They Hired Me to Steal a Shopping Cart Full of Human DNA 🧬 Darknet Diaries Ep. 160: Greg

They Hired Me to Steal a Shopping Cart Full of Human DNA 🧬 Darknet Diaries Ep. 160: Greg

Jack Rhysider

0:04 JACK: [App beeping] Hey.

0:07 DAD: Man, I don't see you.

0:08 JACK: Yeah, my tape is usually over my camera.

0:10 DAD: Why don’t I see you?

0:11 JACK: I got my tape on my camera.

0:13 One second.

0:13 DAD: Ah.

0:14 I can't even hear you.

0:15 JACK: You can't hear me?

0:17 DAD: My sound… JACK: [Background talk] There’s a story I had

0:19 that I totally forgot about but I remembered recently,

0:21 and I wanted to call up my dad and walk through

0:23 it again with him to try to remember how it went.

0:25 DAD: Yeah.

0:26 JACK: I want to recollect the story with you.

0:29 DAD: Yes.

0:30 JACK: Because as I tell it, I don't think people will believe it.

0:33 So, I figure you can verify that this is true.

0:37 DAD: Yeah.

0:38 JACK: Alright, so, do you remember my senior year at high school?

0:42 DAD: Okay.

0:43 JACK: I had my own car then.

0:45 I was mentally done with school.

0:46 I did not want to go to high school anymore.

0:49 I was just sick of it.

0:50 I just had been there too long.

0:52 I had one elective left, and I said,

0:56 what is the easiest possible class I could take?

0:59 Do you remember what I chose as my last elective in my senior year?

1:02 DAD: It was either welding or typing.

1:05 I can't remember.

1:06 JACK: Typing, yeah.

1:07 But typing— how fast could I type as a senior in high school?

1:13 DAD: At least 99 words a minute [inaudible].

1:16 JACK: Right, right.

1:18 So, choosing that as an elective… DAD: Oh… JACK: …that’s the easiest class ever.

1:24 That would— that’s gonna be a walk in the park.

1:27 DAD: [Music] I was happy for you.

1:29 Senior year.

1:30 JACK: Here’s the problem, though.

1:32 The class was the first period of the day, and… DAD: 8:40?

1:36 JACK: 8:40, yeah.

1:38 So, I had to be at Typing, first class of the day.

1:43 Yeah, the class was real easy.

1:45 When I got there I was like, oh good, this is just a beginner typing class.

1:49 I could type super fast.

1:51 So, I’ll tell you what I’ll do,

1:52 is I’ll finish up my lesson in like, ten minutes.

1:55 I could do this whole— these— all the stuff you guys are doing today,

1:59 I’ll do it in ten minutes and I’m done.

2:01 So, I even worked ahead.

2:02 I said, hey, teacher, can I go on to the next lesson?

2:06 Sure, sure.

2:06 So, I would do a whole week’s worth of work on Monday,

2:10 and then I would help out some of the other students and stuff.

2:14 I mean, I think I was the star student in that class.

2:18 DAD: Of course you were.

2:20 JACK: But once I got ahead enough— I mean, you know what my morning routine is.

2:28 Am I a morning person?

2:30 DAD: I probably woke you up at 8:30 and said, you have ten minutes.

2:34 You could not wake up.

2:36 JACK: Yeah, I had trouble waking up.

2:39 So… DAD: You had narcolepsy or something.

2:42 JACK: I did.

2:42 Yeah, that was— I used to use that excuse all the time.

2:46 DAD: You did.

2:46 JACK: So, I would get to school late on this typing class.

2:52 I thought, no problem, I’m a perfect straight-A student in this typing class.

2:56 I’m helping the other ones.

2:58 All my work is complete.

2:59 I don't think it’s gonna be an issue

3:01 if I’m seven minutes late, ten minutes late.

3:03 That’s fine.

3:04 So, I would show up late consistently to this typing class.

3:08 DAD: Oh no.

3:08 JACK: But yeah, well, the teacher didn’t like that.

3:12 She said, you can't come in late like— I have to send

3:16 you to the principal’s office if you come in late one more time.

3:18 You gotta come in on time.

3:20 This is like, your fifth time being late.

3:22 I said, yeah, but I’m getting all the work done.

3:25 What’s the problem?

3:25 She said, no, no, no, if you come in late again, I’m gonna have to report you.

3:30 So, the next day, I couldn't get it together.

3:33 You tried waking me up again, and I was late.

3:36 She said, that’s it.

3:37 You gotta go to the principal’s office.

3:40 The principal didn’t want to see me, but the vice principal was there.

3:43 He said, what’s the problem?

3:44 I said, no problem.

3:46 I’m doing well.

3:47 He said, well, the report here says that you're late,

3:49 so this is— you're a senior, you know?

3:53 If you get late too many times, you're not gonna graduate.

3:56 DAD: Oh, my.

3:57 JACK: I said, listen, I— have you looked at my grade in this class?

4:02 He said, that doesn't matter if you're late.

4:04 I said, no, it should matter.

4:06 Listen, I think your priorities are all screwed up.

4:08 If I’m acing this class,

4:09 if I’m getting it all correct and if I’m helping the other

4:12 students and I’m a value add to the class in general,

4:15 not just myself, then don’t you think that I

4:18 should be graduating with that sort of work ethic?

4:20 He said, no, it has everything to do with being on time.

4:24 It has nothing to do with work ethic.

4:26 You have one more chance, and if you— I’m gonna be there tomorrow,

4:30 and if you are late again this year, you are not gonna graduate.

4:34 I said, really?

4:35 You're gonna hold me back just for being late even though I have perfect grades?

4:40 The next day, of course, I’m late.

4:42 I could not get it together.

4:44 The vice principal was standing at the door when I arrived.

4:47 DAD: Oh.

4:49 JACK: He said, that’s it.

4:50 You're late.

4:51 This is the last straw.

4:53 You’ve failed this class.

4:54 I said, how would you— why would you do this to me?

4:59 It’s not like I’m struggling with this class.

5:01 This class is easy.

5:02 I’ve got it nailed.

5:03 I’m like, three weeks ahead of every other student in the class.

5:07 He said, I don't care.

5:09 You can't come to school on time, so therefore, you fail.

5:14 Fail.

5:14 So, they wanted to hold me back a year,

5:18 a whole year of high school, and not let me graduate.

5:21 DAD: Now, you're only missing a half

5:23 a credit at that point if you didn’t graduate.

5:26 You could have went to summer school and picked up a half a credit.

5:30 JACK: That’s right, I could have.

5:32 DAD: But you did something else.

5:33 JACK: [Music] So, what I brought— when I brought

5:36 this news home to you and I said, listen, I’m not gonna graduate this year,

5:42 your brain started going into overtime

5:45 and you started thinking up of— solutions.

5:48 DAD: Yeah, here’s a couple things.

5:50 One, after you got thrown out of the class,

5:53 I noticed you didn’t go to school when I’d wake you up in the morning.

5:58 I’m not even sure what was going on.

6:01 You'd say, don't worry about it, dad.

6:03 I can get in there.

6:04 Second period I gotta be there.

6:06 So, that.

6:07 But third, your social engineering wasn’t 100% yet.

6:11 That was your problem.

6:13 JACK: Yeah.

6:14 DAD: You should have done a lot

6:15 better with the assistant principal and the teacher.

6:17 JACK: Oh yeah.

6:18 But you saved me that year.

6:20 DAD: Of course I did.

6:21 JACK: I don't know how you came up with the idea,

6:24 but you found me an extra half credit.

6:27 DAD: Well, you one time switched high schools for, I don't know,

6:33 four weeks or something.

6:35 You didn’t like those kids, so you went back to the original high school,

6:39 which, by the way, was less than a mile from our house.

6:42 I don't know how you were ever late; less than a mile.

6:44 JACK: Yeah, it was very close.

6:46 DAD: So, I knew you were at that other school.

6:50 I went over there, and one of my kinda

6:53 best friends— played sports together and things— I said,

6:57 do you remember my son Jack?

6:59 Yeah, yeah, nice kid.

7:01 Well, is he in your PE class?

7:03 Yeah, yeah.

7:04 I said, you never gave him credit for that.

7:07 He said, oh, man, this is so hard.

7:09 Credit?

7:10 I said, not only do you gotta give him credit,

7:12 but you gotta get it done before graduation.

7:15 You got like, six days.

7:17 He just said, I don't think I can do it.

7:21 I said, no; you go to the registrar, you put his name down.

7:25 Well, he said, you owe me big time, and somehow magically gave you a C for PE,

7:31 sent it over to your high school, and that’s really not the end of it.

7:36 The end of it was graduation at your high school.

7:39 JACK: Yeah, yeah.

7:40 So, that sorted it.

7:41 Now I was back on track to graduate and everything was fine.

7:44 I went to the ceremony, I sat in the stands, and then how did the ceremony go?

7:49 DAD: The assistant principal, your arch enemy,

7:52 he’s the one handing out the diplomas.

7:55 JACK: The same guy who told me I can't graduate.

7:58 DAD: Yeah, just six days before;

8:00 you're not graduating, and now he calls your name.

8:05 You come up.

8:06 He looks at the diploma, stares at you.

8:08 I didn’t think he was gonna hand it to you,

8:11 and then he grimaced and gave it to you.

8:15 There you had the diploma with the missing half credit.

8:19 I think the statute of limitations ran out on all that, so… JACK:

8:26 Okay, I won't be kicked out of school?

8:28 DAD: Permanent record.

8:30 JACK: It’ll go on my permanent record, this one.

8:32 Oh, no.

8:33 DAD: Yeah.

8:34 JACK: Yeah, so that was quite the— all because of the typing.

8:38 DAD: Unbelievable.

8:39 Yeah, so, do you still know how to type?

8:44 JACK: [Laughs] Yeah, I do, but do you know how at this point?

8:47 DAD: No.

8:48 I’ve never had a job in forty years where I needed a typewriter or a computer.

8:54 Never needed one, or a cell phone.

8:58 I’m analog all the way.

9:01 (INTRO): [INTRO MUSIC] These are true stories

9:03 from the dark side of the internet.

9:07 I’m Jack Rhysider.

9:12 This is Darknet Diaries.

9:19 [INTRO MUSIC ENDS] JACK: I want you to meet Greg.

9:29 GREG: So, I grew up really, really poor.

9:33 I grew up in Tucson.

9:36 Fortunately my father was a avionics technician,

9:39 and he was a un-diagnosed autistic.

9:42 Brilliant man.

9:43 He was a MacGyver.

9:44 The man would just tinker and make things throughout his life.

9:49 While we were poor, my father decided to dumpster dive.

9:54 JACK: His dad would find various computer parts

9:57 in trash dumpsters behind buildings and bring them home.

10:00 After doing that a few times,

10:01 he had enough spare parts to assemble whole computers.

10:04 GREG: I had a Commodore VIC-20, I had a trash 80,

10:07 and then I had an Apple IIe, all when I was born, and I always loved them.

10:14 JACK: [Music] Back then, computers were not as common as they are now.

10:17 Having one in your house was a luxury.

10:20 Having three, you were really fancy,

10:22 and simply having these things within easy reach enabled

10:25 Greg to learn tons growing up instead of maybe

10:28 getting introduced to them sometime in high school if

10:30 your school was lucky enough to even have computers.

10:32 GREG: That was my escape as a kid.

10:35 I was a un-diagnosed autistic kid until in my thirties,

10:39 and I just immediately loved computers.

10:42 JACK: Computers were a novelty for me as a kid until we got AOL.

10:47 Then I became obsessed with them.

10:49 GREG: I was an AOL kid, too.

10:51 Matter of fact, that’s where most of my first programs ever came around.

10:56 I was one of the first to discover the 1IM exploit.

11:00 That was my first vulnerability I ever discovered,

11:03 was the integer overflow in the AOL client when

11:06 you sent a font size with a long enough number.

11:10 I remember finding that and making the 1IM punter back in the day.

11:14 JACK: I remember AOL punters.

11:16 You could send someone a message but then put

11:19 something in that message that when they receive it,

11:21 their client wouldn't know how to process it,

11:23 and it would just crash their AOL session.

11:25 So, you could come into a chat room, send everyone a message,

11:29 and then see half the room suddenly

11:31 disappear because their apps would be crashing, and they would disconnect.

11:34 So, all this fascinated Greg, to be able to force someone else’s

11:39 computer to do something it’s not supposed to.

11:41 That’s cool.

11:42 What else can you do?

11:44 [Music] His interest in hacking took root and grew.

11:47 Soon he found himself in an online group that was trying to create malware.

11:51 GREG: When I was a virus writer,

11:54 my ideology— I had— I actually targeted pedophiles.

11:58 Every single— every piece of malware I

12:02 ever wrote was designed to target pedophiles.

12:04 We ran a group in there to target people who were targeting children.

12:09 The best part about targeting pedophiles is I

12:11 think it’s the only case that you can say I gave malware to someone and they're

12:16 absolutely not gonna report you to the police, because what are they gonna say?

12:19 I was trying to pick up this kid and they sent me a jpeg.exe to them?

12:24 That was the case for many years.

12:26 When I wrote viruses, that was the only people I targeted.

12:30 Otherwise, for me, writing viruses, again,

12:32 was the thrill of learning about polymorphism,

12:34 metamorphism, and— as well as high-level, low-level code execution.

12:40 I just generally loved the thrill of the knowledge of it.

12:43 It was an art.

12:44 I still think it’s an art form.

12:46 JACK: His specialty was using Visual Basic

12:49 to code malicious macros in Microsoft Word documents.

12:53 So, he would send the Word doc to someone, trick them into opening it,

12:57 and if they had macros enabled,

12:59 that would allow Greg to take over their computer.

13:02 Now, keep in mind, he was doing all this in middle school,

13:05 not even in high school yet,

13:07 and middle schools back then didn’t even have computer classes.

13:10 If they did, it was just to take a math quiz

13:13 or something like that, not really teaching how to use them and stuff.

13:16 By the time he got to high school, they were just starting to teach

13:20 kids commands and certain applications on computers.

13:22 So, one of the first classes he took was keyboarding, which is learning to type.

13:27 GREG: I was like, no, fuck that.

13:29 I ain’t gonna type.

13:31 I know how to type.

13:32 [Music] So, our school worked on Excel.

13:35 All the great systems were in Excel.

13:39 So, I’m one of the old-school macro virus writers.

13:43 I remember Colors, and back in the day, those series of Colors and Tristate,

13:47 those were the areas of macro viruses I remember I started programming in.

13:52 So, with Excel, I was like, I could do this.

13:54 I don't want to be in this class.

13:56 I don't want to be in this school.

13:57 So, the entire grade system was in Excel, and I made a macro virus that would

14:01 look for my student ID number— a trick number,

14:05 identify the areas where the grades were in, take

14:09 the average number of the number of the percentage,

14:13 or if it was A through F, it would be— I’d make myself as a B,

14:18 and it would average a number to be 87%, and gave myself 87%.

14:22 JACK: He was able to take this malicious

14:25 Excel file and get it onto the teacher’s computer,

14:27 and suddenly he was getting all B’s in his classes.

14:30 On top of that, he made it so he had perfect attendance,

14:34 too, no matter if he was there or not.

14:36 So, he just stopped going to class.

14:39 What’s hilarious is he did all this while in his typing class.

14:43 He even coding in obfuscation techniques to avoid detection.

14:46 Like, after the teacher would record his grade and then close Excel,

14:50 that’s when the macro would trigger, on close.

14:52 He would stage all this information in a column that he hid off

14:56 to the side so you couldn't see any of the funny business happening.

14:59 GREG: This worked really well.

15:01 I was in school for nine days.

15:03 That’s how long it took me to write this and then put it into the school system.

15:07 Then every day I went home.

15:09 I was just at home.

15:10 One day my friends came over and— they came back

15:13 from class 'cause I still would hang out with them.

15:15 They were like, hey, Greg, man, the computers at school are really weird.

15:19 I was like, oh, what are they doing?

15:21 He’s like, well, they're crashing.

15:23 Everyone says Excel’s not doing well.

15:25 [Music] I remember my stomach sinking.

15:26 Like, oh, what do you mean?

15:28 They're like, well, they— when they're getting everyone ready for the finals,

15:33 everything changed and something crashed.

15:35 I think they're calling McAfee over it.

15:37 I was like, oh no.

15:39 So, I walk— I went to school the next day,

15:42 get into the school library— and I hadn't been in school

15:46 for so long that the librarian was like, who are you?

15:49 I was like, I go to this school.

15:50 I promise.

15:50 I’m here.

15:51 She’s like, I’ve never seen you.

15:52 Who are you?

15:53 I was like, well— do you have a student ID?

15:55 I was like, no, I don't have a student ID.

15:58 She’s like, okay, go to the principal’s office.

16:00 So, the principal, they’re just like, hey, we know you're a kid.

16:04 We know your name checks out.

16:05 You're in these classes, but none of your teachers recognize who you are.

16:09 I was like, oh, I’m sorry.

16:10 I just kinda shut up at that point.

16:13 They sent me home, and what happened was the school added a column in all

16:18 the Excel sheets to calculate final grades and to do something for final grades,

16:22 and unfortunately that column just happened to be where

16:24 I stored the previous data of all the columns.

16:27 So, the virus would restore the doc—

16:31 the sheets when teachers opened up the sheets.

16:36 That caused the Excel files to crash on grade,

16:39 and they sent the sample to McAfee.

16:41 McAfee at the time was like, yeah,

16:43 this is a macro virus and it was custom-written for your school.

16:48 So, the school decided to call the police.

16:51 The police showed up, knocked on my door, arrested me, and… JACK: Really?

16:55 GREG: Yeah, yeah.

16:55 I mean, it’s a government— it’s a public school.

16:57 It’s a public high school, so it’s technically the government.

17:00 JACK: This was real bad.

17:02 He went to juvie, juvenile detention.

17:04 They locked him up in a concrete room

17:07 with a steel door and a tiny, little window.

17:10 It’s a scary place for a teenager.

17:12 [Music] So, I have a note here.

17:15 It says you're the youngest hacker to be arrested… GREG:

17:18 Youngest… JACK: …in Arizona.

17:19 GREG: I was the youngest child to be arrested

17:21 in the state of Arizona for a computer crime,

17:24 for— I’m not sure if that still holds,

17:26 but that was the case for a long, long time.

17:28 JACK: A politician wanted to make an example of him, saying, see?

17:31 Cyber criminals are really bad and we should do more to stop them.

17:35 But he caught a lucky break.

17:37 GREG: But they came back that the Tucson police failed to handle

17:40 the evidence correctly and my case got dropped, luckily for me.

17:45 JACK: However, he was ordered not to touch computers for a whole year.

17:50 Can you imagine no computers for a whole year?

17:53 GREG: I made a deal with the courts to say I won't touch a computer for a year.

17:57 I’ll have to get a probation officer to sit next to me when I operate computers,

18:02 and then I— and after that we’ll re-evaluate the situation.

18:06 So, for a year, any time I wanted to touch a computer,

18:11 which was mostly the library back in the day— if you remember

18:13 when libraries had the little internal library machines to go look up

18:16 for books in the library— I had to go call this very large

18:21 sixty-year-old man who was— absolutely had

18:24 no idea what computer hacking looked like,

18:27 and I remember fucking with him quite a bit and saying,

18:29 oh, I’m getting into the system.

18:31 He’d look at me and grab my hand and pull

18:33 me away from the computer and— like, we're going now.

18:36 JACK: [Music] What kind of person— what kind

18:39 of kid were you like in high school?

18:41 GREG: Oh man, I was absolutely— I was a goth kid.

18:44 I was the goth kid who wore the large— I got in trouble for wearing

18:49 a black trench coat 'cause unfortunately going

18:52 to high school during the 2001 era, you come across the Combine incident.

18:58 JACK: You know, back in the nineties when I saw a goth kid,

19:01 I just thought they really liked the movie The Crow.

19:05 GREG: Yeah, The Crow was a good one.

19:07 My best friend at the time, his name was John Oller.

19:09 John was a huge Crow fan.

19:11 He actually— he kinda looked like Brandon Lee, too.

19:13 So, he was a goth-of-The Crow type.

19:16 I was more into the industrial music.

19:19 I always loved Skinny Puppy and Suicide Commando,

19:22 Velvet Acid Christ, all that— all those late-nineties industrial bands.

19:26 So, I was more of a rivethead.

19:28 I didn’t know at the time what a rivethead was,

19:30 but I was just an industrial kid; big, stomping boots, goth, industrial music.

19:35 I liked metal but I didn’t like metal so much; I like electronic music.

19:39 So, when I found out industrial music,

19:41 which is essentially goth music mixed with techno, I was like, this is it.

19:45 This is my lifestyle.

19:46 JACK: You wear earrings?

19:47 GREG: No.

19:48 I actually— well, sorry, I take that back.

19:50 In high school I think I had nine piercings.

19:54 I had, you know… JACK: Did you wear eyeliner?

19:58 GREG: No, I was not a makeup goth.

20:00 I was not a makeup goth.

20:01 I had the dog collars, so I had the goth collars.

20:05 So, I had the bondage outfits.

20:07 I was one of those goths for sure.

20:10 JACK: Okay, so this just emphasizes when

20:13 they're looking for the person who did this.

20:16 GREG: Yep.

20:16 JACK: They’re just like, you're the one… GREG: Yeah,

20:18 I’m sorry… JACK: …who does not look like everyone else.

20:19 GREG: I’m sorry, everyone.

20:21 The goth stereotype for the virus writers, that was me.

20:25 That was me, everyone.

20:27 I apologize.

20:28 Yeah, I remember… JACK: You started this.

20:30 GREG: I did, I did.

20:31 So, my parents kicked me out of my house.

20:33 I lived in a group home after being arrested.

20:35 I was in a… JACK: Wow, just because of that event?

20:37 GREG: Yeah, yeah.

20:38 So, I lived in… JACK: And you're not normal, Greg.

20:41 You're wearing— you got too many piercings.

20:44 Come on.

20:45 GREG: Yeah, I did that all myself, too.

20:48 So, I got kicked out.

20:50 I lived in a group home from the age of fourteen to eighteen.

20:55 [Music] So, I was in and out… JACK: That was a tough time.

20:59 GREG: Yeah.

20:59 JACK: So, at fourteen is when you got arrested.

21:01 GREG: Correct.

21:01 JACK: Then, that’s a hard time to go through an arrest.

21:04 That’s scary.

21:05 You don’t know what you're facing there.

21:06 GREG: Correct, yeah.

21:07 JACK: Then to be thrown out of the house… GREG: Yeah.

21:08 JACK: …and then like, what?

21:09 I gotta do this on my own?

21:11 Gosh.

21:11 GREG: Yeah.

21:12 So, I lived in a group home; didn’t have access to a real computer.

21:15 So, my only computers at the time were the ones in school.

21:19 It was rough, man.

21:21 It’s one of the big reasons why I always try

21:24 to reach out to people who are kind of in rough situations,

21:27 'cause my life has not been an easy one.

21:30 It has not been easy.

21:31 Living in a group home, which— the group home was— the one I

21:36 got assigned to was a government group home,

21:39 and it was mostly for kids who were domestic violence or runaways.

21:43 So, it was a lot of violent kids in there.

21:47 It was a small— it was like a small four-bedroom house,

21:52 but it had— at any time it had between

21:56 six guys and six girls and then staff members there.

22:00 So, it was cramped.

22:02 Everything was shared.

22:04 It was not a good time.

22:07 It was a rough life.

22:09 JACK: I think I just got some clarity on what it means to be goth just now.

22:16 It’s not about the clothes and the makeup and the music.

22:20 It’s about not fitting into a world that tells you

22:24 to shrink and conform and smile when you're falling apart inside.

22:29 [Music] It’s about understanding that you are

22:32 different and you can embrace your difference, and you gotta pay the price.

22:37 Being misunderstood by your teachers, so-called friends,

22:41 even your own family, can become isolating.

22:44 There’s this moment I imagine that every goth must face.

22:49 You have a choice; either break yourself down into something more acceptable,

22:54 force yourself into a version of normal that everyone wants you to be,

22:59 or you can embrace that shadow inside you,

23:02 that one that’s screaming out, wanting to be seen, wanting to be heard,

23:05 but knows that it’s just too weird for people to understand.

23:09 Goths choose to embrace that inner shadow, lean into their weirdness,

23:14 wear it like armor, and let your darkness be your beauty.

23:19 When you're in a place like a halfway house

23:21 with nowhere to go and no one who really knows you,

23:24 that identity, being goth, can become more than just a style.

23:30 It becomes your anchor,

23:31 because being goth means you already know what it’s like to live on the outside.

23:36 You already live in the cracks of the system.

23:39 So when the worst happens, when your life is shattered,

23:42 being goth is a reminder that it’s okay to be on the outside of society.

23:48 The music reinforces the idea that it’s okay to live outside what’s normal,

23:52 and there’s a level of comfort to hear that music

23:55 and to see other goths who are also struggling to fight what’s normal,

24:00 those quiet rebels, the kids who find beauty in broken places.

24:05 I imagine that being goth makes you more resilient to problems like this.

24:10 It gives you a tribe without borders.

24:13 It gives you a sense of self when the world pretends you're invisible.

24:18 So, I imagine being goth in that halfway house was

24:21 an amazingly helpful way to get through it, to self-soothe.

24:25 Every time he put on dark clothes,

24:27 it was like he was giving himself a hug and saying, it’s okay to be different.

24:33 Don't worry about what everyone else thinks of you.

24:36 Man, to go through something like that, and goth being your anchor,

24:41 that could easily make you goth for life.

24:44 Man, I think I got carried away there.

24:47 Okay.

24:48 GREG: So, after I get out of high school— so, I was doing music,

24:53 one of the few things— so,

24:56 I became— I was a musician and I was a successful musician.

25:02 If you've ever seen The Matrix sequels movies, then you've heard my music.

25:07 At one… JACK: What?

25:08 Your music is in The Matrix sequels?

25:10 GREG: Yeah.

25:11 So, I got contacted by a company called Spiderbite Studios,

25:14 and they wanted to make music for The Matrix,

25:17 especially behind-the-scenes Matrix stuff.

25:19 They wanted to do some music there.

25:21 The big thing is they were looking for someone to make

25:25 music for the trailer for the video game The Matrix Online.

25:29 [Music] So, they sent me an e-mail and they were like,

25:33 hey, your music sounds great.

25:35 So, that was my first example of being

25:38 exploited in a contract by a large company.

25:41 I sold my music rights for $400 each.

25:44 I think I got $4,000 total out of that deal.

25:48 So, I was like, I’m $4,000 richer.

25:50 That is awesome.

25:51 After that, that got into— a lot of people asked me to do music and go touring.

25:57 So, I did a European tour.

25:58 It was all throughout Europe.

26:00 I think I went to every country except for Latvia and Lithuania.

26:03 Toured for a while and I came back… JACK: What are you playing here?

26:07 GREG: Synthesizer.

26:07 It was a one-man project.

26:08 So, I did— I love synthesizers.

26:10 At one point I owned over eighty of them.

26:14 So, yeah, after that, I came back.

26:17 After a long tour time, I came back to Arizona.

26:20 I was homeless for a while because you only make $30,000 as a musician,

26:24 average, a year at that time, especially an industrial musician.

26:26 You don’t make any money.

26:28 So, I came back homeless,

26:29 and then I lucked out in getting a job working at Massage Envy.

26:34 JACK: Massage Envy is a massage parlor,

26:36 but it’s a chain and they have over a thousand locations all over the US,

26:41 and their headquarters are in Scottsdale, Arizona,

26:43 and they needed someone to work on the back end of their booking system.

26:47 They gave Greg a shot, and he excelled at it.

26:49 GREG: It was all vb.net and ASP code back end.

26:53 So, I was coding that, and I was breaking software in the meantime.

26:59 Millworm— so, I was coding exploits on Millworm and just throwing them up there,

27:04 and I was literally trying to throw an exploit up there a day.

27:09 I remember I got an e-mail from eEye,

27:13 [music] and they were like, you're cracked.

27:15 What is going— like, what are you doing?

27:18 Where do you work at?

27:19 Tell us about you.

27:20 I was like, well, I’m a software developer in the middle of Phoenix, Arizona.

27:23 I work on Massage Envy’s back end.

27:25 They couldn't believe it.

27:26 They were like, what?

27:27 You're not in security at all?

27:29 I was like, no.

27:29 I was just like, I just break stuff for fun.

27:32 JACK: eEye was a cybersecurity company based in California.

27:35 It’s spelled E-E-Y-E, eEye.

27:37 They created some tools to help people be more secure.

27:41 Like, they made a vulnerability scanner,

27:43 and that’s how they were able to make money.

27:45 So, eEye saw that Greg was writing a lot of malware and posting it publicly,

27:50 and they liked that and decided to hire him,

27:53 and flew him out to California to give him a job.

27:55 GREG: Yeah, well, the team I was on, we

27:58 were all about finding zero-days and finding exploits.

28:00 JACK: Yeah, but there’s no money in that.

28:02 GREG: Marketing, my friend.

28:03 When you have a good research team and they're rockstars,

28:05 they're gonna look at you and your product and think,

28:08 oh man, those guys know what they're doing.

28:10 So, yeah, when I got there, the person I replaced was Barnaby Jack.

28:14 I took— I actually had his desk and everything, man.

28:17 JACK: Wow.

28:18 GREG: Yeah, yeah.

28:20 Lots of respect to him, man.

28:23 It was— I never filled his shoes,

28:27 but it was just an honor to be a part of— you know, be around him.

28:32 I got to meet him multiple times.

28:33 He was a great guy.

28:34 JACK: See, back then, nobody had a bug bounty program.

28:37 If you found a vulnerability in some software,

28:39 that company wouldn't pay you anything.

28:41 You'd be lucky if they sent you a t-shirt.

28:44 There was zero money in vulnerability research then.

28:47 But the reason eEye did this research to try

28:50 to find vulnerabilities in software was for two important reasons.

28:55 One, to earn credibility.

28:58 eEye company must have some pretty sharp

29:00 researchers to constantly be finding vulnerabilities in things.

29:03 I bet their tools are great.

29:05 It works.

29:06 Two, recruitment.

29:07 By making the news again and again that they keep finding vulnerabilities,

29:12 top talent would want to come work there.

29:16 Now, they did follow responsible disclosure.

29:17 When they'd find a vulnerability, they would do two things; first,

29:21 tell the software maker and show them exactly what they found.

29:25 Then they would announce publicly that they found a vulnerability in a product.

29:29 They wouldn't say what the vulnerability was, though;

29:31 not until after the software company was able to fix it and patch it.

29:36 So, that was the team that Greg joined,

29:38 to simply find new bugs in software that nobody knows about,

29:41 which is what’s known as a zero-day vulnerability.

29:45 GREG: So, I get there,

29:47 and Office drops— Office 2007 drops probably about four weeks— like,

29:55 within my first month of working there.

29:57 We were looking at other software.

29:58 We were looking at, I think,

30:00 CA Arcserve Backup, if you remember that terrible product.

30:03 I have— as a macro virus author and— I

30:06 can look at Office— hex editors in Office;

30:10 I could tell you where the blobs are in Office.

30:13 I know the bit format very, very well.

30:15 So, when it comes to… JACK: So,

30:18 there— your boss or someone told you… GREG: Marc Maiffret, yes.

30:24 We’ll put his name for the record here.

30:27 [Laughs] JACK: Marc Maiffret; I’ve heard that name before.

30:30 GREG: If you don’t know,

30:31 Marc Maiffret got famous from MTV’s True Life of a Hacker.

30:35 [Music] That’s where— that was his claim to fame.

30:37 He was on that.

30:38 MARC: You know, over the last few years

30:40 and basically ever since I got into hacking,

30:43 it’s just been kinda like a wild ride or somewhat of a movie.

30:47 After the raid, started thinking a lot different about my life

30:51 and what I wanted to start doing with it and turn things around.

30:55 MTV: These days, Chameleon is living the hacker dream,

30:59 creating security software for companies to protect

31:02 themselves from people just like him.

31:04 JACK: [Background talk] That was a clip

31:07 from the MTV show called True Life Hacker from 1999.

31:10 The show follows Marc around as he hacks stuff.

31:13 He was wild back then.

31:15 So, I imagine it’d be really crazy to have him as a boss.

31:19 So, your boss told you Office 2007 just came out.

31:22 Do you want to take a look at it?

31:23 It’d be great if you could find some sort of virus

31:25 or bug— or, not a virus but a exploit in there,

31:29 a bug that we could use for Marketing… GREG: Absolutely.

31:31 JACK: …and make a big deal about.

31:33 So, jump in there.

31:34 You were assigned to do that.

31:35 GREG: Yeah, that’s exactly how it worked.

31:37 Anything that came out, any big thing— we were essentially bounty hunters.

31:41 We would go out and be like, yeah, let’s go break this thing.

31:44 If we have… JACK: Yeah, but there wasn’t paid bounties back then.

31:47 You'd get a t-shirt if anything.

31:49 GREG: It was all about the honor of being the first.

31:52 We wanted to be the first, too.

31:54 That was a big deal.

31:54 JACK: Yeah, the honor was a reward.

31:56 GREG: Yup.

31:56 It was be the people who first found a bug.

32:00 So, I went in there and started manually fuzzing Word at the time.

32:08 JACK: [Music] Fuzzing; the first time I did fuzzing was when I was five years

32:13 old and I went to the supermarket and they had a gumball machine.

32:16 My mom gave me a dime and showed me how you

32:19 put it in and you turn the crank and you get candy.

32:23 It was awesome.

32:24 For years I was drawn to them.

32:26 I just had to touch them every time I saw them and check them out.

32:30 I would try turning the crank on every one to see

32:32 if it would just give me candy with no money in it.

32:35 Nope.

32:35 Unless you put money in it, the crank won't turn.

32:37 I would sometimes try to put money in it and turn it

32:40 very slowly to see if I could get a little bit of candy, and as soon as I do,

32:45 turn it back real quick to reset it and do it again, but that didn’t work.

32:49 I would check the dispenser chutes to see if anyone left candy behind there,

32:52 and yes, sometimes they did, and that was cool, a bit of free candy.

32:56 I would shake the machine sometimes to see if

32:58 I could get candy to come out that way, and that did sometimes work, too.

33:01 But then I was like, how does it know I put money in here?

33:04 Like, how does it know what a quarter or a nickel or a dime actually is?

33:09 So, I started jamming anything I could find that would fit in there;

33:12 plastic pieces, metal washers, cardboard, shoelaces.

33:15 I’d shove it in, I’d turn the crank, and I would see what happens.

33:20 I’m telling you, from five years old all the way to fifteen years old,

33:24 I was fiddling with these things every time I saw one.

33:28 That, to me, is what fuzzing is.

33:30 It’s trying to use the tool or machine or application in ways it’s not supposed

33:35 to be used to see if you could glitch it or somehow get it to act weird.

33:40 What Greg was doing was he was opening Microsoft Word

33:43 and trying to put something in a Word document that wasn’t allowed.

33:46 I don't know, maybe trying to put a Chinese

33:49 letter in there or some strange ASCII symbol.

33:51 Word would accept some of these characters but then just deny others.

33:54 Now, if Word won't let you input a strange character, why?

33:58 Will it break if you somehow force it to take that strange character?

34:02 Well, Greg wanted to try.

34:04 So, he opened up a Word doc, not in Microsoft, though;

34:07 in a hex editor where you can manipulate

34:10 the ones and zeros directly in the file, almost like doing surgery on the file,

34:14 and he put in a character directly

34:16 into the file that he knows Microsoft Word can't accept,

34:19 and then he’d save it and try to open it up in Word to see what it would do.

34:25 Nothing.

34:26 Okay, fine.

34:26 That didn’t work.

34:27 But let’s try again.

34:29 This time, let’s see what the max font size is in Word.

34:32 16.38.

34:33 Well, that’s pretty big.

34:34 Okay, so, Word won't let you make a font size bigger than that number.

34:38 Challenge accepted.

34:39 Let’s set the font to the max, 16.38, close down Word,

34:42 open up the file in a hex editor, look for where that number is.

34:46 16.38, where does that show up?

34:49 Ah, right there.

34:50 Maybe that means the font size.

34:53 So, let’s change that to 9999 and save it and open

34:56 it up in Word and be like, what now, Word?

34:59 You wouldn't let me set the font bigger, but I did.

35:02 What are you gonna do?

35:03 Nothing.

35:03 It just reverts back to the default font size.

35:06 It had some sort of logic to handle what

35:08 happens with a font size that we can't accept.

35:11 That is what fuzzing is, and that’s what Greg was tasked with doing,

35:16 to try to make the brand-new Microsoft Office 2007 Suite crash.

35:20 It’s really a hunt to try to see if the developers at Microsoft accounted

35:26 for every single problem that could possibly

35:28 go wrong in Word and handle it gracefully.

35:31 GREG: So, you're modifying these files at the lowest

35:34 level possible and you're introducing all this unexpected code,

35:37 unexpected code paths.

35:38 It’s parsing these files and it’s parsing these files;

35:41 it’s encountering these unexpected data points.

35:43 These unexpected data points are introducing areas

35:46 of opportunity for you to find a vulnerability.

35:50 JACK: Basically, the goal is to get Word to execute malicious code,

35:54 such as giving someone else control of that computer.

35:57 But you can't just put malicious code in a Word

36:00 doc and then when someone opens it, it runs.

36:02 Word doesn't execute code like that.

36:04 It just displays it as text.

36:06 That’s its job.

36:07 So, can you hide this malicious code somewhere in the Word

36:10 document that it will also get executed when Word gets opened?

36:14 No, not really that, either.

36:16 Yeah, there’s macros that act like code, but that’s different.

36:19 What we want is for Word to take our malicious

36:22 little code and stick it into the memory of the computer.

36:26 So, the goal is to cause Word to crash,

36:29 but then use that crash to force malicious code

36:32 into memory or a pointer that references the code into memory.

36:35 [Music] Now, just opening Word is not

36:37 enough to see all the stuff that’s happening.

36:39 You want extra visibility on how well Word is behaving,

36:42 what stuff it’s putting into memory and everything.

36:45 That’s where a debugger comes in.

36:46 At the time, he was using a debugger called Olly,

36:49 which would show him a lot more details of what Word is actually doing.

36:53 GREG: Correct.

36:53 Olly is a tool that you attach to your— any

36:56 application that you want to see at low level, assembly level.

36:59 You want to see what the code’s actually doing,

37:01 your registers and your memory output and what’s going on with the application.

37:05 You attach a debugger; that allows… JACK: Sounds like a wrapper for the app.

37:08 So, you open Olly and then tell Olly to open this, and then Olly would be like,

37:12 I will watch all the memory… GREG: Exactly.

37:13 JACK: …everything that’s happening here and tell you everything.

37:15 GREG: That is a great summary of that, and that’s exactly what it does.

37:18 JACK: It sounds a bit tedious to open a file in a hex editor,

37:22 manually change one or two numbers, then close it,

37:25 and then open Word up and then see how it behaves;

37:28 and nothing, so just close it all and try again.

37:31 So, all day he’s editing these files,

37:33 opening them in Word, and then closing them.

37:35 GREG: I just really liked looking at the files in the hex editor,

37:39 modifying the files, opening the file, and noticing the UI change.

37:43 It would distort the— it would— if you had your Office file,

37:46 if you had graphics and stuff in there,

37:48 it would distort it or make it look wrong 'cause it’s rendering improperly.

37:52 So, you could actually get better feedback, I found,

37:56 by doing it that way, to identify where in the file you're affecting.

38:01 So, I did this for like, two days, and all of a sudden I had a crash.

38:05 JACK: Ooh, a crash.

38:07 This is what he’s been trying to create.

38:10 Okay, first thing’s first; will it crash every time?

38:13 Yes.

38:13 Awesome.

38:14 Okay, it wasn’t a fluke.

38:16 Next, can he inject code into memory when it crashes?

38:19 Yes.

38:19 Wow, this is great.

38:21 Now he has to see if he can get control of a pointer

38:25 or inject some shell code into memory along with this crash.

38:28 Yes, he can.

38:29 GREG: It was a classic crash at that time

38:32 where you overwrote a data pointer and you

38:35 could control the data pointer at that, which

38:38 is— allows— that’s the basis for remote code execution.

38:43 JACK: So, what he’s discovered is he can craft

38:45 a malicious Word doc so that when the user opens it,

38:48 Word crashes, but then malicious code is put into memory,

38:52 and now the system is severely weakened.

38:54 It’s vulnerable.

38:55 Wow, very cool, all within weeks of Microsoft Office coming out.

39:00 Greg has discovered a pretty serious vulnerability in it,

39:03 which allows arbitrary code execution.

39:05 He feels great.

39:07 His team is impressed.

39:09 So, you tell your coworker, your coworker tells your boss,

39:12 you tell your boss, whatever, and what does your company do with this?

39:16 GREG: My boss is like, awesome.

39:19 He immediately starts writing all the press.

39:23 Marc Maiffret is— if you know him, he’s very enthusiastic.

39:26 He’s just like, oh my god, we're gonna fuck— this is gonna be fucking awesome.

39:31 We're gonna send this to the press.

39:32 We're gonna throw this out there.

39:34 So, he immediately starts writing to everyone,

39:36 all these typical— you know, the tech writing— the tech writers.

39:40 So, they immediately start writing, and then we report to Microsoft.

39:43 JACK: Again, they aren't sharing exactly what the vulnerability is to the press.

39:47 They're just telling them that eEye found another zero-day,

39:50 this time in the latest Microsoft Office,

39:53 and of course only giving Microsoft the full details so they can fix it.

39:57 Once it’s fixed, then eEye will show the world how it was done.

40:00 The news spread fast.

40:02 A few big tech publications were talking about this zero-day that Greg found.

40:06 GREG: Three days later we get a e-mail back from Microsoft and it says,

40:12 hey, we can't reproduce this.

40:14 [Music] We're like, this is typical.

40:16 This is— we’ve dealt with this before.

40:19 This is a typical Microsoft security response, response team typical action.

40:23 So, they're like, okay.

40:24 So, we send them— we send the sample again and we're like,

40:28 hey, you know— we show the debug output.

40:30 We show— and then another day after that, it comes back,

40:35 and they're like, hey, did you try this without a debugger attached?

40:40 Marc Maiffret is like, of course we did.

40:43 Then he looks over to Andre; Andre looks at me, and I’m like, I don't think so.

40:53 So, we go run it again, and there is a special trap that Microsoft added.

41:00 This is— at the time,

41:02 this was pretty new technology where they had debug-only routing inside Office.

41:07 So, it would reach a code flow path that was only exploitable,

41:13 only triggerable when you had a debug attached to the Word,

41:18 meaning no one’s gonna be vulnerable to this unless they have a debug attached,

41:24 unless they're a security researcher.

41:26 JACK: Oh man.

41:27 How embarrassing.

41:28 The news is out there saying that eEye found a serious vulnerability,

41:34 but now it turns out they don’t actually have a vulnerability.

41:39 It’s because this new kid, this weird-looking goth kid,

41:42 didn’t verify it all the way.

41:45 GREG: So, I remember there was yelling.

41:49 There was yelling involved.

41:51 I remember I was there for three weeks

41:56 and I remember just— literally just staring down,

41:59 being ashamed, just being like, oh god.

42:02 This is it.

42:03 This is how I lose my career.

42:05 It was nice.

42:06 It was a good couple months in security.

42:09 JACK: Okay, 'cause the stress here is

42:11 because a press release was written, right?

42:14 GREG: Yes, yes.

42:15 eEye at the time was— they're like the rockstars.

42:18 This is— everyone else in the room,

42:21 all those rockstars; Yugi, Derek, Daniel Soder,

42:24 the brothers, everyone else in there

42:27 has written vulnerabilities in a professional manner.

42:29 They've all done this for years.

42:31 They've found the first Vista vulnerability.

42:33 They found— this is their thing.

42:36 Now I’m the new guy who screwed up and made them look bad.

42:42 So, behind the closed door, they were like, we gotta fire this guy.

42:48 Luckily for me, I believe Andre was like, nah, dude, we gotta give him a chance.

42:52 He’s gotta— we're gonna give him a chance to make this right.

42:58 So, they come out and they were like, look, man, you gotta find a vulnerability.

43:03 We don’t care how you do it.

43:05 It’s gotta happen.

43:06 I’m like, okay.

43:07 JACK: There’s some hope still.

43:09 The press release just said they found a vulnerability in Microsoft Office,

43:13 which consists of Excel, Word, PowerPoint, Visio, and more.

43:17 It didn’t give any details as to how the vulnerability works.

43:22 So, if they can find a bug in any of these products,

43:27 it’ll save the reputation of the company.

43:29 But to be clear, for a young guy in his first

43:33 cybersecurity job to find a zero-day vulnerability in Microsoft Office,

43:38 that’s an incredibly complicated task.

43:40 The entire team of coders at Microsoft worked tirelessly

43:44 to prevent people like him from finding bugs like that.

43:48 So, he’s gotta find something they missed?

43:51 This was a big deal for Greg.

43:53 [Music] He needed to find a zero-day vulnerability

43:56 in Microsoft Office or else he’s going to be fired.

44:00 He calls his girlfriend and says, don’t wait up for me tonight.

44:03 I am going to be working late.

44:05 Sorry, I just have to do this.

44:07 He just gets down right into the zone, downing energy drinks,

44:11 grabbing extra monitors to be more productive, ordering pizza right to his desk.

44:15 He’s fully committed to doing this.

44:17 He was so committed that he was going to stay

44:20 in that office until he found a zero-day vulnerability.

44:23 GREG: So, I am there twenty-four hours by myself,

44:27 just manually— and I’m just like, oh god, I can't do it.

44:31 JACK: He’s sleeping under his desk, he’s living off of donuts and coffee.

44:34 GREG: So, what happened here, man, was— so,

44:37 the crew comes up to me and they're like,

44:39 dude, we're not gonna let you do this by yourself.

44:42 We got your back.

44:43 So, everyone stayed in there, and we were in there for three days.

44:48 Man, I— that— I remember girlfriends calling,

44:52 wives calling guys and being like, are you guys coming home yet?

44:55 They're like, no, we gotta do this.

44:56 This is an important thing.

44:58 We ordered pizza.

44:59 We had Mountain Dew.

45:01 That area of the office, I remember, it was not smelling great.

45:06 The other teams were like, what are you guys doing?

45:09 What is going on in here?

45:10 JACK: Are you just like, opening text files in edit and then close,

45:13 and then open, and then close?

45:14 GREG: We have— okay, so, I think during that time— so,

45:17 there’s at least six of us.

45:19 We have one guy who’s writing his own program to fuzz it.

45:23 We have— I think Yugi had three screens up fuzzing data, reverse-engineering.

45:27 He’s trying to reverse-engineer that.

45:29 I have a program I have written running on one machine over here.

45:32 I have a machine to my left.

45:34 I have a machine left to me that’s

45:35 running software to try to find this vulnerability.

45:37 I’m in a hex editor editing files left and right.

45:40 I think Derek was also editing files.

45:42 Derek found— was finding something else.

45:45 He found— I think he later found another vulnerability

45:47 out of this, but he’s going in there editing,

45:49 looking at this, and we're all look—

45:51 everything we find is really interesting stuff,

45:53 which turns out it was— we found a lot

45:55 of really cool stuff in Office at the time,

45:57 but none of it was a vulnerability as we described.

45:59 So, we are literally just sitting there

46:02 geeking out and just— pizza being ordered.

46:04 eEye was a wild time.

46:06 JACK: Days go by like this where all

46:09 the researchers are pouring tons of time into this.

46:12 Nobody was going home.

46:13 People were sleeping in shifts under their desks, in the break room.

46:17 The energy was amazing to have so many people come

46:20 together to try to save the reputation of the company.

46:23 GREG: Day three, I was modifying a file, and all of a sudden it popped.

46:32 We look at it and we're like, oh, wait.

46:36 I remember Yugi— Yugi looks at it first and he’s like— Yugi is this incredibly,

46:43 unbelievably talented Japanese hacker.

46:45 He’s like, oh, it looks good.

46:47 When Yugi says it’s good, everyone’s like, okay.

46:50 So— and the first thing that happens after

46:52 that is— I remember one of the guys was like, is the debugger detached?

46:56 We're like, oh yeah, get that thing off there.

46:58 So, retry it, and it happens to be in Office Visio.

47:02 It was another product inside the Office suite.

47:05 So, it wasn’t Word, not as sexy as Word, but, hey, we only said Office 2007.

47:11 So, again, saved our butt.

47:13 So— and the thing is, when Microsoft sent that e-mail, they were like,

47:18 hey, man, this vulnerability occurs in this wrapper function called safent.

47:23 What safent does is it prevents the integer

47:27 overflow from occurring and causing that control flow,

47:31 your code execution, to occur.

47:32 So, it checks all the integers.

47:34 [Music] What happened with the new vulnerability

47:36 we found was we happened— just happened

47:39 to have found a legacy pointer for a integer

47:43 that was not safented-wrapped and was vulnerable.

47:46 So, they sent that e-mail out,

47:49 and unfortunately, David LeBlanc in Microsoft— David,

47:53 if you're listening to this, I’m sorry, man— I think he was on vacation.

47:58 He got called back.

47:59 Maybe he didn’t get called back, but that’s what I heard,

48:02 'cause he was the one who was in charge of safent.

48:04 Safent was his baby, and it’s an awesome security feature.

48:08 He got called back because when we sent that sample to Microsoft and it worked,

48:14 that was a big deal to them.

48:17 So, we are all happy.

48:19 The vulnerability goes out.

48:21 A couple months later it gets disclosed,

48:24 and we have indeed the first vulnerability in Microsoft Office.

48:29 That was the case.

48:31 That was a wild time, to say the least.

48:36 JACK: He saved his butt on that one.

48:39 His whole career was on the line, and he did what he had to do to save it.

48:44 Being awake for so long wasn’t much of a celebration after he found it.

48:48 GREG: Dude, I crashed.

48:49 I fell asleep.

48:50 I remember being— just being so exhausted,

48:52 I straight— at the time when I found it,

48:55 I was already tired because I was half-asleep.

48:56 I remember the alarm that I had for it to find it,

48:59 I nearly spilled— I think I did spill soda all over the place,

49:03 'cause I was just waking up— like,

49:04 we're all fasting out— like, we're literally sleeping at our desk here.

49:07 There’s no— we're not sleeping on hammocks or anything.

49:09 We're just sleeping at our desk.

49:10 So, I remember it being— like, we find the— we're like, yes,

49:15 and we were all so tired to actually have a proper— I guess

49:20 we did have a proper— we did yell out extremely— a malware— like,

49:24 yes, we're finally— and then immediately after— 'cause we're like,

49:27 we're celebrating, high-fiving, everything was like that.

49:29 But man, after that, I just remember us all being like, and we're going home.

49:34 I fell asleep at the office.

49:35 I didn’t even make it home at the time,

49:37 'cause I had to— I lived walking distance.

49:39 I was too tired to even walk home that day.

49:41 So, I just crashed out, woke up, went home,

49:45 and I remember my girlfriend just drew me— the pillow and the blanket,

49:51 and I was on the couch for like a week for that one, rightfully so.

49:56 She was so pissed.

49:57 JACK: But it was your job on the line.

50:00 She should understand that.

50:01 Like, listen, I’m gonna get fired or I could stay three days and not see you.

50:05 What would you rather I do?

50:06 GREG: Oh man, I was a newly father.

50:08 My kid was probably… JACK: Okay.

50:12 GREG: [Laughs] Yeah.

50:13 My kid… JACK: Well, hold on, so you just had a kid at the time.

50:16 GREG: My kid when I started, yeah, was six months old.

50:19 So, that kid was not even a year old,

50:22 and colic— and my kid was extreme colic, like twelve hours a day crying.

50:26 Oh man, she was so mad.

50:28 JACK: Oh, that’s— that makes it even more stressful.

50:33 GREG: Oh yeah.

50:34 Oh, oh yeah.

50:36 But yeah, so— oof, yeah, that was— I remember the e-mails— that was— oh,

50:43 the e-mails I was getting from her was always popping up,

50:45 just being like— her just getting angrier and angrier as the day is going on.

50:49 She’s like, where are you?

50:51 Like, I don't believe you're at work for three days doing this.

50:53 I was like, okay, I’ll send you a picture of us.

50:56 We had the team just doing random pictures.

50:59 I was like, oh man, this is— this was a time.

51:04 JACK: [Music] eEye was a magic place.

51:07 A lot of amazing talent worked there,

51:09 and many went off to start their own cybersecurity businesses.

51:12 Rumor has it that some of the anecdotes from the TV

51:15 show Silicon Valley came from stories that happened at eEye.

51:17 Greg learned a ton from working there for years.

51:20 GREG: So, years later— god, this is like my third year at eEye.

51:27 I remember we had a honeypot system,

51:31 which— it’s a system that’s designed to catch hackers and lure in individuals.

51:36 We tried to— we were trying to get zero-day exploits

51:39 and definitely try to lure people into attacking the system.

51:41 It was one of the largest honeypots at the time.

51:44 It was nearly a Class B internet group of honeypots.

51:47 It was massive.

51:48 I remember I was logging into one of the systems that we

51:54 had maintained for that, and I see a log-in called Lfeng.

52:00 I was just like, what is this?

52:03 Who’s account is this?

52:04 Maybe this is a new hire I just don’t know about.

52:08 I walk into my boss’ office and I was like, hey, I got that all set up.

52:15 However, there was someone who logged in recently,

52:19 and maybe it’s someone we hired in dev ops or something.

52:22 Do you know a Lfeng?

52:24 I remember my boss was just typing.

52:27 All of a sudden I remember the distinct sound of him stopping

52:31 and the sound of the chair creaking back and him looking at me.

52:36 He’s like, you found what?

52:38 Who?

52:39 I was like, yeah, Lfeng.

52:41 I think I looked at— the extended name was Li Feng.

52:46 He was like, what do you mean you found a Li Feng log-in?

52:51 I was like, yeah, it’s on the honeypot system.

52:53 It was— it looks like it was a maintainer.

52:56 He goes and he closes the door behind me and he’s like,

52:59 alright, I’m gonna tell you a story about Li Feng.

53:02 I was like, okay, let’s hear about it.

53:06 So, back in the day, like I mentioned,

53:09 eEye was the rockstar group for finding vulnerabilities.

53:13 It was like, eEye and I-Defense.

53:15 That was the two big companies back

53:19 in the day for finding zero-day vulnerabilities.

53:24 At one point, eEye was so good at what they were doing,

53:31 Microsoft decided to hire someone in order to go work

53:37 at eEye in order to get them to tell them,

53:41 Microsoft, about the zero-days they found in Microsoft.

53:45 JACK: Wait, wait, what— hold on a second.

53:49 You're saying Microsoft got someone to— a job at eEye… GREG:

53:55 It was a different time.

53:56 JACK: …so that they could— but they worked for Microsoft

53:58 so they could report to Microsoft what eEye is working on.

54:00 GREG: It was a different time.

54:02 Yep.

54:03 JACK: This is ridiculous.

54:04 You don’t hear about this ever.

54:07 GREG: It was a different time.

54:08 JACK: Did this news ever actually go public?

54:11 GREG: I don't think so.

54:12 This is… JACK: I can't imagine Microsoft hiring

54:16 to work— getting people to work at a other company; this is corporate espionage.

54:21 GREG: That’s correct.

54:23 [Music] Well, it gets even better.

54:26 It gets even better after that.

54:28 It gets even better after that.

54:30 JACK: Okay, so Microsoft hires Li Feng to work for them,

54:35 but then plants him in eEye to go find

54:39 out what they're working on and report back to Microsoft.

54:42 So, Li Feng was working at eEye for a while,

54:45 but then suddenly left, and nobody really knows why.

54:48 He just disappeared one day.

54:49 GREG: But then Microsoft, sometime after he left,

54:51 they're like, hey, we gotta have a talk.

54:53 We gotta have a conversation.

54:55 So, we're like, okay.

54:57 So, Microsoft was like, so, Li Feng,

55:01 he was working for us to identify zero-days that you guys may have found.

55:07 JACK: Which had to be a bombshell for your company to hear.

55:10 GREG: I think… JACK: They thought that must have… GREG:

55:13 I think they had suspicions that he was being a little odd, but— so,

55:17 Microsoft then goes to say, so,

55:20 apparently he was also working for a foreign government

55:25 entity to do the same for us and you.

55:30 So…[laughs] JACK: So, someone placed him in Microsoft?

55:35 GREG: Correct, correct.

55:36 JACK: Go get a job there and… GREG: And then he got chosen to go work for us.

55:40 We hired him, and he got planted,

55:42 and then he was siphoning zero-days from not only us;

55:46 apparently he also had privy information at Microsoft,

55:49 and that went back to his foreign government that he was ultimately working for.

55:57 JACK: Holy moly, someone planted him at Microsoft

56:00 and then Microsoft planted him at eEye?

56:02 That’s unreal.

56:03 How embarrassing for Microsoft.

56:05 It’s like being caught doing something you shouldn't have been doing, like,

56:09 I don't know, having your pants down when the elevator door opens.

56:12 They know they shouldn't have been playing that game,

56:14 but now they realized that they got played themselves.

56:18 Oof.

56:18 So, I really wanted to confirm this story,

56:21 and I reached out to people that I know

56:23 who have been at Microsoft for a very long time,

56:26 and all of them said that does not sound like something Microsoft would do.

56:30 So, I can't confirm that that story is true,

56:32 but I would love to know if it is or isn't.

56:35 So, if you have information about Microsoft planting

56:37 people in other companies, tell me about it.

56:40 Because here’s the thing; we know corporate espionage is happening.

56:43 There’s people sending secrets back and forth to tech giants all the time,

56:47 but it’s a secret, so we don’t know about it.

56:49 We only know about the ones who get caught.

56:52 So, it seems plausible like something like that could happen.

56:55 You know what?

56:57 I’m curious what corporate espionage stories are out there.

57:01 Taking a quick peek, there seems to be some cool ones.

57:04 In fact, I think I’m gonna take an ad break and look at this a little deeper,

57:09 because I’m fascinated by corporate espionage,

57:10 and I might have to do a few episodes on that sort of stuff.

57:14 But stay with us because after the break,

57:15 Greg is gonna tell us some penetration testing stories that he’s done.

57:20 After a while, Greg left eEye and started doing red-team stuff.

57:25 That is penetration testing, breaking into companies to test their security.

57:29 He also does threat intelligence, which he tells me he got some really

57:35 interesting contacts and worked at some very interesting places.

57:38 But we're gonna have to skip those stories

57:41 because they're too sensitive to talk about.

57:43 But he is willing to tell us a few pen test stories that he did go on.

57:48 The first story is about a time when he was paid to try

57:51 to hack into a major tech firm which has a lot of user data.

57:54 I mean, they have millions of users.

57:56 But not just simple user data; they’ve collected highly personal information

58:00 on their users as part of their service.

58:03 So, Greg meets with the customer, and it started out weird from the get go.

58:07 The customer was saying, look, we are crazy about security.

58:10 We go over the top on cybersecurity because

58:12 we cannot risk our user data getting out.

58:15 So, we don’t think you're going to find anything.

58:18 In fact, the last pen testing company struggled so

58:21 bad to try to hack us that they got arrested.

58:24 GREG: [Music] So, they use a third-party payment

58:26 processing system that is not used by them,

58:29 and their previous pen testers accidentally exploited

58:32 the third-party payment system that was vital to them.

58:35 The third-party payment system was an Oracle system

58:39 and not owned by the customer at all.

58:42 So, when— apparently— that’s why I heard from the customer;

58:46 they were— they did their exploitation and then they said,

58:50 hey, we got into credit cards and we're gonna present

58:54 it to you in the next day in a presentation.

58:57 So, they got the blue team there, all the blue team,

59:01 all the people, and then he presented them and said, hey, we exploited this.

59:05 We exploited this IP address.

59:07 We got access.

59:08 We gain it.

59:09 Here is your raw credit card details.

59:12 As you can imagine, the team looks at it and they're like, what IP is that?

59:17 That’s not local.

59:18 That’s not— it’s a ten— it’s a local address, but that’s not ran by us.

59:23 That is not.

59:24 Then they found it was actually owned by the third-party payment system,

59:27 and they had exploited a zero-day and that gained access to there.

59:31 On top of that, the credit card details were

59:33 now— it was a stream of credit card details.

59:36 So, I believe it was outside of even scope for the customer.

59:39 So, the customer reported them on the safety of their half 'cause

59:43 they didn’t want to think that someone on their network compromised them,

59:47 and reported them to the law enforcement authorities.

59:49 I believe that led to the arrest of them.

59:53 Either way, that was— that’s always wonderful to hear going into a pen test.

59:57 You hear, hey, the previous guys got arrested.

59:59 Why don’t you guys come in here?

1:00:03 So, great start already.

1:00:05 Great start.

1:00:05 [Music] So, if you know me, I still dress like a goth kid.

1:00:11 I’m still all black.

1:00:12 I’m cyber-punked out.

1:00:14 I wear Neo4ic; love them.

1:00:16 I’ll wear everything from vx-underground, all black, anything I can.

1:00:20 So, I show up at this facility— oh, and at this time,

1:00:24 we also have a coworker of mine,

1:00:25 and my— this is my coworker’s first big— real big pen test.

1:00:29 So, he comes in, too, and I will never forget the people there because they look

1:00:35 at me and they look at each other and they're like,

1:00:39 oh god, we gotta put you guys in the back room.

1:00:41 So, they set us a separate room away from everyone else.

1:00:46 Throughout my career, this is kinda the thing.

1:00:48 I’m the guy in the back room.

1:00:50 I’ve been there because of how I am.

1:00:51 So, they sent us back there, and this is a five-day insider-threat pen test.

1:01:01 Go.

1:01:02 JACK: [Music] So, his job was to simulate an employee

1:01:04 there who had gone rogue or had been hacked.

1:01:07 Just by being in the building, what could he do?

1:01:11 Sniff some Wi-Fi traffic?

1:01:12 Plug into some network ports?

1:01:15 All that’s worth checking out,

1:01:17 but they did give him a single user’s login, and they said,

1:01:21 that user should be locked down so tight that you shouldn't

1:01:24 be able to do any harm even by knowing their password.

1:01:28 GREG: This customer— I’ve been red-teaming a lot of places.

1:01:32 Their blue team, their SOC team is absolutely legit,

1:01:35 one of the best defense teams I’ve ever had the honor of working with.

1:01:41 So, they literally are running their own kind of built-in EDR system

1:01:45 that they built themselves that’s tied into their SOC, going in there.

1:01:50 We get nowhere, man.

1:01:52 Day one; nothing.

1:01:53 Day two; nothing.

1:01:55 Day three; my coworker’s laptop dies in the middle of it,

1:01:58 and he can't even work anymore, and we had to give a report to the customer.

1:02:04 I remember them just looking at us and being like,

1:02:07 I think we hired the wrong people.

1:02:09 Literally, they were like,

1:02:10 do you— you guys want to resign and we can scrap this up,

1:02:14 call it quits, and then we can go hire somewhere else?

1:02:16 I was like, no, man, we got this.

1:02:18 [Music] Day four happens, and we— I remember it was 4:30 and we have

1:02:26 to give— at 5:00 we have to give our meeting,

1:02:30 and my coworker had to go to Best Buy and buy a brand-new machine.

1:02:34 He spent the entire day imaging a machine on a red-team engagement.

1:02:38 He looks at me; he’s like, man, I don't know what to do.

1:02:40 So, I was like, hey,

1:02:41 let’s try one more— let’s do some ARP poisoning and just do one more time.

1:02:48 I remember looking up, and that ARP poison grabbed one plain text

1:02:53 credential that just happened to be an FTP job.

1:02:57 We're like, oh, we got a credential.

1:03:00 We got somewhere.

1:03:01 We got something.

1:03:03 It turns out that credential was to build system process,

1:03:07 and it allowed us to get into the build

1:03:11 system to roll code throughout the entire thing.

1:03:14 It just so happened at 4:30 they rolled it

1:03:18 out to do a end-of-day lockdown and build system configuration,

1:03:21 lock everything down so no one is doing any more builds.

1:03:25 We went into that meeting; said, hey, we just intercepted this.

1:03:30 I remember them all thinking, wait a minute,

1:03:33 that’s the old build— and that credential is still active.

1:03:37 At that point we had a really cool exploit for that one.

1:03:39 We got into the build system,

1:03:40 and they had a lot of controls on the actual files in there.

1:03:44 So, we couldn't modify in the build files, but we could edit the command line.

1:03:48 So, we rolled an inline assembly.net include

1:03:51 in there to roll in, go into their portal,

1:03:54 and steal all the customer data, who’d enter a credit card in there.

1:03:57 We marked it in the data.

1:03:59 We locked out that credit card, but we put a asterisk in there,

1:04:02 *stolen last four digits*, and then had it sent out to them.

1:04:06 They test it, they ran it out, and they were like, holy crap,

1:04:08 we have not had a red team roll out code to production in eight,

1:04:12 nine, ten years that we’re here.

1:04:14 Come back next year.

1:04:16 Come back next year.

1:04:18 JACK: Whew, talk about a Hail Mary.

1:04:19 Not a single find all week, and then 4:30 p.m.

1:04:22 on the last day, they catch a lucky break by sniffing

1:04:25 a credential in the network which gave them tons of access.

1:04:28 What a good find that saved their butts.

1:04:30 GREG: I come back next year, and they’re like,

1:04:32 hey, we want you to do something kinda crazy.

1:04:36 We want you to target DNA.

1:04:39 JACK: [Music] Part of what this company did was genetics studies.

1:04:42 They had DNA data on their users,

1:04:44 and this was regarded as one of the most protected assets of the company.

1:04:49 So, why not hire a hacker to try to find it and steal it?

1:04:52 GREG: We don’t care how you get it.

1:04:56 Any way you can get it, that’s fair game.

1:05:00 So, I spent a week in there as a malicious insider.

1:05:08 JACK: He starts with a basic employee login again.

1:05:12 It is locked down pretty tight,

1:05:14 but it’s just enough for him to get a foothold somewhere else,

1:05:17 and from there he finds an exploit in another system,

1:05:20 and then he was able to pivot from there, collecting more system logins,

1:05:24 and finally he’s able to get in a system which manages backups of machines.

1:05:29 He can see there’s some really large files here.

1:05:33 Maybe those are system snapshots or backups?

1:05:36 But what system is it a backup for?

1:05:39 No idea.

1:05:40 But he decides to try to download it anyway

1:05:42 to see if he can look at what’s in these files.

1:05:45 GREG: It literally errored out on the share size.

1:05:48 I was like, I’ve never seen that before.

1:05:50 I remember clicking a file, and I’m on a local network.

1:05:53 I remember that file taking forever to get to me.

1:05:57 I was like, how big is this?

1:06:00 So, I grab the file and I’m on the local machine,

1:06:03 and I remember looking at it, and it’s TCGA CT, like those letters.

1:06:08 I was just like, I think that’s DNA.

1:06:12 I think that’s DNA.

1:06:14 I was like, huh.

1:06:16 Maybe— this has gotta be— this can't be right.

1:06:20 So, I grab it and I cut off as much as I could.

1:06:25 I remember— and then I sent it over— I work with a biologist.

1:06:29 She was a very, very smart girl,

1:06:30 and she just happened to be a biologist who was working with mice at the time.

1:06:36 She actually knows DNA and she worked with DNA.

1:06:39 I was like, hey, what does this look like to you?

1:06:43 I sent it to her and she looks at it and she’s like, oh,

1:06:47 this is a DNA sequence mapped out by this program,

1:06:50 and this looks like— I was like, oh, okay, cool.

1:06:52 Then she was like, hang on, I could even tell you what kind of DNA this is.

1:06:57 A couple minutes go by and she was like, why do you have human DNA?

1:07:01 I was like, I gotta go.

1:07:03 I gotta— bye!

1:07:04 Click.

1:07:05 So, my next task was like— they were like, you have to get the data out.

1:07:10 You can get in; you had to get access.

1:07:12 We had to get it out.

1:07:14 So, at the time, again, it was ran by a very, very good SOC team.

1:07:20 There was a lot of— the environment I was in was very, very well-restricted.

1:07:26 The only way I got to her was through sending a picture.

1:07:30 I remember selecting it all and then putting it into an app,

1:07:34 sending her a picture of it.

1:07:36 It was so bad quality, I had to send it a couple times, actually.

1:07:40 But so, I was like, how am I gonna get all this data?

1:07:42 I can't do it with a phone.

1:07:43 I can't do it with a picture.

1:07:45 How am I gonna get all this data out?

1:07:47 [Music] I was a malicious insider,

1:07:49 so I was working as a quote, unquote, ā€œIT memberā€.

1:07:53 So, I got introduced to the IT group and they were like,

1:07:56 oh, yeah, you'll be working in this environment.

1:07:58 It’s cool.

1:07:59 So, I was like, I gotta figure out a way I can get a bunch of hard drives,

1:08:03 and I have to get a bunch of hard drives back into the building.

1:08:07 So, what I did was there’s printers that were scheduled

1:08:11 for— to be— these printers were scheduled to be taken to repair.

1:08:16 I remember grabbing one of those printers and gutting it as much as I could.

1:08:21 Walking out, I’m going out to the front desk,

1:08:23 going out the front door and being like,

1:08:25 hey, I gotta send this printer to the repair shop.

1:08:28 It has to be done today, immediately.

1:08:29 So, the front desk people were like, okay, just sign off work.

1:08:32 Cool.

1:08:32 Sign off for the printer.

1:08:34 Load that into the— my rental car, and I go to Best Buy,

1:08:38 and I’m like, I have to get hard drives.

1:08:40 I have to get a lot of hard drives.

1:08:42 So, I went by— and this is back

1:08:45 in the day where external hard drives were those big,

1:08:48 obnoxiously ugly-colored things,

1:08:50 and they came in— I think 32GB or 64GB was a big hard drive at that time.

1:08:59 So, I go through— I have a shopping cart, and I just go from the end line

1:09:03 of these and just pull the whole thing into the shopping cart.

1:09:06 I have a full shopping cart of hard drives.

1:09:08 JACK: You put your arm on the shelf and just…?

1:09:10 GREG: You know that meme where that guy

1:09:12 is running around Best Buy and he’s like,

1:09:13 all— hacked all the things, I hacked all the things?

1:09:16 That was me except with hard drives, shoving it into a shopping cart.

1:09:19 I remember going to Best— the front of the desk,

1:09:24 maxing out my credit card, and then— of hard drives,

1:09:29 and then going back into my hotel

1:09:31 at the time and loading them all into the printer.

1:09:35 I put the shelled out— the hollowed-out printer— I just

1:09:38 stacked the hard drives in there and pulled it up together,

1:09:41 and then I show up to work the next day,

1:09:44 get the little trolley carts they have, go out and say, bring it back.

1:09:50 I remember I’m bringing back the printer, and the front desk person was like,

1:09:56 wait, you sent that off to be fixed yesterday.

1:10:01 I was like, yeah.

1:10:02 He was like, you gotta tell me how you

1:10:05 got those guys to fix that in twenty-four hours because,

1:10:07 man, they are always so slow.

1:10:09 I was like, oh shit.

1:10:11 Well, I bought them a root beer.

1:10:13 They're like, oh, that makes sense.

1:10:15 I was like, I brought them a six pack of root beer.

1:10:19 He was like, ah, okay, good to know.

1:10:21 So, I go back to my area of the building,

1:10:23 putting it— and I have this printer next to me,

1:10:26 and then I am opening up the little panel,

1:10:29 and I am just— USB drive— literally copy, pasting, mounting, copy, pasting.

1:10:34 I started at like, 8:15 a.m.

1:10:37 and I am there until they kicked me out of the building at 9:00 p.m.

1:10:44 doing nothing but moving over data.

1:10:47 Then I leave the printer there,

1:10:50 and for the next two days— I am literally doing this every day.

1:10:55 Then, on my last day of the pen test,

1:10:58 I remember I walk out and I go to the front desk,

1:11:01 and the guy there— he’s still there.

1:11:04 He’s like— I was like, oh, dude, the printer broke again.

1:11:07 He’s like, oh, don't worry, I got something for you.

1:11:10 He goes in the fridge, the little fridge he has,

1:11:12 and he brings out a six pack of root beer.

1:11:15 He’s like, give this to them and tell them I said hi.

1:11:19 I am sitting there trying not to laugh while I’m holding petabytes of— I

1:11:23 can imagine— I think— I don't know how— I couldn't get it all,

1:11:27 but I remember I bought over eighty hard drives from Best Buy.

1:11:30 I think I actually went back a couple days later

1:11:32 and bought some more because I didn’t think I had enough,

1:11:35 and put them in my jacket and my pants,

1:11:38 and I loaded this HP printer and filled that thing up, and got to my hotel.

1:11:43 Then at that point, had— I had a secondary

1:11:46 laptop that I asked— I requested to prove for exfiltration.

1:11:49 I kinda [inaudible] that laptop, I loaded it up and said, done.

1:11:53 JACK: So, when it was time to show him what he found,

1:11:56 he has them go into the room where he was working in and said,

1:11:59 open up the printer.

1:12:00 They open it up, and when they do,

1:12:03 a bunch of hard drives just come pouring out of it.

1:12:07 He says, those hard drives are filled with all your DNA data.

1:12:10 GREG: Yeah.

1:12:11 They later said, hey, you were the first person to do that.

1:12:14 I worked for the red teaming for another—

1:12:17 I think three or four more times after that.

1:12:20 It was— after that it was a call center I attacked— targeted.

1:12:23 JACK: Okay, here’s the big question, though, right;

1:12:26 the first time they're like, you gotta go in the back office.

1:12:29 We can't have that.

1:12:30 After doing it three, four times,

1:12:32 when you're walking through, are you feeling more confident?

1:12:34 Like, oh, no, you can be in the front office.

1:12:35 We don’t mind you being around here.

1:12:36 GREG: Oh man, I went to their barbecues.

1:12:38 I went to their family— they were all very nice.

1:12:41 After the first time, they were like, look, you could never meet the execs,

1:12:49 but we will absolutely hire you every single time.

1:12:54 JACK: [Music] A few years go by of him doing pen tests,

1:12:57 and he gets another job which also has an interesting story.

1:13:00 This time, a venture capital company has hired him to try to hack them.

1:13:04 Now, they wanted to see if he could hack into them

1:13:07 to get data that would influence the market or something

1:13:10 that might hurt the reputation of the company or see if

1:13:13 he can gain information that he can be used against the company.

1:13:16 So, Greg gets tasked with going on site to try

1:13:19 to hack into this venture capital company, which, remember,

1:13:22 even though he’s well into his thirties at this point,

1:13:26 he is still dressing all goth and considers himself a goth kid.

1:13:30 GREG: I’m still a goth kid, man.

1:13:32 I still dress in black.

1:13:34 I still wear my goth— like I said,

1:13:36 I don't wear the colors or anything, but I still dress all black.

1:13:39 I wear my goth outfits.

1:13:40 I wear my vx-underground, my Neo4ic shawls and everything.

1:13:45 I wear my goth boots.

1:13:47 What’s funny is every single contract I’ve signed for work,

1:13:51 I have two clauses in there.

1:13:54 Clause number one; I will never code in Ruby.

1:13:57 Fuck Ruby.

1:13:58 Clause number two; I’ll never adhere to a dress code, period.

1:14:02 Those don’t— if those two don’t happen, I don't work there, period.

1:14:06 So— and that goes back to— I was one of the— when I was in cybersecurity,

1:14:14 I was one of the kids who never went to college for cybersecurity.

1:14:17 So, all these places are like, oh, you gotta get a college degree,

1:14:20 you gotta do all this kinda stuff, and you gotta wear suits.

1:14:23 I was like, no, fuck that, man.

1:14:25 I got— if you don’t hire me for the things I know,

1:14:28 then I don't want to work there.

1:14:29 That’s been a long belief and I still believe that to this very day.

1:14:33 I told my boss, the day that my goth outfit interferes with the way I work,

1:14:40 I will stop doing it.

1:14:41 I still do it to this very day.

1:14:44 It’s been twenty years.

1:14:45 Anyway, so, they send me over, and I remember I get— they're like, hey,

1:14:49 we want you to meet at this outside— it’s

1:14:52 gonna be outside the hotel that we're all staying at.

1:14:57 I walk up to this guy, and this guy is wearing a suit.

1:15:01 He is wearing a suit that costs probably more than what I make in a month.

1:15:06 He’s in there.

1:15:07 He’s smoking a cigarette, clean cut.

1:15:09 The guy looks like he’s still active Secret Service.

1:15:11 I think he even had an ear piece in.

1:15:15 He looks at me and I was like, hey, are you this guy?

1:15:21 We’ll call him Brando.

1:15:23 Are you Brando?

1:15:24 He was just like, yeah.

1:15:26 He’s like, are you Greg?

1:15:28 I was like, yeah, nice to meet you.

1:15:32 I remember he takes the longest drag out of his cigarette.

1:15:37 You know that meme from— what’s that HBO…?

1:15:42 True Detective where the meme of looking at the phone

1:15:45 and the guy is just inhaling the cigarette,

1:15:47 or Matthew McConaughey, I think, is inhaling the cigarette?

1:15:50 I got that exact look from this guy looking at me.

1:15:54 He just tosses that cigarette and he’s like, this is gonna be a long week.

1:15:58 He’s like, let’s go.

1:15:59 JACK: So, this guy is his escort and drives him

1:16:01 to the building where he’s supposed to do the pen test.

1:16:03 He takes Greg to the front door and he tries to go in with his escort.

1:16:08 GREG: I remember physical security is like, sir, who are you?

1:16:11 What are you doing here?

1:16:13 They literally get in front of me.

1:16:15 I was like, no, I’m with Brando over there and I’m part of a assessment.

1:16:20 They're like, give us some ID.

1:16:23 They escort me into the building,

1:16:25 and all of a sudden I’m getting a call from my contact.

1:16:28 He’s like, where are you?

1:16:29 I was like, I’m being detained.

1:16:31 He’s like, oh god, this is a great start.

1:16:34 So, they come over and they realize that I’m supposed to be there,

1:16:38 and then I go meet my contact,

1:16:40 and I remember him looking at me and being like, oh, man.

1:16:44 He’s like, alright, well, you can go work in that back room over there.

1:16:50 We're gonna tell everyone you're an auditor or someone so no one bothers you.

1:16:55 You're gonna set up in this back room, and just don’t bother anyone.

1:16:59 Just go there.

1:17:00 JACK: So, they sat him down and said, okay, hack this place.

1:17:04 He’s like, well, can you give me a user login or something?

1:17:08 No.

1:17:09 Alright, can you give me the Wi-Fi password at least?

1:17:13 No.

1:17:13 Well, listen, I see a bunch of wireless networks,

1:17:16 and I don't want to accidentally hack into the wrong wireless network.

1:17:19 So, can you at least tell me which Wi-Fi network is yours?

1:17:22 GREG: I could see the contact at the venture capital is like, man— it was like,

1:17:28 he looked at me and he wanted me to be

1:17:31 out of this building and to fail as much as possible.

1:17:33 So, he’s like, our guest Wi-Fi ID is this.

1:17:36 Go.

1:17:37 [Music] That’s it.

1:17:38 That’s all I had to go on.

1:17:41 Nothing else.

1:17:41 Just the guest Wi-Fi.

1:17:42 So, I get up and I’m like, okay.

1:17:45 So, I start walking around the building,

1:17:47 and the security team is absolutely following me at every step of this.

1:17:52 Brando from the other third party is like, where are you going?

1:17:55 What’s going on?

1:17:55 I was like, I’m looking for a Wi-Fi password.

1:17:57 He’s like, I think— he’s like,

1:17:59 I’m pretty sure you're supposed to do that with the computer stuff.

1:18:01 I was like, nah, nah, they're gonna have this.

1:18:04 I walk around the building and eventually I find it on a whiteboard.

1:18:08 I’m like, bingo.

1:18:09 So, I go back and I sit down, and now I’m on their guest Wi-Fi network.

1:18:14 JACK: Nice.

1:18:15 How clever; just look around the building for the password.

1:18:18 Alright, so now he’s connected to the guest Wi-Fi.

1:18:21 GREG: So, I get the password, I sit down, and from there I start scanning.

1:18:25 The first thing I go— is I hit the Wi-Fi router.

1:18:30 It’s a Cisco device.

1:18:32 This team— I’ll later learn that this team is very, very good.

1:18:38 However, again, like they mentioned, they've never had a full red team event.

1:18:42 So, the router security is nowhere near where it should be.

1:18:48 It’s actually— the router is a single router, a single Cisco device that is both

1:18:55 the guest Wi-Fi and the internal Wi-Fi as well.

1:19:00 So, I exploit the router, I jump on the router,

1:19:03 and then I make the entire network flat.

1:19:05 I bridge over everything.

1:19:06 So, now my machine can be— can attack anything on the inside of the network.

1:19:11 Even though I’m on the guest Wi-Fi,

1:19:14 I can still start attacking anything on the inside network,

1:19:17 or on certain networks.

1:19:18 They had multiple inside networks, so I start bridging them over one by one.

1:19:21 JACK: How did you exploit the router?

1:19:23 GREG: The router didn’t have— like,

1:19:26 a) their password was default, as— unfortunately.

1:19:29 Number two, I was— they had a administrative password on the panel.

1:19:34 So, the access was one password and then I brute-forced,

1:19:38 I believe, the password of the admin panel.

1:19:42 It was very close to standard password on there.

1:19:46 Gained access, unfortunately.

1:19:48 JACK: So, the guest Wi-Fi should only have very minimal access,

1:19:53 like just to the internet and no internal systems in the building.

1:19:58 But when he bridged the networks,

1:20:00 he could then access anything that other employees could access,

1:20:03 which gives him access to a ton of internal systems.

1:20:06 GREG: There, I start doing man-in-the-middle attacks, and let me tell you,

1:20:10 red teamers out there, pen testers out there,

1:20:13 never skip out on layer two attacks.

1:20:16 Layer two is your responders, your Cain and Abels,

1:20:21 your ARP poisoning, your DHCP spoofing, all of those.

1:20:27 That is gonna be your bread and butter.

1:20:30 I promise you those vulnerabilities are still existing there.

1:20:33 They still work.

1:20:34 I work engagements to this very day— that is where so many places fail.

1:20:40 So, I man-in-the-middle.

1:20:41 Become— I start stealing credentials,

1:20:42 and this is back in the era before SSL security was everywhere,

1:20:46 so you could still do man-in-the-middle and downgrade websites to HTP logins.

1:20:51 [Music] I start getting credentials to people logging into work e-mails.

1:20:58 After about an hour, I get access to a relatively new hire.

1:21:03 She has six months of work in her inbox.

1:21:06 I access her e-mail,

1:21:07 and the first thing I do is I go all the way down to day one.

1:21:12 What do you get in day one?

1:21:15 E-mail.

1:21:16 You get your employee training,

1:21:18 you get your on-boarding information, you get your on-boarding documentation,

1:21:22 and if you come to this building, you get your building alarm code.

1:21:26 So, I have a physical alarm code that goes to her, and I

1:21:30 also have her badge ID number and what she looks like and such.

1:21:34 So, I’m like, okay, so what can I do next?

1:21:38 I remember the— Brando, the— my— the ex-Secret Service guy looking over

1:21:42 my shoulder and he’s like, what are you doing?

1:21:44 He was like— I was like, okay, so, you know the card readers?

1:21:47 Like, yeah; he’s like, we're gonna clone one of these card readers.

1:21:50 He’s at this point where he’s like, alright, goth guy, you're not so bad.

1:21:54 Okay, I like this idea.

1:21:55 He’s like, alright, I’m gonna work with you on this and I’m gonna— he’s like,

1:21:59 I talked with them, and we're gonna talk about

1:22:01 guard shift and times to get into this building.

1:22:03 I was like, okay.

1:22:04 So, I tell him my plan and I was like, man, so I got a building alarm code.

1:22:09 I’m gonna put a RFID cloner next to their badge reader,

1:22:13 and when they badge in, I’m gonna start getting all these badges.

1:22:15 He’s like, okay.

1:22:16 So, a day goes by, and eventually the girl whose building alarm code

1:22:22 comes in, badges in, and I get her— I have a Proxmark system;

1:22:26 I keep pulling it and all of a sudden I notice her ID matches up.

1:22:30 So, now I have her employee ID badge and her building access alarm code.

1:22:34 JACK: To get into this building you need

1:22:36 to use your little badge and tap the badge reader, and the door unlocks.

1:22:39 What Greg did is he put a little badge sniffer behind

1:22:43 the real badge reader so that anytime anyone taps their card,

1:22:46 he gets to see what their badge is,

1:22:48 and that essentially allows him to clone a badge.

1:22:51 GREG: They gave me a tour of the building at one point, very against their will.

1:22:57 They were kinda hushing me around.

1:22:59 The two things I noticed when they gave me that tour was,

1:23:02 a) there was a balcony on the second floor that had a tree next to it,

1:23:08 and from that balcony was a straight shot into their server room.

1:23:11 Basically you go through one room;

1:23:13 in that room you get into— you go down one hallway and you're in a server room,

1:23:18 and the server room did have a badge reader on it.

1:23:21 The second thing I notice is sort

1:23:22 of like— almost like a spiral staircase downward,

1:23:26 there was lots and lots and lots of paintings.

1:23:30 I remember asking during the tour;

1:23:33 I was like, whoa, these look like real paintings.

1:23:37 They nodded.

1:23:38 They're like, yeah, CEO— well, the CEO is here;

1:23:41 loves paintings, and this is their pride and joy.

1:23:45 They like to show art and they like to make sure that— and I was like, huh.

1:23:50 That’s interesting.

1:23:52 That’s cool.

1:23:53 So, I remember— so, for the next couple days, I had to get a badge of an IT guy

1:24:02 'cause I needed to get access to the server room, and eventually I get it.

1:24:06 It’s through the Proxmark system as well.

1:24:08 In the meantime, I’m doing man-in-the-middle,

1:24:10 getting credentials, doing the traditional attacking methods,

1:24:12 but I really wanted to focus on this whole physical element because the— Brando,

1:24:17 working with me, he was just like,

1:24:19 man— he’s like, we could do some Mission Impossible stuff.

1:24:23 I was like, yeah, yeah, we could.

1:24:25 [Music] So, the next phase was— they had cameras everywhere.

1:24:29 They had internal cameras, sort of external cameras.

1:24:33 I remember doing the net— so, eventually,

1:24:35 every day I’m folding different parts of that— of their internal networks

1:24:39 into the guest network that I’m at so I can bridge over and start looking,

1:24:43 and eventually I find all their camera— their camera network.

1:24:47 Luckily for me, they are using access cameras.

1:24:50 If anyone’s worked physical security,

1:24:52 everyone knows there was an era of access cameras from like,

1:24:56 2001 to about 2008, ā€˜09, ā€˜10,

1:24:59 where everyone had— all these places had these access

1:25:04 cameras 'cause they had a ton of features,

1:25:06 they were cheap, they were Chinese-made, wonderful cameras.

1:25:09 However, they were the worst security ever.

1:25:12 They had so many default passwords.

1:25:15 They had buffer overflows— in the access control systems,

1:25:18 they had buffer overflows,

1:25:19 and their web interface— they had a web interface that when you connected to it,

1:25:25 it looked like GeoCities.

1:25:26 It was straight up like 2002 internet all over again,

1:25:29 and that’s how you controlled the cameras directly.

1:25:32 So, talking to Brando and he was like, okay, look, man— he’s like,

1:25:36 I know they do a guard change around— it’s 2:30 a.m.

1:25:39 during— around that time.

1:25:41 He’s like, you gotta be in and out of a building around this time.

1:25:45 I was like, well— and he’s like, also,

1:25:48 there’s gonna be someone always watching these cameras.

1:25:50 I was like, okay, that’s fine.

1:25:52 He’s like, what are you gonna do with the cameras?

1:25:54 So, I show him, and I start connecting to all these cameras,

1:25:57 and at the time there was an access—

1:26:00 I think they were still running firmware from 2005,

1:26:03 and there’s an access buffer overflow that allows you

1:26:05 to control and gain access to every one of these cameras.

1:26:08 Still running that.

1:26:09 They hadn't patched them.

1:26:10 Jump in, and them from there I can access the shitty little interface.

1:26:14 I show him; I was like, look what happens if I modify these two values.

1:26:18 The values is brightness and contrast, and you can edit both of them.

1:26:22 It’s usually for when a viewer wants to look at the camera.

1:26:24 Oh, it’s too dark or too bright.

1:26:27 They can edit these.

1:26:28 In UI, you can edit them a little bit, but programmatically,

1:26:31 you can edit them all the way from 0 to 255 values.

1:26:35 So, you can make them go all black or all white.

1:26:39 So, I show him.

1:26:40 I was like, watch.

1:26:41 We can make their cameras go boom.

1:26:43 Watch; I show the camera.

1:26:45 It goes distinctly black for a second, and then I undo it.

1:26:49 He’s like, oh.

1:26:50 I was like, yeah.

1:26:52 [Music] He’s like, alright, goth guy, alright.

1:26:55 I see what you're cooking here.

1:26:57 So, he’s like, well, how are you gonna get these into an area

1:27:00 that— how are you gonna do this in a way that…?

1:27:03 You're gonna have to be carrying a laptop with you.

1:27:06 It’s gonna just be awkward.

1:27:07 I was like, that’s a good point.

1:27:08 So, in this engagement, I had a shuttle device with me,

1:27:11 a little, tiny— computers are the size of a shoebox.

1:27:14 A lot of pen testers use them for leave-behind devices.

1:27:17 On that shuttle device I put a Bluetooth radio on it.

1:27:22 So, with the Bluetooth radio, I was like, okay,

1:27:25 I’m gonna walk around the building and I’m gonna

1:27:28 get measurements of where I’m at with the Bluetooth.

1:27:30 It’ll signal their noise ratio, and when I’m in front of those areas,

1:27:33 I’m gonna map out what cameras those are at, and I’m

1:27:37 gonna make sure that I can get access to this.

1:27:40 So, I tested out the Bluetooth range.

1:27:42 I had to put a big antenna on this thing to get the Bluetooth receiver on it.

1:27:46 That worked, so I could have the Bluetooth

1:27:48 show— I go in front of these two cameras.

1:27:50 The two cameras that point outside to the patio, I could have them identified.

1:27:54 There was a camera on the inside there,

1:27:56 and then there was a camera facing the server room.

1:27:59 So, those are the cameras I needed to black out.

1:28:02 So, my app sends a signal to the Bluetooth.

1:28:06 The shuttle device would take that signal and relay it,

1:28:09 and when I receive those, it would send

1:28:11 the packets to those cameras to make the values,

1:28:14 brightness or contrast, to 255 or 0.

1:28:16 It was completely random.

1:28:17 It’s flipped back and forth between them to make

1:28:19 it look like a black and white screen,

1:28:21 sort of like an effect that was like the camera was malfunctioned for a bit.

1:28:24 So, I was like, man, I have— I could look at these cameras.

1:28:28 I could test to see if this works.

1:28:29 Not sure if this is really gonna work, but we're gonna try it.

1:28:32 JACK: So, he set everything up to try to break

1:28:34 into the building overnight and not be seen at all.

1:28:37 The front door might have extra security and he didn’t want to take the risk,

1:28:41 so his whole plan was to sneak up to the building,

1:28:44 black out the cameras, get in, and gain access to the server room.

1:28:48 Keep in mind, everyone already was on high alert from this kid.

1:28:52 They thought he was very suspicious,

1:28:53 and he was going to have to do something over the top to get in.

1:28:58 That’s when he realized his point of entry should be the balcony.

1:29:02 GREG: So, that night, man, I came in, 2:30 in the morning, climbed up the tree.

1:29:07 I get onto the balcony.

1:29:09 I push open— they had a security door on the balcony

1:29:12 that they would lock before you can get to the badge-reading door there.

1:29:17 I pry that open, I hit the badge key, go into the building.

1:29:22 The alarm starts beeping.

1:29:24 I hit the building alarm code, and lucky for me,

1:29:27 the girl had not changed her alarm code.

1:29:29 I was in.

1:29:30 [Music] I look at the cameras and I

1:29:33 remember being so nervous about this and being like,

1:29:35 oh man, this is— hopefully this will work or I’m gonna get tackled very soon.

1:29:41 So, I make my way over to the server room, and my secondary badge,

1:29:46 the other one I have from the IT guy, works for that one.

1:29:48 Badge cloned.

1:29:49 Got into there.

1:29:49 Went to the server room, and from there, boot-rooted all the machines.

1:29:52 So, if you're unfamiliar with boot root, back in the day,

1:29:56 this was— you plug a USB device into the machine, you turn off the server.

1:30:02 The machine would then boot off the USB device as a recovery device,

1:30:06 and from here you would replace a Windows component.

1:30:09 Sticky Keys would be a ideal favorite.

1:30:12 So, you replace Sticky Keys with command shell, and then you reboot the machine.

1:30:16 So, the machine— after you do that, the machine— you reboot the machine.

1:30:21 It goes into the password login prompt, and you hit Shift five times.

1:30:25 That would then launch Sticky Keys,

1:30:27 which has now been— become a command prompt instead,

1:30:30 and now you have a command screen on it,

1:30:32 and then you can run commands as elevated privileges like you're on a system.

1:30:37 So, you’d have elevated command.

1:30:38 So, from there I exploited all the machines.

1:30:41 I dropped a flag that said I was here,

1:30:44 and then I went into their stores and put flags on all of those.

1:30:48 JACK: He’s done it.

1:30:49 He’s successfully hacked into the servers Mission Impossible style.

1:30:53 So, he starts to go out, but he notices something.

1:30:56 GREG: Those paintings.

1:30:57 So, I proceed to go down the staircase, and I go down to the paintings.

1:31:02 I just quickly grab a sticky pad and put little happy faces,

1:31:06 like a little sticky page,

1:31:08 and start putting them right next to all these paintings.

1:31:11 There’s a little placard for each of these paintings

1:31:14 telling you essentially who made these paintings,

1:31:17 what did it symbolize, in some cases how much they were worth.

1:31:21 I stick little happy faces on it that says, I stole this.

1:31:24 JACK: Huh.

1:31:25 So, it’s typical for a physical pen tester to leave a token behind to prove

1:31:29 that they were there in a server room or a desk drawer or something.

1:31:33 I mean, just think about how you would feel if you went to bed and then

1:31:36 woke up and there was a sticky note

1:31:38 on your bathroom mirror that said, Greg was here.

1:31:40 Just a small note like that can say a lot, can't it?

1:31:44 Here, what Greg was doing was proving that he had access

1:31:47 to these paintings and he had time to go right up to them,

1:31:51 put notes on them, and security never saw him do it.

1:31:54 So, he wrote ā€˜I stole this’ on a bunch of sticky notes,

1:31:57 and just kept putting the sticky

1:31:59 notes on painting after painting after painting.

1:32:01 GREG: I remember 6:05; I get a call.

1:32:05 Greg, Greg.

1:32:06 Yeah?

1:32:06 Was this you?

1:32:08 What’s the happy face?

1:32:10 What’s that mean?

1:32:11 How did you do…?

1:32:13 What is…?

1:32:14 It doesn't matter.

1:32:15 The CEO wants to talk with you today.

1:32:19 Get in here, like 8:00.

1:32:21 He’s like, I don't know, man.

1:32:23 He’s really upset.

1:32:25 We have to figure out— I was like, okay, okay.

1:32:30 In the meantime, physical security had— they had a incident

1:32:36 'cause they were looking over and they were like,

1:32:38 well, someone walked in and put all these happy face stickers on there,

1:32:41 and they walked out the building.

1:32:43 They're like, what does this mean, ā€˜I stole this’?

1:32:46 I remember they are coming around— and I get to the building.

1:32:50 They escort me to the board room.

1:32:53 The board room has this massive table on it.

1:32:59 Me, in my awkwardness, I pick— I remember sitting and picking the exact opposite

1:33:04 of where I imagine every one— the exact corner of it.

1:33:07 The physical security is like, no, get over here, get over here.

1:33:11 First, give us your ID again.

1:33:12 We're gonna run some background checks on you again just to make sure.

1:33:14 JACK: Physical security knows to treat those paintings

1:33:17 with a very high level of security.

1:33:19 So when the CEO came in and he saw his paintings had sticky notes on them,

1:33:24 he simply asked, who did this?

1:33:26 What does this mean?

1:33:28 When security had no idea, then the CEO is like, okay, well, find out.

1:33:33 Then when security looked at the cameras,

1:33:35 they saw they were glitched out during that time,

1:33:38 and they had almost no evidence of who did it.

1:33:41 This made the CEO furious.

1:33:43 What do you mean no security footage?

1:33:45 Find out who put these sticky notes on this.

1:33:48 The cameras around the building were just all black or white because Greg hacked

1:33:52 into them to prove he could sneak

1:33:54 into the building late at night with nobody noticing.

1:33:56 GREG: The VC came in.

1:33:57 The VCO came in and was like, what the fuck?

1:34:00 What is this?

1:34:01 What do you mean, stole my paintings and little happy faces on them?

1:34:05 That’s what kicked off the security team alert.

1:34:07 I remember I was sitting there,

1:34:09 and then my contact leans over to me and he’s like,

1:34:13 look, again, I have never seen him cancel meetings

1:34:16 and move so and to see someone like this.

1:34:20 So, I don't think it’s gonna go well.

1:34:22 Then I look over to Brando, and Brando is just like— you know, he’s like,

1:34:28 maybe we flew a little bit too close to the sun here,

1:34:30 a little Icarus just a little hard, but whatever.

1:34:32 [Music] So, the CEO comes in with this single security team.

1:34:36 They hand me back my ID, and he looks at me,

1:34:42 and I— you can tell the thoughts of this goth

1:34:48 kid in his board room is not what he expected

1:34:53 and not what he was expecting to meet for when he—

1:34:59 and he looks over and he’s like, you hired this guy?

1:35:02 My contact who worked at the company was just like, yeah.

1:35:05 Looking at him, he’s like, alright.

1:35:08 He’s like, so, walk me through what you did.

1:35:13 For the next ten minutes, I retell him the story of exactly how I did it.

1:35:18 This VC previously had been very technical.

1:35:20 He was a code developer.

1:35:21 He worked on software.

1:35:22 So, he starts going and he starts asking me very intelligence

1:35:24 questions about— we start having a back-and-forth about, oh, okay, so why…?

1:35:28 He’s like, so, two questions for you.

1:35:32 First, what were you gonna do with the paintings?

1:35:37 I was like— I was dating a girl out of Brooklyn at this time, and I was like,

1:35:41 you know, I was thinking of taking them to Pratt

1:35:44 University and maybe fencing them at the university there.

1:35:46 There’s gotta be someone who knows some weird

1:35:48 connections at Pratt Art— Pratt Institute of Art.

1:35:51 He starts laughing.

1:35:52 He’s like, alright.

1:35:53 He’s got a plan.

1:35:55 I was like, okay.

1:35:57 He’s like, I really like those paintings.

1:35:59 He was like, I can't believe you would— I was like, yeah,

1:36:02 I absolutely would have stole them right out from— nothing to do.

1:36:06 He’s like, alright.

1:36:07 So, then he’s like, alright.

1:36:09 So, my next question is what are you doing next year at this time?

1:36:15 That’s how I became their reoccurring red teamer for four years until they

1:36:19 got tired of me breaking into the buildings and doing all the things,

1:36:24 and hired me as full time.

1:36:26 So, after this I got introduced to a lot

1:36:29 of the various levels of executives for this, and I

1:36:33 got to pen test all their personal houses and got

1:36:37 to show them how— why physical security is important,

1:36:41 gaining access to all their penthouse suites, all their large houses.

1:36:47 I did that for quite some time afterwards.

1:36:51 (Outro): [Outro music] A big thank you to Greg Linares, AKA,

1:37:01 Laughing Mantis, for coming on the show and sharing these stories with us.

1:37:05 Please consider supporting this show by visiting plus.darknetdiaries.com.

1:37:08 If you do, you'll get eleven bonus episodes and an ad-free version of the show.

1:37:13 By becoming a supporter is the most direct way that you can

1:37:16 help make sure this show continues running and delivers you more episodes.

1:37:21 Please visit plus.darknetdiaries.com.

1:37:22 This episode is created by me, CAPTCHA America, Jack Rhysider.

1:37:27 Our editor is the super subnetter,

1:37:29 Tristan Ledger, mixing done by Proximity Sound,

1:37:32 and our intro music is by the mysterious Breakmaster Cylinder.

1:37:35 I’ve been working on a new dance lately.

1:37:37 It requires the most efficient use of muscle

1:37:40 memory in order to spin at the perfect RPM.

1:37:44 I call my dance the algorhythm.

1:37:46 This is Darknet Diaries.

Study with Looplines Download Captions Watch on YouTube