this really, I have no way to verify this claim, but it was we had Donald Trump at, I think it was Yahoo.com. It might have been hotmail, but I think it was Yahoo.com. And I know, like I said, it's completely unbelievable. And I still know the password we use, because it was like a generic password, but I've, and I know the accounts have been disabled probably years ago. If there was some way to verify it, I could tell you the password. I guarantee we could get into this account. It'd be surprising if we got into that account and it was still receiving email updates from like old ass computers that hadn't been updated that were still running this rat. Donald Trump at yahoo.com.
Starting point is 00:47:19 And then we started uploading this combined, you know, this silk rope. We uploaded this thing to all the FTP sites so we could find all these ratio sites. and then we just sat back and waited. And I remember it wasn't very long. I mean, it was like less than a day that we started getting emails. And it was like, you know, tens of emails, hundreds of emails. Like by the end of the week, it was like we were getting like a thousand a day. And it was like, holy shit, dude, like gold mine.
Starting point is 00:47:51 And so then we started, you know, plundering people's devices like it. Oh, we're deep in felony territory now. Yeah, this is a lot. like a distributed Trojan attack taking over control of thousands of PCs on the internet and then plundering them? Was that the term he disused? I am so curious to find out what dear caller means by plundering.
Starting point is 00:48:19 We have six more minutes where I'm sure we'll learn the details. Plunder on. My badge of honor, I remember so it was like somebody from like UCLA. I had, you know, remoted in, and I'm like, I stole their background, street, like, your, you know, their desktop background, which back on, it was always like, you know, some college, it was always like some, like, you know, sports illustrated swimsuit edition model, you know, like lying on a beach or a bikini or whatever. So, like, I would steal that, make that my background. And that was, like, you know, my trophy is I would steal people's backgrounds. And then here's what, here's where, like, here's where the guilt really comes in. Oftentimes, it would be, like, you know, people would have have, you know, 3.2 gig hard drives. Like, it was pretty small. But people would have, like, a C drive. And then they would have a second drive, like their D drive.
Starting point is 00:49:03 And that's where all their, you know, all the wares would be. And, you know, crack copies of Photoshop, all their MP3s. You know, we would steal MP3s and stuff. Called that. Yeah, no, credit where credits do, you called that one, a mile out. You know, if they, if, if somebody's drive, like their secondary drive was full of just, like, cracks and MP3s and nefarious stuff, I, I would format the drive.
Starting point is 00:49:30 So I would go to a command prompt on the machine. And I would type in format, space, D-colon, space, forward slash, v, colon, loser. And V is deceptive volume name. And so if they open up my computer, they would see the C-drive, and then they would see their D-drive, and the D-drive would just say, loser, and it would be empty because I had just formatted it. So I don't feel good about it. I don't feel good about it either.
Starting point is 00:50:09 Like, oh man. There's a hint of Robin hitting here because he's like deleting stolen software, but there's also a hint of like just mass crime. Like trolling almost? I keep coming back to the visual of the snowboarding goggles. Just like formatting someone's drive and leaving the word loser behind. just popping them up off your head and going for a coffee. It's not me that's doing it.
Starting point is 00:50:41 It's my alter ego. 1080 snowboarding hacker. This is great. I love that. We should have four minutes. Let's find out. I said, there's been like 25 years of guilt that I feel extremely remorseful for,
Starting point is 00:50:56 but I really only did it for people who had a bunch of trash on their job. Like I wouldn't do it if they had like schoolwork on there or like, you know, important documents. because I would stupid for everything. I didn't do any of that. So it makes me feel a little better, but I still feel pretty shitty about it. So I'm sorry.
Starting point is 00:51:16 Wow, public confession. Like we've got like a, never, haven't had a hotline hack that's a public confession and an apology. And like I, like, it seemed like you got a good heart on you. Like you did something.
Starting point is 00:51:29 It was a little, a little bit anarcho. There were shades of that to it, but you carried it around. You realized you maybe sure. of and the thing you know yeah totally i appreciate gross the thing is like this story is long enough and we've gone on such a journey to get to this part that i'm invested in the main character protagonist or antagonist and here's the thing is like it's good to see the moral evolution as
Starting point is 00:51:52 you went from and like a truth be told like i remember those days it was the actual quote unquote wild west like computers weren't set up and capable of dealing with you know hazards people were trusting and did anything, it was so easy to put a Trojan on a computer, to put a virus on a computer, to get access to information you weren't supposed to have crash servers for your email assignments. It was, yeah, it was, it was, it was, it was the Wild West. And I think a lot of us grew up in that time, or a lot of us that did grow up in that time, remember that that was just like, it's a sad part to say, but what am I trying to say here? I think during that time, a lot of us did things we regret.
Starting point is 00:52:42 And we all grew from it. And it's good to hear that you've grown from your story too. I think about how when I was, I think younger than this caller was during this period of time, but when I was first, when I first got that computer that I had access to by myself and it was just, allegedly an explosion of piracy in the basement of my childhood home. And that if the criteria for, yes, I can go ahead and muck with this person and, yes, I can go ahead and format their drive was the presence of pirated software and MP3s, boy, did I have a big flashing bullseye above my head that entire time. And I'm sure happy. I wasn't, I didn't get into it back in the FTP.
Starting point is 00:53:25 I had had friends growing up that were. I want to say borderline addicted to collecting music, which is to me, like, a more reasonable venture. But I had other friends that collected wares, which was stolen software and things like that. And didn't use any of it. Just collected it, like a mouse hoarding or squirrel hoarding nuts for the winter. I remember a friend of mine, I won't say his name, but he had, you know, back in the day there was like CD binders that you would store your CDs in. Oh yeah. And he had a CD burner, which was an expensive toy like Scuzzy Hard Drives that the rich kids had.
Starting point is 00:54:09 And he would have binders and binders full of like every piece of software, every game, everything. And he would download it and then burn it to a disc and put it in his binder. And he just collected them. He never used any of it. He just collected them. Anyway, that's a digression. Let's... There was one.
Starting point is 00:54:30 person who I, you know, I connected to and I, I, I, it was like a web server, so I like, go to it and this kind of hit home for you guys. But it was a, it was like a Canadian, um, mom and pop travel, uh, place. So they would do like guided tours. Like, if you visited Canada, you go to this place and they would take you on like, you know, guided hiking tours and canoe trips and things like that. I was like, man, like, these people have no idea that, that they're just exposed. Um, you know, so I, I, I actually went, I, like, drove to a pay phone somewhere. And I called international, which I never called international before. And I was like, hey, you know, I called them and let them know. I'm like, hey, your web server is compromised. And they were like, dude, what are you talking about? And I'm like, just trust me, have somebody technical go look at this. Here's what they should look for. And I like hung up.
Starting point is 00:55:19 And I was like, I felt like I did sort of a good team, but I still, I felt guilty. You know, and I'm like, man, that was crappy. But whatever, you know, so I moved on. And I think the final The last part of the story really is The part that scared the shit out of me So I'm like you know
Starting point is 00:55:38 Somebody's live on their computer and I have like You could You know watch their keystrokes and I think it was like a notepad I don't remember exactly how it worked I think I you know I could see like it was like in a notepad type thing You could see their keystrokes and you would see like they're misspellings and things But it wouldn't correct their misspellings like a notepad like if they hit back It wouldn't like Backspace in notepad.
Starting point is 00:56:02 It would just give you like a Backspace, you know, character thing to let you know they typed in Backspace. So seeing what they're typing is kind of hard, you kind of had to decipher what they're typing because it was kind of jumbly. But this person went to Microsoft.com and he searched for something. And I don't, I didn't know at the time what it was he was searching for, but I knew immediately after because he went to Commandprompt. prompt and he typed in NetStat. And then he typed, and I don't know where he typed this, it's probably still in the command prompt, but he just typed it knowing somehow he knew. He typed, I know who you are, 151.167.x.x. Or whatever, you know,
Starting point is 00:56:43 but it was, it was my IP address. And the first, the first two, you know, octets or whatever are tied to my school. And so, like, he knew for sure what school I went to. And so he knew for sure who he could contact and that I was like, I powered on my PC. I remember this was a Friday night at like 8 o'clock. Because we were getting ready to kind of go out to parties, you know, so, because he didn't go out until, you didn't even go to parties until like 10 or 11 o'clock at night when you're in college. But I remember freaking out, getting extremely drunk. I was like, man, the feds are going to kick down my door.
Starting point is 00:57:19 And just that was like, that was like the end of my hacking. That was it, man. I was freaked out, and that really set me straight. And I ended up switching degrees into, I got into computer science at that point, and became a web developer. I was a developer for 20 years. I got into infrastructure. And during that time, I actually kind of was getting back into the scene.
Starting point is 00:57:43 I was buying 2,600 magazine and going to hacking conferences. And now I'm in AppSec and hacking legally for money. I work for a company, and I get paid for it. to do what I really like to do. So kind of all came full circle. Sorry to those people that I formatted these drives, but you had probably had it coming anyway. And that's the end of my story.
Starting point is 00:58:04 Thanks for listening. Great story. You truly earned every minute of that. That was fantastic. I like that the ending of it. I said earlier that you clearly got a conscious on you. And it's like you really appreciate that in a story like this, this sort of double beat right at the end of there's this one person I connected to the Canadian mom and pop travel place. They take you on guided tours, driving out to a pay phone so that you can call them and tell them your computer network is compromised. Your web server is compromised. Who are you? Just trust me, have someone technical look at it. It's such a great little turn in that story. Not before the final turn in the story, however, when you were scared straight. Yeah.
Starting point is 00:58:52 You ran into somebody that knew, like, somebody that knew the footprint of back orifice, probably. They knew. And the thing is, too, is I remember back in the day, too, of doing the same thing, like net statting people, seeing what people were. So net stat, you're looking at all the connections on your computer on the network, finding the one that's the anomaly. And then there's even geolocation, so you can take an IP address and essentially geolocate it at varying. degrees of specificity. So you can figure out essentially where someone is. And you can do this even nowadays, like in certain games and stuff where there's direct
Starting point is 00:59:33 connections between gaming clients, you can still see the IP address of the people you're playing against. This is where DDoSing and games comes in and stuff like that. As you can figure out other people that are around use IP addresses and then DDoS them off the network, essentially killing their connection to the game, allowing you to beat them whatever, whatever that goal is. It's part of the cheating matrix now in gaming. But I remember doing the same thing with geolocation and freaking people out, like when people would be talking smack on the internet and stuff. Like a lot of forum posts save the IP address
Starting point is 01:00:07 that things came from. And if you had access to those records, be it the database or whether they were embedded in the source files, like the HTML source for forums. And being able to geolocate people and being like, you know, how's Boston these days? And like, you know, just like, and in varying degrees of specificity. So the person that they ran into clearly had that knowledge, knew how to look up where the connections were coming from and probably knew how to geolocate it. So not just, you know, looking at the IP address and what organization it's associated with, but also probably geolocate the IP. So they probably had a really good idea of where you were. And yeah.
Starting point is 01:00:48 Great story. A really, really good story. I think about how often scammers, you always see this moment when someone's trying to scam someone that they think is probably less technically literate than by saying, you have no idea who I am. I'm the scariest hacker you've ever seen. It's like you're texting with someone. They're just making shit up. But they're trying to scare you by saying, I know where you are, I know your IP address,
Starting point is 01:01:13 I can see out of your, this just lies. And that that is such a pale shadow of an image. of this very real, very scary moment you had where you were the technically literate one who had gotten control of someone else's system. And they very matter-of-factly typed to you out of the darkness. I know who you are and then your location. It's so good. You couldn't script it better.
Starting point is 01:01:37 It's funny too because it's like this person's journey, I'd say it's probably very common in people that work in defensive security and appsec and stuff like that, where it's like you get the interest and you learn the skills. That's a good point. Not a lot of people go into the security sector blind and like with no knowledge. Like you're coming in with a catalog and a toolbox that you developed somewhere. And I would say most cases that was not developed doing good. So it's like the fork and the robot between the white hat.
Starting point is 01:02:17 and the black hats is, you know, this person was in the black hat camp and then started to feel remorseful for their actions and ended up in a career of a white hat. And I think the same goes for a lot of people. The same happened to me. The same happened to probably a lot of people that you work with probably have a similar, similar journey, whether it's as severe as this one, you know, mass distribution of remote access Trojans and, And, you know, mass gross data privacy violations, like definitely, definitely a severe tale. And especially when to tell to us, so appreciate you taking the time. We really appreciate that.
Starting point is 01:03:04 That's the kind of calls we want. Totally. To borrow your phrase, it felt like the fork in the road led him to that pay phone. It was his conscience led him to go, you know what, I did this. And it was fun and it was interesting. and I've got my snowboarding goggles on and I'm mucking with my friends and it's just sort of this naturally evolving process. But you sort of hit the moral crux of it and it led you down that kind of white hat road. You were actually yoinked off the road entirely when that other person wrote that terrifying message to you and you're like,
Starting point is 01:03:35 I'm actually going to detour through a really nice 20 year career in web development before I come back to this road I am going down and pursue work as a white hat hacker. This is a really, really good one. I appreciate you taking the time to record it. The detail was worth it. And we love getting stuff like this. So thank you again. Anything else? I think that about puts a pin in it.
Starting point is 01:04:00 If you've got a story that you would like to share, something short and punch or something like a real crime saga drama like that one, kick it on over to hotlinehack.com. You can send us an email with raw text. You can send us an email with an anonymized. voice. You can send your own voice. You can call into a real phone line that we have listed on the website, a myriad of options. All we want from you is your story. We'd love to hear it. Love to talk about it on the show. Take care, buddy. Catch you in the next one.

There aren't comments yet for this episode. Click on any sentence in the transcript to leave a comment.