They Hired Me to Steal a Shopping Cart Full of Human DNA 𧬠Darknet Diaries Ep. 160: Greg
Jack Rhysider
0:04 JACK: [App beeping] Hey.
0:07 DAD: Man, I don't see you.
0:08 JACK: Yeah, my tape is usually over my camera.
0:10 DAD: Why donāt I see you?
0:11 JACK: I got my tape on my camera.
0:13 One second.
0:13 DAD: Ah.
0:14 I can't even hear you.
0:15 JACK: You can't hear me?
0:17 DAD: My sound⦠JACK: [Background talk] Thereās a story I had
0:19 that I totally forgot about but I remembered recently,
0:21 and I wanted to call up my dad and walk through
0:23 it again with him to try to remember how it went.
0:25 DAD: Yeah.
0:26 JACK: I want to recollect the story with you.
0:29 DAD: Yes.
0:30 JACK: Because as I tell it, I don't think people will believe it.
0:33 So, I figure you can verify that this is true.
0:37 DAD: Yeah.
0:38 JACK: Alright, so, do you remember my senior year at high school?
0:42 DAD: Okay.
0:43 JACK: I had my own car then.
0:45 I was mentally done with school.
0:46 I did not want to go to high school anymore.
0:49 I was just sick of it.
0:50 I just had been there too long.
0:52 I had one elective left, and I said,
0:56 what is the easiest possible class I could take?
0:59 Do you remember what I chose as my last elective in my senior year?
1:02 DAD: It was either welding or typing.
1:05 I can't remember.
1:06 JACK: Typing, yeah.
1:07 But typingā how fast could I type as a senior in high school?
1:13 DAD: At least 99 words a minute [inaudible].
1:16 JACK: Right, right.
1:18 So, choosing that as an elective⦠DAD: Oh⦠JACK: ā¦thatās the easiest class ever.
1:24 That wouldā thatās gonna be a walk in the park.
1:27 DAD: [Music] I was happy for you.
1:29 Senior year.
1:30 JACK: Hereās the problem, though.
1:32 The class was the first period of the day, and⦠DAD: 8:40?
1:36 JACK: 8:40, yeah.
1:38 So, I had to be at Typing, first class of the day.
1:43 Yeah, the class was real easy.
1:45 When I got there I was like, oh good, this is just a beginner typing class.
1:49 I could type super fast.
1:51 So, Iāll tell you what Iāll do,
1:52 is Iāll finish up my lesson in like, ten minutes.
1:55 I could do this wholeā theseā all the stuff you guys are doing today,
1:59 Iāll do it in ten minutes and Iām done.
2:01 So, I even worked ahead.
2:02 I said, hey, teacher, can I go on to the next lesson?
2:06 Sure, sure.
2:06 So, I would do a whole weekās worth of work on Monday,
2:10 and then I would help out some of the other students and stuff.
2:14 I mean, I think I was the star student in that class.
2:18 DAD: Of course you were.
2:20 JACK: But once I got ahead enoughā I mean, you know what my morning routine is.
2:28 Am I a morning person?
2:30 DAD: I probably woke you up at 8:30 and said, you have ten minutes.
2:34 You could not wake up.
2:36 JACK: Yeah, I had trouble waking up.
2:39 So⦠DAD: You had narcolepsy or something.
2:42 JACK: I did.
2:42 Yeah, that wasā I used to use that excuse all the time.
2:46 DAD: You did.
2:46 JACK: So, I would get to school late on this typing class.
2:52 I thought, no problem, Iām a perfect straight-A student in this typing class.
2:56 Iām helping the other ones.
2:58 All my work is complete.
2:59 I don't think itās gonna be an issue
3:01 if Iām seven minutes late, ten minutes late.
3:03 Thatās fine.
3:04 So, I would show up late consistently to this typing class.
3:08 DAD: Oh no.
3:08 JACK: But yeah, well, the teacher didnāt like that.
3:12 She said, you can't come in late likeā I have to send
3:16 you to the principalās office if you come in late one more time.
3:18 You gotta come in on time.
3:20 This is like, your fifth time being late.
3:22 I said, yeah, but Iām getting all the work done.
3:25 Whatās the problem?
3:25 She said, no, no, no, if you come in late again, Iām gonna have to report you.
3:30 So, the next day, I couldn't get it together.
3:33 You tried waking me up again, and I was late.
3:36 She said, thatās it.
3:37 You gotta go to the principalās office.
3:40 The principal didnāt want to see me, but the vice principal was there.
3:43 He said, whatās the problem?
3:44 I said, no problem.
3:46 Iām doing well.
3:47 He said, well, the report here says that you're late,
3:49 so this isā you're a senior, you know?
3:53 If you get late too many times, you're not gonna graduate.
3:56 DAD: Oh, my.
3:57 JACK: I said, listen, Iā have you looked at my grade in this class?
4:02 He said, that doesn't matter if you're late.
4:04 I said, no, it should matter.
4:06 Listen, I think your priorities are all screwed up.
4:08 If Iām acing this class,
4:09 if Iām getting it all correct and if Iām helping the other
4:12 students and Iām a value add to the class in general,
4:15 not just myself, then donāt you think that I
4:18 should be graduating with that sort of work ethic?
4:20 He said, no, it has everything to do with being on time.
4:24 It has nothing to do with work ethic.
4:26 You have one more chance, and if youā Iām gonna be there tomorrow,
4:30 and if you are late again this year, you are not gonna graduate.
4:34 I said, really?
4:35 You're gonna hold me back just for being late even though I have perfect grades?
4:40 The next day, of course, Iām late.
4:42 I could not get it together.
4:44 The vice principal was standing at the door when I arrived.
4:47 DAD: Oh.
4:49 JACK: He said, thatās it.
4:50 You're late.
4:51 This is the last straw.
4:53 Youāve failed this class.
4:54 I said, how would youā why would you do this to me?
4:59 Itās not like Iām struggling with this class.
5:01 This class is easy.
5:02 Iāve got it nailed.
5:03 Iām like, three weeks ahead of every other student in the class.
5:07 He said, I don't care.
5:09 You can't come to school on time, so therefore, you fail.
5:14 Fail.
5:14 So, they wanted to hold me back a year,
5:18 a whole year of high school, and not let me graduate.
5:21 DAD: Now, you're only missing a half
5:23 a credit at that point if you didnāt graduate.
5:26 You could have went to summer school and picked up a half a credit.
5:30 JACK: Thatās right, I could have.
5:32 DAD: But you did something else.
5:33 JACK: [Music] So, what I broughtā when I brought
5:36 this news home to you and I said, listen, Iām not gonna graduate this year,
5:42 your brain started going into overtime
5:45 and you started thinking up ofā solutions.
5:48 DAD: Yeah, hereās a couple things.
5:50 One, after you got thrown out of the class,
5:53 I noticed you didnāt go to school when Iād wake you up in the morning.
5:58 Iām not even sure what was going on.
6:01 You'd say, don't worry about it, dad.
6:03 I can get in there.
6:04 Second period I gotta be there.
6:06 So, that.
6:07 But third, your social engineering wasnāt 100% yet.
6:11 That was your problem.
6:13 JACK: Yeah.
6:14 DAD: You should have done a lot
6:15 better with the assistant principal and the teacher.
6:17 JACK: Oh yeah.
6:18 But you saved me that year.
6:20 DAD: Of course I did.
6:21 JACK: I don't know how you came up with the idea,
6:24 but you found me an extra half credit.
6:27 DAD: Well, you one time switched high schools for, I don't know,
6:33 four weeks or something.
6:35 You didnāt like those kids, so you went back to the original high school,
6:39 which, by the way, was less than a mile from our house.
6:42 I don't know how you were ever late; less than a mile.
6:44 JACK: Yeah, it was very close.
6:46 DAD: So, I knew you were at that other school.
6:50 I went over there, and one of my kinda
6:53 best friendsā played sports together and thingsā I said,
6:57 do you remember my son Jack?
6:59 Yeah, yeah, nice kid.
7:01 Well, is he in your PE class?
7:03 Yeah, yeah.
7:04 I said, you never gave him credit for that.
7:07 He said, oh, man, this is so hard.
7:09 Credit?
7:10 I said, not only do you gotta give him credit,
7:12 but you gotta get it done before graduation.
7:15 You got like, six days.
7:17 He just said, I don't think I can do it.
7:21 I said, no; you go to the registrar, you put his name down.
7:25 Well, he said, you owe me big time, and somehow magically gave you a C for PE,
7:31 sent it over to your high school, and thatās really not the end of it.
7:36 The end of it was graduation at your high school.
7:39 JACK: Yeah, yeah.
7:40 So, that sorted it.
7:41 Now I was back on track to graduate and everything was fine.
7:44 I went to the ceremony, I sat in the stands, and then how did the ceremony go?
7:49 DAD: The assistant principal, your arch enemy,
7:52 heās the one handing out the diplomas.
7:55 JACK: The same guy who told me I can't graduate.
7:58 DAD: Yeah, just six days before;
8:00 you're not graduating, and now he calls your name.
8:05 You come up.
8:06 He looks at the diploma, stares at you.
8:08 I didnāt think he was gonna hand it to you,
8:11 and then he grimaced and gave it to you.
8:15 There you had the diploma with the missing half credit.
8:19 I think the statute of limitations ran out on all that, so⦠JACK:
8:26 Okay, I won't be kicked out of school?
8:28 DAD: Permanent record.
8:30 JACK: Itāll go on my permanent record, this one.
8:32 Oh, no.
8:33 DAD: Yeah.
8:34 JACK: Yeah, so that was quite theā all because of the typing.
8:38 DAD: Unbelievable.
8:39 Yeah, so, do you still know how to type?
8:44 JACK: [Laughs] Yeah, I do, but do you know how at this point?
8:47 DAD: No.
8:48 Iāve never had a job in forty years where I needed a typewriter or a computer.
8:54 Never needed one, or a cell phone.
8:58 Iām analog all the way.
9:01 (INTRO): [INTRO MUSIC] These are true stories
9:03 from the dark side of the internet.
9:07 Iām Jack Rhysider.
9:12 This is Darknet Diaries.
9:19 [INTRO MUSIC ENDS] JACK: I want you to meet Greg.
9:29 GREG: So, I grew up really, really poor.
9:33 I grew up in Tucson.
9:36 Fortunately my father was a avionics technician,
9:39 and he was a un-diagnosed autistic.
9:42 Brilliant man.
9:43 He was a MacGyver.
9:44 The man would just tinker and make things throughout his life.
9:49 While we were poor, my father decided to dumpster dive.
9:54 JACK: His dad would find various computer parts
9:57 in trash dumpsters behind buildings and bring them home.
10:00 After doing that a few times,
10:01 he had enough spare parts to assemble whole computers.
10:04 GREG: I had a Commodore VIC-20, I had a trash 80,
10:07 and then I had an Apple IIe, all when I was born, and I always loved them.
10:14 JACK: [Music] Back then, computers were not as common as they are now.
10:17 Having one in your house was a luxury.
10:20 Having three, you were really fancy,
10:22 and simply having these things within easy reach enabled
10:25 Greg to learn tons growing up instead of maybe
10:28 getting introduced to them sometime in high school if
10:30 your school was lucky enough to even have computers.
10:32 GREG: That was my escape as a kid.
10:35 I was a un-diagnosed autistic kid until in my thirties,
10:39 and I just immediately loved computers.
10:42 JACK: Computers were a novelty for me as a kid until we got AOL.
10:47 Then I became obsessed with them.
10:49 GREG: I was an AOL kid, too.
10:51 Matter of fact, thatās where most of my first programs ever came around.
10:56 I was one of the first to discover the 1IM exploit.
11:00 That was my first vulnerability I ever discovered,
11:03 was the integer overflow in the AOL client when
11:06 you sent a font size with a long enough number.
11:10 I remember finding that and making the 1IM punter back in the day.
11:14 JACK: I remember AOL punters.
11:16 You could send someone a message but then put
11:19 something in that message that when they receive it,
11:21 their client wouldn't know how to process it,
11:23 and it would just crash their AOL session.
11:25 So, you could come into a chat room, send everyone a message,
11:29 and then see half the room suddenly
11:31 disappear because their apps would be crashing, and they would disconnect.
11:34 So, all this fascinated Greg, to be able to force someone elseās
11:39 computer to do something itās not supposed to.
11:41 Thatās cool.
11:42 What else can you do?
11:44 [Music] His interest in hacking took root and grew.
11:47 Soon he found himself in an online group that was trying to create malware.
11:51 GREG: When I was a virus writer,
11:54 my ideologyā I hadā I actually targeted pedophiles.
11:58 Every singleā every piece of malware I
12:02 ever wrote was designed to target pedophiles.
12:04 We ran a group in there to target people who were targeting children.
12:09 The best part about targeting pedophiles is I
12:11 think itās the only case that you can say I gave malware to someone and they're
12:16 absolutely not gonna report you to the police, because what are they gonna say?
12:19 I was trying to pick up this kid and they sent me a jpeg.exe to them?
12:24 That was the case for many years.
12:26 When I wrote viruses, that was the only people I targeted.
12:30 Otherwise, for me, writing viruses, again,
12:32 was the thrill of learning about polymorphism,
12:34 metamorphism, andā as well as high-level, low-level code execution.
12:40 I just generally loved the thrill of the knowledge of it.
12:43 It was an art.
12:44 I still think itās an art form.
12:46 JACK: His specialty was using Visual Basic
12:49 to code malicious macros in Microsoft Word documents.
12:53 So, he would send the Word doc to someone, trick them into opening it,
12:57 and if they had macros enabled,
12:59 that would allow Greg to take over their computer.
13:02 Now, keep in mind, he was doing all this in middle school,
13:05 not even in high school yet,
13:07 and middle schools back then didnāt even have computer classes.
13:10 If they did, it was just to take a math quiz
13:13 or something like that, not really teaching how to use them and stuff.
13:16 By the time he got to high school, they were just starting to teach
13:20 kids commands and certain applications on computers.
13:22 So, one of the first classes he took was keyboarding, which is learning to type.
13:27 GREG: I was like, no, fuck that.
13:29 I aināt gonna type.
13:31 I know how to type.
13:32 [Music] So, our school worked on Excel.
13:35 All the great systems were in Excel.
13:39 So, Iām one of the old-school macro virus writers.
13:43 I remember Colors, and back in the day, those series of Colors and Tristate,
13:47 those were the areas of macro viruses I remember I started programming in.
13:52 So, with Excel, I was like, I could do this.
13:54 I don't want to be in this class.
13:56 I don't want to be in this school.
13:57 So, the entire grade system was in Excel, and I made a macro virus that would
14:01 look for my student ID numberā a trick number,
14:05 identify the areas where the grades were in, take
14:09 the average number of the number of the percentage,
14:13 or if it was A through F, it would beā Iād make myself as a B,
14:18 and it would average a number to be 87%, and gave myself 87%.
14:22 JACK: He was able to take this malicious
14:25 Excel file and get it onto the teacherās computer,
14:27 and suddenly he was getting all Bās in his classes.
14:30 On top of that, he made it so he had perfect attendance,
14:34 too, no matter if he was there or not.
14:36 So, he just stopped going to class.
14:39 Whatās hilarious is he did all this while in his typing class.
14:43 He even coding in obfuscation techniques to avoid detection.
14:46 Like, after the teacher would record his grade and then close Excel,
14:50 thatās when the macro would trigger, on close.
14:52 He would stage all this information in a column that he hid off
14:56 to the side so you couldn't see any of the funny business happening.
14:59 GREG: This worked really well.
15:01 I was in school for nine days.
15:03 Thatās how long it took me to write this and then put it into the school system.
15:07 Then every day I went home.
15:09 I was just at home.
15:10 One day my friends came over andā they came back
15:13 from class 'cause I still would hang out with them.
15:15 They were like, hey, Greg, man, the computers at school are really weird.
15:19 I was like, oh, what are they doing?
15:21 Heās like, well, they're crashing.
15:23 Everyone says Excelās not doing well.
15:25 [Music] I remember my stomach sinking.
15:26 Like, oh, what do you mean?
15:28 They're like, well, theyā when they're getting everyone ready for the finals,
15:33 everything changed and something crashed.
15:35 I think they're calling McAfee over it.
15:37 I was like, oh no.
15:39 So, I walkā I went to school the next day,
15:42 get into the school libraryā and I hadn't been in school
15:46 for so long that the librarian was like, who are you?
15:49 I was like, I go to this school.
15:50 I promise.
15:50 Iām here.
15:51 Sheās like, Iāve never seen you.
15:52 Who are you?
15:53 I was like, wellā do you have a student ID?
15:55 I was like, no, I don't have a student ID.
15:58 Sheās like, okay, go to the principalās office.
16:00 So, the principal, theyāre just like, hey, we know you're a kid.
16:04 We know your name checks out.
16:05 You're in these classes, but none of your teachers recognize who you are.
16:09 I was like, oh, Iām sorry.
16:10 I just kinda shut up at that point.
16:13 They sent me home, and what happened was the school added a column in all
16:18 the Excel sheets to calculate final grades and to do something for final grades,
16:22 and unfortunately that column just happened to be where
16:24 I stored the previous data of all the columns.
16:27 So, the virus would restore the docā
16:31 the sheets when teachers opened up the sheets.
16:36 That caused the Excel files to crash on grade,
16:39 and they sent the sample to McAfee.
16:41 McAfee at the time was like, yeah,
16:43 this is a macro virus and it was custom-written for your school.
16:48 So, the school decided to call the police.
16:51 The police showed up, knocked on my door, arrested me, and⦠JACK: Really?
16:55 GREG: Yeah, yeah.
16:55 I mean, itās a governmentā itās a public school.
16:57 Itās a public high school, so itās technically the government.
17:00 JACK: This was real bad.
17:02 He went to juvie, juvenile detention.
17:04 They locked him up in a concrete room
17:07 with a steel door and a tiny, little window.
17:10 Itās a scary place for a teenager.
17:12 [Music] So, I have a note here.
17:15 It says you're the youngest hacker to be arrested⦠GREG:
17:18 Youngest⦠JACK: ā¦in Arizona.
17:19 GREG: I was the youngest child to be arrested
17:21 in the state of Arizona for a computer crime,
17:24 forā Iām not sure if that still holds,
17:26 but that was the case for a long, long time.
17:28 JACK: A politician wanted to make an example of him, saying, see?
17:31 Cyber criminals are really bad and we should do more to stop them.
17:35 But he caught a lucky break.
17:37 GREG: But they came back that the Tucson police failed to handle
17:40 the evidence correctly and my case got dropped, luckily for me.
17:45 JACK: However, he was ordered not to touch computers for a whole year.
17:50 Can you imagine no computers for a whole year?
17:53 GREG: I made a deal with the courts to say I won't touch a computer for a year.
17:57 Iāll have to get a probation officer to sit next to me when I operate computers,
18:02 and then Iā and after that weāll re-evaluate the situation.
18:06 So, for a year, any time I wanted to touch a computer,
18:11 which was mostly the library back in the dayā if you remember
18:13 when libraries had the little internal library machines to go look up
18:16 for books in the libraryā I had to go call this very large
18:21 sixty-year-old man who wasā absolutely had
18:24 no idea what computer hacking looked like,
18:27 and I remember fucking with him quite a bit and saying,
18:29 oh, Iām getting into the system.
18:31 Heād look at me and grab my hand and pull
18:33 me away from the computer andā like, we're going now.
18:36 JACK: [Music] What kind of personā what kind
18:39 of kid were you like in high school?
18:41 GREG: Oh man, I was absolutelyā I was a goth kid.
18:44 I was the goth kid who wore the largeā I got in trouble for wearing
18:49 a black trench coat 'cause unfortunately going
18:52 to high school during the 2001 era, you come across the Combine incident.
18:58 JACK: You know, back in the nineties when I saw a goth kid,
19:01 I just thought they really liked the movie The Crow.
19:05 GREG: Yeah, The Crow was a good one.
19:07 My best friend at the time, his name was John Oller.
19:09 John was a huge Crow fan.
19:11 He actuallyā he kinda looked like Brandon Lee, too.
19:13 So, he was a goth-of-The Crow type.
19:16 I was more into the industrial music.
19:19 I always loved Skinny Puppy and Suicide Commando,
19:22 Velvet Acid Christ, all thatā all those late-nineties industrial bands.
19:26 So, I was more of a rivethead.
19:28 I didnāt know at the time what a rivethead was,
19:30 but I was just an industrial kid; big, stomping boots, goth, industrial music.
19:35 I liked metal but I didnāt like metal so much; I like electronic music.
19:39 So, when I found out industrial music,
19:41 which is essentially goth music mixed with techno, I was like, this is it.
19:45 This is my lifestyle.
19:46 JACK: You wear earrings?
19:47 GREG: No.
19:48 I actuallyā well, sorry, I take that back.
19:50 In high school I think I had nine piercings.
19:54 I had, you know⦠JACK: Did you wear eyeliner?
19:58 GREG: No, I was not a makeup goth.
20:00 I was not a makeup goth.
20:01 I had the dog collars, so I had the goth collars.
20:05 So, I had the bondage outfits.
20:07 I was one of those goths for sure.
20:10 JACK: Okay, so this just emphasizes when
20:13 they're looking for the person who did this.
20:16 GREG: Yep.
20:16 JACK: Theyāre just like, you're the one⦠GREG: Yeah,
20:18 Iām sorry⦠JACK: ā¦who does not look like everyone else.
20:19 GREG: Iām sorry, everyone.
20:21 The goth stereotype for the virus writers, that was me.
20:25 That was me, everyone.
20:27 I apologize.
20:28 Yeah, I remember⦠JACK: You started this.
20:30 GREG: I did, I did.
20:31 So, my parents kicked me out of my house.
20:33 I lived in a group home after being arrested.
20:35 I was in a⦠JACK: Wow, just because of that event?
20:37 GREG: Yeah, yeah.
20:38 So, I lived in⦠JACK: And you're not normal, Greg.
20:41 You're wearingā you got too many piercings.
20:44 Come on.
20:45 GREG: Yeah, I did that all myself, too.
20:48 So, I got kicked out.
20:50 I lived in a group home from the age of fourteen to eighteen.
20:55 [Music] So, I was in and out⦠JACK: That was a tough time.
20:59 GREG: Yeah.
20:59 JACK: So, at fourteen is when you got arrested.
21:01 GREG: Correct.
21:01 JACK: Then, thatās a hard time to go through an arrest.
21:04 Thatās scary.
21:05 You donāt know what you're facing there.
21:06 GREG: Correct, yeah.
21:07 JACK: Then to be thrown out of the house⦠GREG: Yeah.
21:08 JACK: ā¦and then like, what?
21:09 I gotta do this on my own?
21:11 Gosh.
21:11 GREG: Yeah.
21:12 So, I lived in a group home; didnāt have access to a real computer.
21:15 So, my only computers at the time were the ones in school.
21:19 It was rough, man.
21:21 Itās one of the big reasons why I always try
21:24 to reach out to people who are kind of in rough situations,
21:27 'cause my life has not been an easy one.
21:30 It has not been easy.
21:31 Living in a group home, whichā the group home wasā the one I
21:36 got assigned to was a government group home,
21:39 and it was mostly for kids who were domestic violence or runaways.
21:43 So, it was a lot of violent kids in there.
21:47 It was a smallā it was like a small four-bedroom house,
21:52 but it hadā at any time it had between
21:56 six guys and six girls and then staff members there.
22:00 So, it was cramped.
22:02 Everything was shared.
22:04 It was not a good time.
22:07 It was a rough life.
22:09 JACK: I think I just got some clarity on what it means to be goth just now.
22:16 Itās not about the clothes and the makeup and the music.
22:20 Itās about not fitting into a world that tells you
22:24 to shrink and conform and smile when you're falling apart inside.
22:29 [Music] Itās about understanding that you are
22:32 different and you can embrace your difference, and you gotta pay the price.
22:37 Being misunderstood by your teachers, so-called friends,
22:41 even your own family, can become isolating.
22:44 Thereās this moment I imagine that every goth must face.
22:49 You have a choice; either break yourself down into something more acceptable,
22:54 force yourself into a version of normal that everyone wants you to be,
22:59 or you can embrace that shadow inside you,
23:02 that one thatās screaming out, wanting to be seen, wanting to be heard,
23:05 but knows that itās just too weird for people to understand.
23:09 Goths choose to embrace that inner shadow, lean into their weirdness,
23:14 wear it like armor, and let your darkness be your beauty.
23:19 When you're in a place like a halfway house
23:21 with nowhere to go and no one who really knows you,
23:24 that identity, being goth, can become more than just a style.
23:30 It becomes your anchor,
23:31 because being goth means you already know what itās like to live on the outside.
23:36 You already live in the cracks of the system.
23:39 So when the worst happens, when your life is shattered,
23:42 being goth is a reminder that itās okay to be on the outside of society.
23:48 The music reinforces the idea that itās okay to live outside whatās normal,
23:52 and thereās a level of comfort to hear that music
23:55 and to see other goths who are also struggling to fight whatās normal,
24:00 those quiet rebels, the kids who find beauty in broken places.
24:05 I imagine that being goth makes you more resilient to problems like this.
24:10 It gives you a tribe without borders.
24:13 It gives you a sense of self when the world pretends you're invisible.
24:18 So, I imagine being goth in that halfway house was
24:21 an amazingly helpful way to get through it, to self-soothe.
24:25 Every time he put on dark clothes,
24:27 it was like he was giving himself a hug and saying, itās okay to be different.
24:33 Don't worry about what everyone else thinks of you.
24:36 Man, to go through something like that, and goth being your anchor,
24:41 that could easily make you goth for life.
24:44 Man, I think I got carried away there.
24:47 Okay.
24:48 GREG: So, after I get out of high schoolā so, I was doing music,
24:53 one of the few thingsā so,
24:56 I becameā I was a musician and I was a successful musician.
25:02 If you've ever seen The Matrix sequels movies, then you've heard my music.
25:07 At one⦠JACK: What?
25:08 Your music is in The Matrix sequels?
25:10 GREG: Yeah.
25:11 So, I got contacted by a company called Spiderbite Studios,
25:14 and they wanted to make music for The Matrix,
25:17 especially behind-the-scenes Matrix stuff.
25:19 They wanted to do some music there.
25:21 The big thing is they were looking for someone to make
25:25 music for the trailer for the video game The Matrix Online.
25:29 [Music] So, they sent me an e-mail and they were like,
25:33 hey, your music sounds great.
25:35 So, that was my first example of being
25:38 exploited in a contract by a large company.
25:41 I sold my music rights for $400 each.
25:44 I think I got $4,000 total out of that deal.
25:48 So, I was like, Iām $4,000 richer.
25:50 That is awesome.
25:51 After that, that got intoā a lot of people asked me to do music and go touring.
25:57 So, I did a European tour.
25:58 It was all throughout Europe.
26:00 I think I went to every country except for Latvia and Lithuania.
26:03 Toured for a while and I came back⦠JACK: What are you playing here?
26:07 GREG: Synthesizer.
26:07 It was a one-man project.
26:08 So, I didā I love synthesizers.
26:10 At one point I owned over eighty of them.
26:14 So, yeah, after that, I came back.
26:17 After a long tour time, I came back to Arizona.
26:20 I was homeless for a while because you only make $30,000 as a musician,
26:24 average, a year at that time, especially an industrial musician.
26:26 You donāt make any money.
26:28 So, I came back homeless,
26:29 and then I lucked out in getting a job working at Massage Envy.
26:34 JACK: Massage Envy is a massage parlor,
26:36 but itās a chain and they have over a thousand locations all over the US,
26:41 and their headquarters are in Scottsdale, Arizona,
26:43 and they needed someone to work on the back end of their booking system.
26:47 They gave Greg a shot, and he excelled at it.
26:49 GREG: It was all vb.net and ASP code back end.
26:53 So, I was coding that, and I was breaking software in the meantime.
26:59 Millwormā so, I was coding exploits on Millworm and just throwing them up there,
27:04 and I was literally trying to throw an exploit up there a day.
27:09 I remember I got an e-mail from eEye,
27:13 [music] and they were like, you're cracked.
27:15 What is goingā like, what are you doing?
27:18 Where do you work at?
27:19 Tell us about you.
27:20 I was like, well, Iām a software developer in the middle of Phoenix, Arizona.
27:23 I work on Massage Envyās back end.
27:25 They couldn't believe it.
27:26 They were like, what?
27:27 You're not in security at all?
27:29 I was like, no.
27:29 I was just like, I just break stuff for fun.
27:32 JACK: eEye was a cybersecurity company based in California.
27:35 Itās spelled E-E-Y-E, eEye.
27:37 They created some tools to help people be more secure.
27:41 Like, they made a vulnerability scanner,
27:43 and thatās how they were able to make money.
27:45 So, eEye saw that Greg was writing a lot of malware and posting it publicly,
27:50 and they liked that and decided to hire him,
27:53 and flew him out to California to give him a job.
27:55 GREG: Yeah, well, the team I was on, we
27:58 were all about finding zero-days and finding exploits.
28:00 JACK: Yeah, but thereās no money in that.
28:02 GREG: Marketing, my friend.
28:03 When you have a good research team and they're rockstars,
28:05 they're gonna look at you and your product and think,
28:08 oh man, those guys know what they're doing.
28:10 So, yeah, when I got there, the person I replaced was Barnaby Jack.
28:14 I tookā I actually had his desk and everything, man.
28:17 JACK: Wow.
28:18 GREG: Yeah, yeah.
28:20 Lots of respect to him, man.
28:23 It wasā I never filled his shoes,
28:27 but it was just an honor to be a part ofā you know, be around him.
28:32 I got to meet him multiple times.
28:33 He was a great guy.
28:34 JACK: See, back then, nobody had a bug bounty program.
28:37 If you found a vulnerability in some software,
28:39 that company wouldn't pay you anything.
28:41 You'd be lucky if they sent you a t-shirt.
28:44 There was zero money in vulnerability research then.
28:47 But the reason eEye did this research to try
28:50 to find vulnerabilities in software was for two important reasons.
28:55 One, to earn credibility.
28:58 eEye company must have some pretty sharp
29:00 researchers to constantly be finding vulnerabilities in things.
29:03 I bet their tools are great.
29:05 It works.
29:06 Two, recruitment.
29:07 By making the news again and again that they keep finding vulnerabilities,
29:12 top talent would want to come work there.
29:16 Now, they did follow responsible disclosure.
29:17 When they'd find a vulnerability, they would do two things; first,
29:21 tell the software maker and show them exactly what they found.
29:25 Then they would announce publicly that they found a vulnerability in a product.
29:29 They wouldn't say what the vulnerability was, though;
29:31 not until after the software company was able to fix it and patch it.
29:36 So, that was the team that Greg joined,
29:38 to simply find new bugs in software that nobody knows about,
29:41 which is whatās known as a zero-day vulnerability.
29:45 GREG: So, I get there,
29:47 and Office dropsā Office 2007 drops probably about four weeksā like,
29:55 within my first month of working there.
29:57 We were looking at other software.
29:58 We were looking at, I think,
30:00 CA Arcserve Backup, if you remember that terrible product.
30:03 I haveā as a macro virus author andā I
30:06 can look at Officeā hex editors in Office;
30:10 I could tell you where the blobs are in Office.
30:13 I know the bit format very, very well.
30:15 So, when it comes to⦠JACK: So,
30:18 thereā your boss or someone told you⦠GREG: Marc Maiffret, yes.
30:24 Weāll put his name for the record here.
30:27 [Laughs] JACK: Marc Maiffret; Iāve heard that name before.
30:30 GREG: If you donāt know,
30:31 Marc Maiffret got famous from MTVās True Life of a Hacker.
30:35 [Music] Thatās whereā that was his claim to fame.
30:37 He was on that.
30:38 MARC: You know, over the last few years
30:40 and basically ever since I got into hacking,
30:43 itās just been kinda like a wild ride or somewhat of a movie.
30:47 After the raid, started thinking a lot different about my life
30:51 and what I wanted to start doing with it and turn things around.
30:55 MTV: These days, Chameleon is living the hacker dream,
30:59 creating security software for companies to protect
31:02 themselves from people just like him.
31:04 JACK: [Background talk] That was a clip
31:07 from the MTV show called True Life Hacker from 1999.
31:10 The show follows Marc around as he hacks stuff.
31:13 He was wild back then.
31:15 So, I imagine itād be really crazy to have him as a boss.
31:19 So, your boss told you Office 2007 just came out.
31:22 Do you want to take a look at it?
31:23 Itād be great if you could find some sort of virus
31:25 or bugā or, not a virus but a exploit in there,
31:29 a bug that we could use for Marketing⦠GREG: Absolutely.
31:31 JACK: ā¦and make a big deal about.
31:33 So, jump in there.
31:34 You were assigned to do that.
31:35 GREG: Yeah, thatās exactly how it worked.
31:37 Anything that came out, any big thingā we were essentially bounty hunters.
31:41 We would go out and be like, yeah, letās go break this thing.
31:44 If we have⦠JACK: Yeah, but there wasnāt paid bounties back then.
31:47 You'd get a t-shirt if anything.
31:49 GREG: It was all about the honor of being the first.
31:52 We wanted to be the first, too.
31:54 That was a big deal.
31:54 JACK: Yeah, the honor was a reward.
31:56 GREG: Yup.
31:56 It was be the people who first found a bug.
32:00 So, I went in there and started manually fuzzing Word at the time.
32:08 JACK: [Music] Fuzzing; the first time I did fuzzing was when I was five years
32:13 old and I went to the supermarket and they had a gumball machine.
32:16 My mom gave me a dime and showed me how you
32:19 put it in and you turn the crank and you get candy.
32:23 It was awesome.
32:24 For years I was drawn to them.
32:26 I just had to touch them every time I saw them and check them out.
32:30 I would try turning the crank on every one to see
32:32 if it would just give me candy with no money in it.
32:35 Nope.
32:35 Unless you put money in it, the crank won't turn.
32:37 I would sometimes try to put money in it and turn it
32:40 very slowly to see if I could get a little bit of candy, and as soon as I do,
32:45 turn it back real quick to reset it and do it again, but that didnāt work.
32:49 I would check the dispenser chutes to see if anyone left candy behind there,
32:52 and yes, sometimes they did, and that was cool, a bit of free candy.
32:56 I would shake the machine sometimes to see if
32:58 I could get candy to come out that way, and that did sometimes work, too.
33:01 But then I was like, how does it know I put money in here?
33:04 Like, how does it know what a quarter or a nickel or a dime actually is?
33:09 So, I started jamming anything I could find that would fit in there;
33:12 plastic pieces, metal washers, cardboard, shoelaces.
33:15 Iād shove it in, Iād turn the crank, and I would see what happens.
33:20 Iām telling you, from five years old all the way to fifteen years old,
33:24 I was fiddling with these things every time I saw one.
33:28 That, to me, is what fuzzing is.
33:30 Itās trying to use the tool or machine or application in ways itās not supposed
33:35 to be used to see if you could glitch it or somehow get it to act weird.
33:40 What Greg was doing was he was opening Microsoft Word
33:43 and trying to put something in a Word document that wasnāt allowed.
33:46 I don't know, maybe trying to put a Chinese
33:49 letter in there or some strange ASCII symbol.
33:51 Word would accept some of these characters but then just deny others.
33:54 Now, if Word won't let you input a strange character, why?
33:58 Will it break if you somehow force it to take that strange character?
34:02 Well, Greg wanted to try.
34:04 So, he opened up a Word doc, not in Microsoft, though;
34:07 in a hex editor where you can manipulate
34:10 the ones and zeros directly in the file, almost like doing surgery on the file,
34:14 and he put in a character directly
34:16 into the file that he knows Microsoft Word can't accept,
34:19 and then heād save it and try to open it up in Word to see what it would do.
34:25 Nothing.
34:26 Okay, fine.
34:26 That didnāt work.
34:27 But letās try again.
34:29 This time, letās see what the max font size is in Word.
34:32 16.38.
34:33 Well, thatās pretty big.
34:34 Okay, so, Word won't let you make a font size bigger than that number.
34:38 Challenge accepted.
34:39 Letās set the font to the max, 16.38, close down Word,
34:42 open up the file in a hex editor, look for where that number is.
34:46 16.38, where does that show up?
34:49 Ah, right there.
34:50 Maybe that means the font size.
34:53 So, letās change that to 9999 and save it and open
34:56 it up in Word and be like, what now, Word?
34:59 You wouldn't let me set the font bigger, but I did.
35:02 What are you gonna do?
35:03 Nothing.
35:03 It just reverts back to the default font size.
35:06 It had some sort of logic to handle what
35:08 happens with a font size that we can't accept.
35:11 That is what fuzzing is, and thatās what Greg was tasked with doing,
35:16 to try to make the brand-new Microsoft Office 2007 Suite crash.
35:20 Itās really a hunt to try to see if the developers at Microsoft accounted
35:26 for every single problem that could possibly
35:28 go wrong in Word and handle it gracefully.
35:31 GREG: So, you're modifying these files at the lowest
35:34 level possible and you're introducing all this unexpected code,
35:37 unexpected code paths.
35:38 Itās parsing these files and itās parsing these files;
35:41 itās encountering these unexpected data points.
35:43 These unexpected data points are introducing areas
35:46 of opportunity for you to find a vulnerability.
35:50 JACK: Basically, the goal is to get Word to execute malicious code,
35:54 such as giving someone else control of that computer.
35:57 But you can't just put malicious code in a Word
36:00 doc and then when someone opens it, it runs.
36:02 Word doesn't execute code like that.
36:04 It just displays it as text.
36:06 Thatās its job.
36:07 So, can you hide this malicious code somewhere in the Word
36:10 document that it will also get executed when Word gets opened?
36:14 No, not really that, either.
36:16 Yeah, thereās macros that act like code, but thatās different.
36:19 What we want is for Word to take our malicious
36:22 little code and stick it into the memory of the computer.
36:26 So, the goal is to cause Word to crash,
36:29 but then use that crash to force malicious code
36:32 into memory or a pointer that references the code into memory.
36:35 [Music] Now, just opening Word is not
36:37 enough to see all the stuff thatās happening.
36:39 You want extra visibility on how well Word is behaving,
36:42 what stuff itās putting into memory and everything.
36:45 Thatās where a debugger comes in.
36:46 At the time, he was using a debugger called Olly,
36:49 which would show him a lot more details of what Word is actually doing.
36:53 GREG: Correct.
36:53 Olly is a tool that you attach to yourā any
36:56 application that you want to see at low level, assembly level.
36:59 You want to see what the codeās actually doing,
37:01 your registers and your memory output and whatās going on with the application.
37:05 You attach a debugger; that allows⦠JACK: Sounds like a wrapper for the app.
37:08 So, you open Olly and then tell Olly to open this, and then Olly would be like,
37:12 I will watch all the memory⦠GREG: Exactly.
37:13 JACK: ā¦everything thatās happening here and tell you everything.
37:15 GREG: That is a great summary of that, and thatās exactly what it does.
37:18 JACK: It sounds a bit tedious to open a file in a hex editor,
37:22 manually change one or two numbers, then close it,
37:25 and then open Word up and then see how it behaves;
37:28 and nothing, so just close it all and try again.
37:31 So, all day heās editing these files,
37:33 opening them in Word, and then closing them.
37:35 GREG: I just really liked looking at the files in the hex editor,
37:39 modifying the files, opening the file, and noticing the UI change.
37:43 It would distort theā it wouldā if you had your Office file,
37:46 if you had graphics and stuff in there,
37:48 it would distort it or make it look wrong 'cause itās rendering improperly.
37:52 So, you could actually get better feedback, I found,
37:56 by doing it that way, to identify where in the file you're affecting.
38:01 So, I did this for like, two days, and all of a sudden I had a crash.
38:05 JACK: Ooh, a crash.
38:07 This is what heās been trying to create.
38:10 Okay, first thingās first; will it crash every time?
38:13 Yes.
38:13 Awesome.
38:14 Okay, it wasnāt a fluke.
38:16 Next, can he inject code into memory when it crashes?
38:19 Yes.
38:19 Wow, this is great.
38:21 Now he has to see if he can get control of a pointer
38:25 or inject some shell code into memory along with this crash.
38:28 Yes, he can.
38:29 GREG: It was a classic crash at that time
38:32 where you overwrote a data pointer and you
38:35 could control the data pointer at that, which
38:38 isā allowsā thatās the basis for remote code execution.
38:43 JACK: So, what heās discovered is he can craft
38:45 a malicious Word doc so that when the user opens it,
38:48 Word crashes, but then malicious code is put into memory,
38:52 and now the system is severely weakened.
38:54 Itās vulnerable.
38:55 Wow, very cool, all within weeks of Microsoft Office coming out.
39:00 Greg has discovered a pretty serious vulnerability in it,
39:03 which allows arbitrary code execution.
39:05 He feels great.
39:07 His team is impressed.
39:09 So, you tell your coworker, your coworker tells your boss,
39:12 you tell your boss, whatever, and what does your company do with this?
39:16 GREG: My boss is like, awesome.
39:19 He immediately starts writing all the press.
39:23 Marc Maiffret isā if you know him, heās very enthusiastic.
39:26 Heās just like, oh my god, we're gonna fuckā this is gonna be fucking awesome.
39:31 We're gonna send this to the press.
39:32 We're gonna throw this out there.
39:34 So, he immediately starts writing to everyone,
39:36 all these typicalā you know, the tech writingā the tech writers.
39:40 So, they immediately start writing, and then we report to Microsoft.
39:43 JACK: Again, they aren't sharing exactly what the vulnerability is to the press.
39:47 They're just telling them that eEye found another zero-day,
39:50 this time in the latest Microsoft Office,
39:53 and of course only giving Microsoft the full details so they can fix it.
39:57 Once itās fixed, then eEye will show the world how it was done.
40:00 The news spread fast.
40:02 A few big tech publications were talking about this zero-day that Greg found.
40:06 GREG: Three days later we get a e-mail back from Microsoft and it says,
40:12 hey, we can't reproduce this.
40:14 [Music] We're like, this is typical.
40:16 This isā weāve dealt with this before.
40:19 This is a typical Microsoft security response, response team typical action.
40:23 So, they're like, okay.
40:24 So, we send themā we send the sample again and we're like,
40:28 hey, you knowā we show the debug output.
40:30 We showā and then another day after that, it comes back,
40:35 and they're like, hey, did you try this without a debugger attached?
40:40 Marc Maiffret is like, of course we did.
40:43 Then he looks over to Andre; Andre looks at me, and Iām like, I don't think so.
40:53 So, we go run it again, and there is a special trap that Microsoft added.
41:00 This isā at the time,
41:02 this was pretty new technology where they had debug-only routing inside Office.
41:07 So, it would reach a code flow path that was only exploitable,
41:13 only triggerable when you had a debug attached to the Word,
41:18 meaning no oneās gonna be vulnerable to this unless they have a debug attached,
41:24 unless they're a security researcher.
41:26 JACK: Oh man.
41:27 How embarrassing.
41:28 The news is out there saying that eEye found a serious vulnerability,
41:34 but now it turns out they donāt actually have a vulnerability.
41:39 Itās because this new kid, this weird-looking goth kid,
41:42 didnāt verify it all the way.
41:45 GREG: So, I remember there was yelling.
41:49 There was yelling involved.
41:51 I remember I was there for three weeks
41:56 and I remember justā literally just staring down,
41:59 being ashamed, just being like, oh god.
42:02 This is it.
42:03 This is how I lose my career.
42:05 It was nice.
42:06 It was a good couple months in security.
42:09 JACK: Okay, 'cause the stress here is
42:11 because a press release was written, right?
42:14 GREG: Yes, yes.
42:15 eEye at the time wasā they're like the rockstars.
42:18 This isā everyone else in the room,
42:21 all those rockstars; Yugi, Derek, Daniel Soder,
42:24 the brothers, everyone else in there
42:27 has written vulnerabilities in a professional manner.
42:29 They've all done this for years.
42:31 They've found the first Vista vulnerability.
42:33 They foundā this is their thing.
42:36 Now Iām the new guy who screwed up and made them look bad.
42:42 So, behind the closed door, they were like, we gotta fire this guy.
42:48 Luckily for me, I believe Andre was like, nah, dude, we gotta give him a chance.
42:52 Heās gottaā we're gonna give him a chance to make this right.
42:58 So, they come out and they were like, look, man, you gotta find a vulnerability.
43:03 We donāt care how you do it.
43:05 Itās gotta happen.
43:06 Iām like, okay.
43:07 JACK: Thereās some hope still.
43:09 The press release just said they found a vulnerability in Microsoft Office,
43:13 which consists of Excel, Word, PowerPoint, Visio, and more.
43:17 It didnāt give any details as to how the vulnerability works.
43:22 So, if they can find a bug in any of these products,
43:27 itāll save the reputation of the company.
43:29 But to be clear, for a young guy in his first
43:33 cybersecurity job to find a zero-day vulnerability in Microsoft Office,
43:38 thatās an incredibly complicated task.
43:40 The entire team of coders at Microsoft worked tirelessly
43:44 to prevent people like him from finding bugs like that.
43:48 So, heās gotta find something they missed?
43:51 This was a big deal for Greg.
43:53 [Music] He needed to find a zero-day vulnerability
43:56 in Microsoft Office or else heās going to be fired.
44:00 He calls his girlfriend and says, donāt wait up for me tonight.
44:03 I am going to be working late.
44:05 Sorry, I just have to do this.
44:07 He just gets down right into the zone, downing energy drinks,
44:11 grabbing extra monitors to be more productive, ordering pizza right to his desk.
44:15 Heās fully committed to doing this.
44:17 He was so committed that he was going to stay
44:20 in that office until he found a zero-day vulnerability.
44:23 GREG: So, I am there twenty-four hours by myself,
44:27 just manuallyā and Iām just like, oh god, I can't do it.
44:31 JACK: Heās sleeping under his desk, heās living off of donuts and coffee.
44:34 GREG: So, what happened here, man, wasā so,
44:37 the crew comes up to me and they're like,
44:39 dude, we're not gonna let you do this by yourself.
44:42 We got your back.
44:43 So, everyone stayed in there, and we were in there for three days.
44:48 Man, Iā thatā I remember girlfriends calling,
44:52 wives calling guys and being like, are you guys coming home yet?
44:55 They're like, no, we gotta do this.
44:56 This is an important thing.
44:58 We ordered pizza.
44:59 We had Mountain Dew.
45:01 That area of the office, I remember, it was not smelling great.
45:06 The other teams were like, what are you guys doing?
45:09 What is going on in here?
45:10 JACK: Are you just like, opening text files in edit and then close,
45:13 and then open, and then close?
45:14 GREG: We haveā okay, so, I think during that timeā so,
45:17 thereās at least six of us.
45:19 We have one guy whoās writing his own program to fuzz it.
45:23 We haveā I think Yugi had three screens up fuzzing data, reverse-engineering.
45:27 Heās trying to reverse-engineer that.
45:29 I have a program I have written running on one machine over here.
45:32 I have a machine to my left.
45:34 I have a machine left to me thatās
45:35 running software to try to find this vulnerability.
45:37 Iām in a hex editor editing files left and right.
45:40 I think Derek was also editing files.
45:42 Derek foundā was finding something else.
45:45 He foundā I think he later found another vulnerability
45:47 out of this, but heās going in there editing,
45:49 looking at this, and we're all lookā
45:51 everything we find is really interesting stuff,
45:53 which turns out it wasā we found a lot
45:55 of really cool stuff in Office at the time,
45:57 but none of it was a vulnerability as we described.
45:59 So, we are literally just sitting there
46:02 geeking out and justā pizza being ordered.
46:04 eEye was a wild time.
46:06 JACK: Days go by like this where all
46:09 the researchers are pouring tons of time into this.
46:12 Nobody was going home.
46:13 People were sleeping in shifts under their desks, in the break room.
46:17 The energy was amazing to have so many people come
46:20 together to try to save the reputation of the company.
46:23 GREG: Day three, I was modifying a file, and all of a sudden it popped.
46:32 We look at it and we're like, oh, wait.
46:36 I remember Yugiā Yugi looks at it first and heās likeā Yugi is this incredibly,
46:43 unbelievably talented Japanese hacker.
46:45 Heās like, oh, it looks good.
46:47 When Yugi says itās good, everyoneās like, okay.
46:50 Soā and the first thing that happens after
46:52 that isā I remember one of the guys was like, is the debugger detached?
46:56 We're like, oh yeah, get that thing off there.
46:58 So, retry it, and it happens to be in Office Visio.
47:02 It was another product inside the Office suite.
47:05 So, it wasnāt Word, not as sexy as Word, but, hey, we only said Office 2007.
47:11 So, again, saved our butt.
47:13 Soā and the thing is, when Microsoft sent that e-mail, they were like,
47:18 hey, man, this vulnerability occurs in this wrapper function called safent.
47:23 What safent does is it prevents the integer
47:27 overflow from occurring and causing that control flow,
47:31 your code execution, to occur.
47:32 So, it checks all the integers.
47:34 [Music] What happened with the new vulnerability
47:36 we found was we happenedā just happened
47:39 to have found a legacy pointer for a integer
47:43 that was not safented-wrapped and was vulnerable.
47:46 So, they sent that e-mail out,
47:49 and unfortunately, David LeBlanc in Microsoftā David,
47:53 if you're listening to this, Iām sorry, manā I think he was on vacation.
47:58 He got called back.
47:59 Maybe he didnāt get called back, but thatās what I heard,
48:02 'cause he was the one who was in charge of safent.
48:04 Safent was his baby, and itās an awesome security feature.
48:08 He got called back because when we sent that sample to Microsoft and it worked,
48:14 that was a big deal to them.
48:17 So, we are all happy.
48:19 The vulnerability goes out.
48:21 A couple months later it gets disclosed,
48:24 and we have indeed the first vulnerability in Microsoft Office.
48:29 That was the case.
48:31 That was a wild time, to say the least.
48:36 JACK: He saved his butt on that one.
48:39 His whole career was on the line, and he did what he had to do to save it.
48:44 Being awake for so long wasnāt much of a celebration after he found it.
48:48 GREG: Dude, I crashed.
48:49 I fell asleep.
48:50 I remember beingā just being so exhausted,
48:52 I straightā at the time when I found it,
48:55 I was already tired because I was half-asleep.
48:56 I remember the alarm that I had for it to find it,
48:59 I nearly spilledā I think I did spill soda all over the place,
49:03 'cause I was just waking upā like,
49:04 we're all fasting outā like, we're literally sleeping at our desk here.
49:07 Thereās noā we're not sleeping on hammocks or anything.
49:09 We're just sleeping at our desk.
49:10 So, I remember it beingā like, we find theā we're like, yes,
49:15 and we were all so tired to actually have a properā I guess
49:20 we did have a properā we did yell out extremelyā a malwareā like,
49:24 yes, we're finallyā and then immediately afterā 'cause we're like,
49:27 we're celebrating, high-fiving, everything was like that.
49:29 But man, after that, I just remember us all being like, and we're going home.
49:34 I fell asleep at the office.
49:35 I didnāt even make it home at the time,
49:37 'cause I had toā I lived walking distance.
49:39 I was too tired to even walk home that day.
49:41 So, I just crashed out, woke up, went home,
49:45 and I remember my girlfriend just drew meā the pillow and the blanket,
49:51 and I was on the couch for like a week for that one, rightfully so.
49:56 She was so pissed.
49:57 JACK: But it was your job on the line.
50:00 She should understand that.
50:01 Like, listen, Iām gonna get fired or I could stay three days and not see you.
50:05 What would you rather I do?
50:06 GREG: Oh man, I was a newly father.
50:08 My kid was probably⦠JACK: Okay.
50:12 GREG: [Laughs] Yeah.
50:13 My kid⦠JACK: Well, hold on, so you just had a kid at the time.
50:16 GREG: My kid when I started, yeah, was six months old.
50:19 So, that kid was not even a year old,
50:22 and colicā and my kid was extreme colic, like twelve hours a day crying.
50:26 Oh man, she was so mad.
50:28 JACK: Oh, thatāsā that makes it even more stressful.
50:33 GREG: Oh yeah.
50:34 Oh, oh yeah.
50:36 But yeah, soā oof, yeah, that wasā I remember the e-mailsā that wasā oh,
50:43 the e-mails I was getting from her was always popping up,
50:45 just being likeā her just getting angrier and angrier as the day is going on.
50:49 Sheās like, where are you?
50:51 Like, I don't believe you're at work for three days doing this.
50:53 I was like, okay, Iāll send you a picture of us.
50:56 We had the team just doing random pictures.
50:59 I was like, oh man, this isā this was a time.
51:04 JACK: [Music] eEye was a magic place.
51:07 A lot of amazing talent worked there,
51:09 and many went off to start their own cybersecurity businesses.
51:12 Rumor has it that some of the anecdotes from the TV
51:15 show Silicon Valley came from stories that happened at eEye.
51:17 Greg learned a ton from working there for years.
51:20 GREG: So, years laterā god, this is like my third year at eEye.
51:27 I remember we had a honeypot system,
51:31 whichā itās a system thatās designed to catch hackers and lure in individuals.
51:36 We tried toā we were trying to get zero-day exploits
51:39 and definitely try to lure people into attacking the system.
51:41 It was one of the largest honeypots at the time.
51:44 It was nearly a Class B internet group of honeypots.
51:47 It was massive.
51:48 I remember I was logging into one of the systems that we
51:54 had maintained for that, and I see a log-in called Lfeng.
52:00 I was just like, what is this?
52:03 Whoās account is this?
52:04 Maybe this is a new hire I just donāt know about.
52:08 I walk into my bossā office and I was like, hey, I got that all set up.
52:15 However, there was someone who logged in recently,
52:19 and maybe itās someone we hired in dev ops or something.
52:22 Do you know a Lfeng?
52:24 I remember my boss was just typing.
52:27 All of a sudden I remember the distinct sound of him stopping
52:31 and the sound of the chair creaking back and him looking at me.
52:36 Heās like, you found what?
52:38 Who?
52:39 I was like, yeah, Lfeng.
52:41 I think I looked atā the extended name was Li Feng.
52:46 He was like, what do you mean you found a Li Feng log-in?
52:51 I was like, yeah, itās on the honeypot system.
52:53 It wasā it looks like it was a maintainer.
52:56 He goes and he closes the door behind me and heās like,
52:59 alright, Iām gonna tell you a story about Li Feng.
53:02 I was like, okay, letās hear about it.
53:06 So, back in the day, like I mentioned,
53:09 eEye was the rockstar group for finding vulnerabilities.
53:13 It was like, eEye and I-Defense.
53:15 That was the two big companies back
53:19 in the day for finding zero-day vulnerabilities.
53:24 At one point, eEye was so good at what they were doing,
53:31 Microsoft decided to hire someone in order to go work
53:37 at eEye in order to get them to tell them,
53:41 Microsoft, about the zero-days they found in Microsoft.
53:45 JACK: Wait, wait, whatā hold on a second.
53:49 You're saying Microsoft got someone toā a job at eEye⦠GREG:
53:55 It was a different time.
53:56 JACK: ā¦so that they couldā but they worked for Microsoft
53:58 so they could report to Microsoft what eEye is working on.
54:00 GREG: It was a different time.
54:02 Yep.
54:03 JACK: This is ridiculous.
54:04 You donāt hear about this ever.
54:07 GREG: It was a different time.
54:08 JACK: Did this news ever actually go public?
54:11 GREG: I don't think so.
54:12 This is⦠JACK: I can't imagine Microsoft hiring
54:16 to workā getting people to work at a other company; this is corporate espionage.
54:21 GREG: Thatās correct.
54:23 [Music] Well, it gets even better.
54:26 It gets even better after that.
54:28 It gets even better after that.
54:30 JACK: Okay, so Microsoft hires Li Feng to work for them,
54:35 but then plants him in eEye to go find
54:39 out what they're working on and report back to Microsoft.
54:42 So, Li Feng was working at eEye for a while,
54:45 but then suddenly left, and nobody really knows why.
54:48 He just disappeared one day.
54:49 GREG: But then Microsoft, sometime after he left,
54:51 they're like, hey, we gotta have a talk.
54:53 We gotta have a conversation.
54:55 So, we're like, okay.
54:57 So, Microsoft was like, so, Li Feng,
55:01 he was working for us to identify zero-days that you guys may have found.
55:07 JACK: Which had to be a bombshell for your company to hear.
55:10 GREG: I think⦠JACK: They thought that must have⦠GREG:
55:13 I think they had suspicions that he was being a little odd, butā so,
55:17 Microsoft then goes to say, so,
55:20 apparently he was also working for a foreign government
55:25 entity to do the same for us and you.
55:30 Soā¦[laughs] JACK: So, someone placed him in Microsoft?
55:35 GREG: Correct, correct.
55:36 JACK: Go get a job there and⦠GREG: And then he got chosen to go work for us.
55:40 We hired him, and he got planted,
55:42 and then he was siphoning zero-days from not only us;
55:46 apparently he also had privy information at Microsoft,
55:49 and that went back to his foreign government that he was ultimately working for.
55:57 JACK: Holy moly, someone planted him at Microsoft
56:00 and then Microsoft planted him at eEye?
56:02 Thatās unreal.
56:03 How embarrassing for Microsoft.
56:05 Itās like being caught doing something you shouldn't have been doing, like,
56:09 I don't know, having your pants down when the elevator door opens.
56:12 They know they shouldn't have been playing that game,
56:14 but now they realized that they got played themselves.
56:18 Oof.
56:18 So, I really wanted to confirm this story,
56:21 and I reached out to people that I know
56:23 who have been at Microsoft for a very long time,
56:26 and all of them said that does not sound like something Microsoft would do.
56:30 So, I can't confirm that that story is true,
56:32 but I would love to know if it is or isn't.
56:35 So, if you have information about Microsoft planting
56:37 people in other companies, tell me about it.
56:40 Because hereās the thing; we know corporate espionage is happening.
56:43 Thereās people sending secrets back and forth to tech giants all the time,
56:47 but itās a secret, so we donāt know about it.
56:49 We only know about the ones who get caught.
56:52 So, it seems plausible like something like that could happen.
56:55 You know what?
56:57 Iām curious what corporate espionage stories are out there.
57:01 Taking a quick peek, there seems to be some cool ones.
57:04 In fact, I think Iām gonna take an ad break and look at this a little deeper,
57:09 because Iām fascinated by corporate espionage,
57:10 and I might have to do a few episodes on that sort of stuff.
57:14 But stay with us because after the break,
57:15 Greg is gonna tell us some penetration testing stories that heās done.
57:20 After a while, Greg left eEye and started doing red-team stuff.
57:25 That is penetration testing, breaking into companies to test their security.
57:29 He also does threat intelligence, which he tells me he got some really
57:35 interesting contacts and worked at some very interesting places.
57:38 But we're gonna have to skip those stories
57:41 because they're too sensitive to talk about.
57:43 But he is willing to tell us a few pen test stories that he did go on.
57:48 The first story is about a time when he was paid to try
57:51 to hack into a major tech firm which has a lot of user data.
57:54 I mean, they have millions of users.
57:56 But not just simple user data; theyāve collected highly personal information
58:00 on their users as part of their service.
58:03 So, Greg meets with the customer, and it started out weird from the get go.
58:07 The customer was saying, look, we are crazy about security.
58:10 We go over the top on cybersecurity because
58:12 we cannot risk our user data getting out.
58:15 So, we donāt think you're going to find anything.
58:18 In fact, the last pen testing company struggled so
58:21 bad to try to hack us that they got arrested.
58:24 GREG: [Music] So, they use a third-party payment
58:26 processing system that is not used by them,
58:29 and their previous pen testers accidentally exploited
58:32 the third-party payment system that was vital to them.
58:35 The third-party payment system was an Oracle system
58:39 and not owned by the customer at all.
58:42 So, whenā apparentlyā thatās why I heard from the customer;
58:46 they wereā they did their exploitation and then they said,
58:50 hey, we got into credit cards and we're gonna present
58:54 it to you in the next day in a presentation.
58:57 So, they got the blue team there, all the blue team,
59:01 all the people, and then he presented them and said, hey, we exploited this.
59:05 We exploited this IP address.
59:07 We got access.
59:08 We gain it.
59:09 Here is your raw credit card details.
59:12 As you can imagine, the team looks at it and they're like, what IP is that?
59:17 Thatās not local.
59:18 Thatās notā itās a tenā itās a local address, but thatās not ran by us.
59:23 That is not.
59:24 Then they found it was actually owned by the third-party payment system,
59:27 and they had exploited a zero-day and that gained access to there.
59:31 On top of that, the credit card details were
59:33 nowā it was a stream of credit card details.
59:36 So, I believe it was outside of even scope for the customer.
59:39 So, the customer reported them on the safety of their half 'cause
59:43 they didnāt want to think that someone on their network compromised them,
59:47 and reported them to the law enforcement authorities.
59:49 I believe that led to the arrest of them.
59:53 Either way, that wasā thatās always wonderful to hear going into a pen test.
59:57 You hear, hey, the previous guys got arrested.
59:59 Why donāt you guys come in here?
1:00:03 So, great start already.
1:00:05 Great start.
1:00:05 [Music] So, if you know me, I still dress like a goth kid.
1:00:11 Iām still all black.
1:00:12 Iām cyber-punked out.
1:00:14 I wear Neo4ic; love them.
1:00:16 Iāll wear everything from vx-underground, all black, anything I can.
1:00:20 So, I show up at this facilityā oh, and at this time,
1:00:24 we also have a coworker of mine,
1:00:25 and myā this is my coworkerās first bigā real big pen test.
1:00:29 So, he comes in, too, and I will never forget the people there because they look
1:00:35 at me and they look at each other and they're like,
1:00:39 oh god, we gotta put you guys in the back room.
1:00:41 So, they set us a separate room away from everyone else.
1:00:46 Throughout my career, this is kinda the thing.
1:00:48 Iām the guy in the back room.
1:00:50 Iāve been there because of how I am.
1:00:51 So, they sent us back there, and this is a five-day insider-threat pen test.
1:01:01 Go.
1:01:02 JACK: [Music] So, his job was to simulate an employee
1:01:04 there who had gone rogue or had been hacked.
1:01:07 Just by being in the building, what could he do?
1:01:11 Sniff some Wi-Fi traffic?
1:01:12 Plug into some network ports?
1:01:15 All thatās worth checking out,
1:01:17 but they did give him a single userās login, and they said,
1:01:21 that user should be locked down so tight that you shouldn't
1:01:24 be able to do any harm even by knowing their password.
1:01:28 GREG: This customerā Iāve been red-teaming a lot of places.
1:01:32 Their blue team, their SOC team is absolutely legit,
1:01:35 one of the best defense teams Iāve ever had the honor of working with.
1:01:41 So, they literally are running their own kind of built-in EDR system
1:01:45 that they built themselves thatās tied into their SOC, going in there.
1:01:50 We get nowhere, man.
1:01:52 Day one; nothing.
1:01:53 Day two; nothing.
1:01:55 Day three; my coworkerās laptop dies in the middle of it,
1:01:58 and he can't even work anymore, and we had to give a report to the customer.
1:02:04 I remember them just looking at us and being like,
1:02:07 I think we hired the wrong people.
1:02:09 Literally, they were like,
1:02:10 do youā you guys want to resign and we can scrap this up,
1:02:14 call it quits, and then we can go hire somewhere else?
1:02:16 I was like, no, man, we got this.
1:02:18 [Music] Day four happens, and weā I remember it was 4:30 and we have
1:02:26 to giveā at 5:00 we have to give our meeting,
1:02:30 and my coworker had to go to Best Buy and buy a brand-new machine.
1:02:34 He spent the entire day imaging a machine on a red-team engagement.
1:02:38 He looks at me; heās like, man, I don't know what to do.
1:02:40 So, I was like, hey,
1:02:41 letās try one moreā letās do some ARP poisoning and just do one more time.
1:02:48 I remember looking up, and that ARP poison grabbed one plain text
1:02:53 credential that just happened to be an FTP job.
1:02:57 We're like, oh, we got a credential.
1:03:00 We got somewhere.
1:03:01 We got something.
1:03:03 It turns out that credential was to build system process,
1:03:07 and it allowed us to get into the build
1:03:11 system to roll code throughout the entire thing.
1:03:14 It just so happened at 4:30 they rolled it
1:03:18 out to do a end-of-day lockdown and build system configuration,
1:03:21 lock everything down so no one is doing any more builds.
1:03:25 We went into that meeting; said, hey, we just intercepted this.
1:03:30 I remember them all thinking, wait a minute,
1:03:33 thatās the old buildā and that credential is still active.
1:03:37 At that point we had a really cool exploit for that one.
1:03:39 We got into the build system,
1:03:40 and they had a lot of controls on the actual files in there.
1:03:44 So, we couldn't modify in the build files, but we could edit the command line.
1:03:48 So, we rolled an inline assembly.net include
1:03:51 in there to roll in, go into their portal,
1:03:54 and steal all the customer data, whoād enter a credit card in there.
1:03:57 We marked it in the data.
1:03:59 We locked out that credit card, but we put a asterisk in there,
1:04:02 *stolen last four digits*, and then had it sent out to them.
1:04:06 They test it, they ran it out, and they were like, holy crap,
1:04:08 we have not had a red team roll out code to production in eight,
1:04:12 nine, ten years that weāre here.
1:04:14 Come back next year.
1:04:16 Come back next year.
1:04:18 JACK: Whew, talk about a Hail Mary.
1:04:19 Not a single find all week, and then 4:30 p.m.
1:04:22 on the last day, they catch a lucky break by sniffing
1:04:25 a credential in the network which gave them tons of access.
1:04:28 What a good find that saved their butts.
1:04:30 GREG: I come back next year, and theyāre like,
1:04:32 hey, we want you to do something kinda crazy.
1:04:36 We want you to target DNA.
1:04:39 JACK: [Music] Part of what this company did was genetics studies.
1:04:42 They had DNA data on their users,
1:04:44 and this was regarded as one of the most protected assets of the company.
1:04:49 So, why not hire a hacker to try to find it and steal it?
1:04:52 GREG: We donāt care how you get it.
1:04:56 Any way you can get it, thatās fair game.
1:05:00 So, I spent a week in there as a malicious insider.
1:05:08 JACK: He starts with a basic employee login again.
1:05:12 It is locked down pretty tight,
1:05:14 but itās just enough for him to get a foothold somewhere else,
1:05:17 and from there he finds an exploit in another system,
1:05:20 and then he was able to pivot from there, collecting more system logins,
1:05:24 and finally heās able to get in a system which manages backups of machines.
1:05:29 He can see thereās some really large files here.
1:05:33 Maybe those are system snapshots or backups?
1:05:36 But what system is it a backup for?
1:05:39 No idea.
1:05:40 But he decides to try to download it anyway
1:05:42 to see if he can look at whatās in these files.
1:05:45 GREG: It literally errored out on the share size.
1:05:48 I was like, Iāve never seen that before.
1:05:50 I remember clicking a file, and Iām on a local network.
1:05:53 I remember that file taking forever to get to me.
1:05:57 I was like, how big is this?
1:06:00 So, I grab the file and Iām on the local machine,
1:06:03 and I remember looking at it, and itās TCGA CT, like those letters.
1:06:08 I was just like, I think thatās DNA.
1:06:12 I think thatās DNA.
1:06:14 I was like, huh.
1:06:16 Maybeā this has gotta beā this can't be right.
1:06:20 So, I grab it and I cut off as much as I could.
1:06:25 I rememberā and then I sent it overā I work with a biologist.
1:06:29 She was a very, very smart girl,
1:06:30 and she just happened to be a biologist who was working with mice at the time.
1:06:36 She actually knows DNA and she worked with DNA.
1:06:39 I was like, hey, what does this look like to you?
1:06:43 I sent it to her and she looks at it and sheās like, oh,
1:06:47 this is a DNA sequence mapped out by this program,
1:06:50 and this looks likeā I was like, oh, okay, cool.
1:06:52 Then she was like, hang on, I could even tell you what kind of DNA this is.
1:06:57 A couple minutes go by and she was like, why do you have human DNA?
1:07:01 I was like, I gotta go.
1:07:03 I gottaā bye!
1:07:04 Click.
1:07:05 So, my next task was likeā they were like, you have to get the data out.
1:07:10 You can get in; you had to get access.
1:07:12 We had to get it out.
1:07:14 So, at the time, again, it was ran by a very, very good SOC team.
1:07:20 There was a lot ofā the environment I was in was very, very well-restricted.
1:07:26 The only way I got to her was through sending a picture.
1:07:30 I remember selecting it all and then putting it into an app,
1:07:34 sending her a picture of it.
1:07:36 It was so bad quality, I had to send it a couple times, actually.
1:07:40 But so, I was like, how am I gonna get all this data?
1:07:42 I can't do it with a phone.
1:07:43 I can't do it with a picture.
1:07:45 How am I gonna get all this data out?
1:07:47 [Music] I was a malicious insider,
1:07:49 so I was working as a quote, unquote, āIT memberā.
1:07:53 So, I got introduced to the IT group and they were like,
1:07:56 oh, yeah, you'll be working in this environment.
1:07:58 Itās cool.
1:07:59 So, I was like, I gotta figure out a way I can get a bunch of hard drives,
1:08:03 and I have to get a bunch of hard drives back into the building.
1:08:07 So, what I did was thereās printers that were scheduled
1:08:11 forā to beā these printers were scheduled to be taken to repair.
1:08:16 I remember grabbing one of those printers and gutting it as much as I could.
1:08:21 Walking out, Iām going out to the front desk,
1:08:23 going out the front door and being like,
1:08:25 hey, I gotta send this printer to the repair shop.
1:08:28 It has to be done today, immediately.
1:08:29 So, the front desk people were like, okay, just sign off work.
1:08:32 Cool.
1:08:32 Sign off for the printer.
1:08:34 Load that into theā my rental car, and I go to Best Buy,
1:08:38 and Iām like, I have to get hard drives.
1:08:40 I have to get a lot of hard drives.
1:08:42 So, I went byā and this is back
1:08:45 in the day where external hard drives were those big,
1:08:48 obnoxiously ugly-colored things,
1:08:50 and they came inā I think 32GB or 64GB was a big hard drive at that time.
1:08:59 So, I go throughā I have a shopping cart, and I just go from the end line
1:09:03 of these and just pull the whole thing into the shopping cart.
1:09:06 I have a full shopping cart of hard drives.
1:09:08 JACK: You put your arm on the shelf and just�
1:09:10 GREG: You know that meme where that guy
1:09:12 is running around Best Buy and heās like,
1:09:13 allā hacked all the things, I hacked all the things?
1:09:16 That was me except with hard drives, shoving it into a shopping cart.
1:09:19 I remember going to Bestā the front of the desk,
1:09:24 maxing out my credit card, and thenā of hard drives,
1:09:29 and then going back into my hotel
1:09:31 at the time and loading them all into the printer.
1:09:35 I put the shelled outā the hollowed-out printerā I just
1:09:38 stacked the hard drives in there and pulled it up together,
1:09:41 and then I show up to work the next day,
1:09:44 get the little trolley carts they have, go out and say, bring it back.
1:09:50 I remember Iām bringing back the printer, and the front desk person was like,
1:09:56 wait, you sent that off to be fixed yesterday.
1:10:01 I was like, yeah.
1:10:02 He was like, you gotta tell me how you
1:10:05 got those guys to fix that in twenty-four hours because,
1:10:07 man, they are always so slow.
1:10:09 I was like, oh shit.
1:10:11 Well, I bought them a root beer.
1:10:13 They're like, oh, that makes sense.
1:10:15 I was like, I brought them a six pack of root beer.
1:10:19 He was like, ah, okay, good to know.
1:10:21 So, I go back to my area of the building,
1:10:23 putting itā and I have this printer next to me,
1:10:26 and then I am opening up the little panel,
1:10:29 and I am justā USB driveā literally copy, pasting, mounting, copy, pasting.
1:10:34 I started at like, 8:15 a.m.
1:10:37 and I am there until they kicked me out of the building at 9:00 p.m.
1:10:44 doing nothing but moving over data.
1:10:47 Then I leave the printer there,
1:10:50 and for the next two daysā I am literally doing this every day.
1:10:55 Then, on my last day of the pen test,
1:10:58 I remember I walk out and I go to the front desk,
1:11:01 and the guy thereā heās still there.
1:11:04 Heās likeā I was like, oh, dude, the printer broke again.
1:11:07 Heās like, oh, don't worry, I got something for you.
1:11:10 He goes in the fridge, the little fridge he has,
1:11:12 and he brings out a six pack of root beer.
1:11:15 Heās like, give this to them and tell them I said hi.
1:11:19 I am sitting there trying not to laugh while Iām holding petabytes ofā I
1:11:23 can imagineā I thinkā I don't know howā I couldn't get it all,
1:11:27 but I remember I bought over eighty hard drives from Best Buy.
1:11:30 I think I actually went back a couple days later
1:11:32 and bought some more because I didnāt think I had enough,
1:11:35 and put them in my jacket and my pants,
1:11:38 and I loaded this HP printer and filled that thing up, and got to my hotel.
1:11:43 Then at that point, hadā I had a secondary
1:11:46 laptop that I askedā I requested to prove for exfiltration.
1:11:49 I kinda [inaudible] that laptop, I loaded it up and said, done.
1:11:53 JACK: So, when it was time to show him what he found,
1:11:56 he has them go into the room where he was working in and said,
1:11:59 open up the printer.
1:12:00 They open it up, and when they do,
1:12:03 a bunch of hard drives just come pouring out of it.
1:12:07 He says, those hard drives are filled with all your DNA data.
1:12:10 GREG: Yeah.
1:12:11 They later said, hey, you were the first person to do that.
1:12:14 I worked for the red teaming for anotherā
1:12:17 I think three or four more times after that.
1:12:20 It wasā after that it was a call center I attackedā targeted.
1:12:23 JACK: Okay, hereās the big question, though, right;
1:12:26 the first time they're like, you gotta go in the back office.
1:12:29 We can't have that.
1:12:30 After doing it three, four times,
1:12:32 when you're walking through, are you feeling more confident?
1:12:34 Like, oh, no, you can be in the front office.
1:12:35 We donāt mind you being around here.
1:12:36 GREG: Oh man, I went to their barbecues.
1:12:38 I went to their familyā they were all very nice.
1:12:41 After the first time, they were like, look, you could never meet the execs,
1:12:49 but we will absolutely hire you every single time.
1:12:54 JACK: [Music] A few years go by of him doing pen tests,
1:12:57 and he gets another job which also has an interesting story.
1:13:00 This time, a venture capital company has hired him to try to hack them.
1:13:04 Now, they wanted to see if he could hack into them
1:13:07 to get data that would influence the market or something
1:13:10 that might hurt the reputation of the company or see if
1:13:13 he can gain information that he can be used against the company.
1:13:16 So, Greg gets tasked with going on site to try
1:13:19 to hack into this venture capital company, which, remember,
1:13:22 even though heās well into his thirties at this point,
1:13:26 he is still dressing all goth and considers himself a goth kid.
1:13:30 GREG: Iām still a goth kid, man.
1:13:32 I still dress in black.
1:13:34 I still wear my gothā like I said,
1:13:36 I don't wear the colors or anything, but I still dress all black.
1:13:39 I wear my goth outfits.
1:13:40 I wear my vx-underground, my Neo4ic shawls and everything.
1:13:45 I wear my goth boots.
1:13:47 Whatās funny is every single contract Iāve signed for work,
1:13:51 I have two clauses in there.
1:13:54 Clause number one; I will never code in Ruby.
1:13:57 Fuck Ruby.
1:13:58 Clause number two; Iāll never adhere to a dress code, period.
1:14:02 Those donātā if those two donāt happen, I don't work there, period.
1:14:06 Soā and that goes back toā I was one of theā when I was in cybersecurity,
1:14:14 I was one of the kids who never went to college for cybersecurity.
1:14:17 So, all these places are like, oh, you gotta get a college degree,
1:14:20 you gotta do all this kinda stuff, and you gotta wear suits.
1:14:23 I was like, no, fuck that, man.
1:14:25 I gotā if you donāt hire me for the things I know,
1:14:28 then I don't want to work there.
1:14:29 Thatās been a long belief and I still believe that to this very day.
1:14:33 I told my boss, the day that my goth outfit interferes with the way I work,
1:14:40 I will stop doing it.
1:14:41 I still do it to this very day.
1:14:44 Itās been twenty years.
1:14:45 Anyway, so, they send me over, and I remember I getā they're like, hey,
1:14:49 we want you to meet at this outsideā itās
1:14:52 gonna be outside the hotel that we're all staying at.
1:14:57 I walk up to this guy, and this guy is wearing a suit.
1:15:01 He is wearing a suit that costs probably more than what I make in a month.
1:15:06 Heās in there.
1:15:07 Heās smoking a cigarette, clean cut.
1:15:09 The guy looks like heās still active Secret Service.
1:15:11 I think he even had an ear piece in.
1:15:15 He looks at me and I was like, hey, are you this guy?
1:15:21 Weāll call him Brando.
1:15:23 Are you Brando?
1:15:24 He was just like, yeah.
1:15:26 Heās like, are you Greg?
1:15:28 I was like, yeah, nice to meet you.
1:15:32 I remember he takes the longest drag out of his cigarette.
1:15:37 You know that meme fromā whatās that HBOā¦?
1:15:42 True Detective where the meme of looking at the phone
1:15:45 and the guy is just inhaling the cigarette,
1:15:47 or Matthew McConaughey, I think, is inhaling the cigarette?
1:15:50 I got that exact look from this guy looking at me.
1:15:54 He just tosses that cigarette and heās like, this is gonna be a long week.
1:15:58 Heās like, letās go.
1:15:59 JACK: So, this guy is his escort and drives him
1:16:01 to the building where heās supposed to do the pen test.
1:16:03 He takes Greg to the front door and he tries to go in with his escort.
1:16:08 GREG: I remember physical security is like, sir, who are you?
1:16:11 What are you doing here?
1:16:13 They literally get in front of me.
1:16:15 I was like, no, Iām with Brando over there and Iām part of a assessment.
1:16:20 They're like, give us some ID.
1:16:23 They escort me into the building,
1:16:25 and all of a sudden Iām getting a call from my contact.
1:16:28 Heās like, where are you?
1:16:29 I was like, Iām being detained.
1:16:31 Heās like, oh god, this is a great start.
1:16:34 So, they come over and they realize that Iām supposed to be there,
1:16:38 and then I go meet my contact,
1:16:40 and I remember him looking at me and being like, oh, man.
1:16:44 Heās like, alright, well, you can go work in that back room over there.
1:16:50 We're gonna tell everyone you're an auditor or someone so no one bothers you.
1:16:55 You're gonna set up in this back room, and just donāt bother anyone.
1:16:59 Just go there.
1:17:00 JACK: So, they sat him down and said, okay, hack this place.
1:17:04 Heās like, well, can you give me a user login or something?
1:17:08 No.
1:17:09 Alright, can you give me the Wi-Fi password at least?
1:17:13 No.
1:17:13 Well, listen, I see a bunch of wireless networks,
1:17:16 and I don't want to accidentally hack into the wrong wireless network.
1:17:19 So, can you at least tell me which Wi-Fi network is yours?
1:17:22 GREG: I could see the contact at the venture capital is like, manā it was like,
1:17:28 he looked at me and he wanted me to be
1:17:31 out of this building and to fail as much as possible.
1:17:33 So, heās like, our guest Wi-Fi ID is this.
1:17:36 Go.
1:17:37 [Music] Thatās it.
1:17:38 Thatās all I had to go on.
1:17:41 Nothing else.
1:17:41 Just the guest Wi-Fi.
1:17:42 So, I get up and Iām like, okay.
1:17:45 So, I start walking around the building,
1:17:47 and the security team is absolutely following me at every step of this.
1:17:52 Brando from the other third party is like, where are you going?
1:17:55 Whatās going on?
1:17:55 I was like, Iām looking for a Wi-Fi password.
1:17:57 Heās like, I thinkā heās like,
1:17:59 Iām pretty sure you're supposed to do that with the computer stuff.
1:18:01 I was like, nah, nah, they're gonna have this.
1:18:04 I walk around the building and eventually I find it on a whiteboard.
1:18:08 Iām like, bingo.
1:18:09 So, I go back and I sit down, and now Iām on their guest Wi-Fi network.
1:18:14 JACK: Nice.
1:18:15 How clever; just look around the building for the password.
1:18:18 Alright, so now heās connected to the guest Wi-Fi.
1:18:21 GREG: So, I get the password, I sit down, and from there I start scanning.
1:18:25 The first thing I goā is I hit the Wi-Fi router.
1:18:30 Itās a Cisco device.
1:18:32 This teamā Iāll later learn that this team is very, very good.
1:18:38 However, again, like they mentioned, they've never had a full red team event.
1:18:42 So, the router security is nowhere near where it should be.
1:18:48 Itās actuallyā the router is a single router, a single Cisco device that is both
1:18:55 the guest Wi-Fi and the internal Wi-Fi as well.
1:19:00 So, I exploit the router, I jump on the router,
1:19:03 and then I make the entire network flat.
1:19:05 I bridge over everything.
1:19:06 So, now my machine can beā can attack anything on the inside of the network.
1:19:11 Even though Iām on the guest Wi-Fi,
1:19:14 I can still start attacking anything on the inside network,
1:19:17 or on certain networks.
1:19:18 They had multiple inside networks, so I start bridging them over one by one.
1:19:21 JACK: How did you exploit the router?
1:19:23 GREG: The router didnāt haveā like,
1:19:26 a) their password was default, asā unfortunately.
1:19:29 Number two, I wasā they had a administrative password on the panel.
1:19:34 So, the access was one password and then I brute-forced,
1:19:38 I believe, the password of the admin panel.
1:19:42 It was very close to standard password on there.
1:19:46 Gained access, unfortunately.
1:19:48 JACK: So, the guest Wi-Fi should only have very minimal access,
1:19:53 like just to the internet and no internal systems in the building.
1:19:58 But when he bridged the networks,
1:20:00 he could then access anything that other employees could access,
1:20:03 which gives him access to a ton of internal systems.
1:20:06 GREG: There, I start doing man-in-the-middle attacks, and let me tell you,
1:20:10 red teamers out there, pen testers out there,
1:20:13 never skip out on layer two attacks.
1:20:16 Layer two is your responders, your Cain and Abels,
1:20:21 your ARP poisoning, your DHCP spoofing, all of those.
1:20:27 That is gonna be your bread and butter.
1:20:30 I promise you those vulnerabilities are still existing there.
1:20:33 They still work.
1:20:34 I work engagements to this very dayā that is where so many places fail.
1:20:40 So, I man-in-the-middle.
1:20:41 Becomeā I start stealing credentials,
1:20:42 and this is back in the era before SSL security was everywhere,
1:20:46 so you could still do man-in-the-middle and downgrade websites to HTP logins.
1:20:51 [Music] I start getting credentials to people logging into work e-mails.
1:20:58 After about an hour, I get access to a relatively new hire.
1:21:03 She has six months of work in her inbox.
1:21:06 I access her e-mail,
1:21:07 and the first thing I do is I go all the way down to day one.
1:21:12 What do you get in day one?
1:21:15 E-mail.
1:21:16 You get your employee training,
1:21:18 you get your on-boarding information, you get your on-boarding documentation,
1:21:22 and if you come to this building, you get your building alarm code.
1:21:26 So, I have a physical alarm code that goes to her, and I
1:21:30 also have her badge ID number and what she looks like and such.
1:21:34 So, Iām like, okay, so what can I do next?
1:21:38 I remember theā Brando, theā myā the ex-Secret Service guy looking over
1:21:42 my shoulder and heās like, what are you doing?
1:21:44 He was likeā I was like, okay, so, you know the card readers?
1:21:47 Like, yeah; heās like, we're gonna clone one of these card readers.
1:21:50 Heās at this point where heās like, alright, goth guy, you're not so bad.
1:21:54 Okay, I like this idea.
1:21:55 Heās like, alright, Iām gonna work with you on this and Iām gonnaā heās like,
1:21:59 I talked with them, and we're gonna talk about
1:22:01 guard shift and times to get into this building.
1:22:03 I was like, okay.
1:22:04 So, I tell him my plan and I was like, man, so I got a building alarm code.
1:22:09 Iām gonna put a RFID cloner next to their badge reader,
1:22:13 and when they badge in, Iām gonna start getting all these badges.
1:22:15 Heās like, okay.
1:22:16 So, a day goes by, and eventually the girl whose building alarm code
1:22:22 comes in, badges in, and I get herā I have a Proxmark system;
1:22:26 I keep pulling it and all of a sudden I notice her ID matches up.
1:22:30 So, now I have her employee ID badge and her building access alarm code.
1:22:34 JACK: To get into this building you need
1:22:36 to use your little badge and tap the badge reader, and the door unlocks.
1:22:39 What Greg did is he put a little badge sniffer behind
1:22:43 the real badge reader so that anytime anyone taps their card,
1:22:46 he gets to see what their badge is,
1:22:48 and that essentially allows him to clone a badge.
1:22:51 GREG: They gave me a tour of the building at one point, very against their will.
1:22:57 They were kinda hushing me around.
1:22:59 The two things I noticed when they gave me that tour was,
1:23:02 a) there was a balcony on the second floor that had a tree next to it,
1:23:08 and from that balcony was a straight shot into their server room.
1:23:11 Basically you go through one room;
1:23:13 in that room you get intoā you go down one hallway and you're in a server room,
1:23:18 and the server room did have a badge reader on it.
1:23:21 The second thing I notice is sort
1:23:22 of likeā almost like a spiral staircase downward,
1:23:26 there was lots and lots and lots of paintings.
1:23:30 I remember asking during the tour;
1:23:33 I was like, whoa, these look like real paintings.
1:23:37 They nodded.
1:23:38 They're like, yeah, CEOā well, the CEO is here;
1:23:41 loves paintings, and this is their pride and joy.
1:23:45 They like to show art and they like to make sure thatā and I was like, huh.
1:23:50 Thatās interesting.
1:23:52 Thatās cool.
1:23:53 So, I rememberā so, for the next couple days, I had to get a badge of an IT guy
1:24:02 'cause I needed to get access to the server room, and eventually I get it.
1:24:06 Itās through the Proxmark system as well.
1:24:08 In the meantime, Iām doing man-in-the-middle,
1:24:10 getting credentials, doing the traditional attacking methods,
1:24:12 but I really wanted to focus on this whole physical element because theā Brando,
1:24:17 working with me, he was just like,
1:24:19 manā heās like, we could do some Mission Impossible stuff.
1:24:23 I was like, yeah, yeah, we could.
1:24:25 [Music] So, the next phase wasā they had cameras everywhere.
1:24:29 They had internal cameras, sort of external cameras.
1:24:33 I remember doing the netā so, eventually,
1:24:35 every day Iām folding different parts of thatā of their internal networks
1:24:39 into the guest network that Iām at so I can bridge over and start looking,
1:24:43 and eventually I find all their cameraā their camera network.
1:24:47 Luckily for me, they are using access cameras.
1:24:50 If anyoneās worked physical security,
1:24:52 everyone knows there was an era of access cameras from like,
1:24:56 2001 to about 2008, ā09, ā10,
1:24:59 where everyone hadā all these places had these access
1:25:04 cameras 'cause they had a ton of features,
1:25:06 they were cheap, they were Chinese-made, wonderful cameras.
1:25:09 However, they were the worst security ever.
1:25:12 They had so many default passwords.
1:25:15 They had buffer overflowsā in the access control systems,
1:25:18 they had buffer overflows,
1:25:19 and their web interfaceā they had a web interface that when you connected to it,
1:25:25 it looked like GeoCities.
1:25:26 It was straight up like 2002 internet all over again,
1:25:29 and thatās how you controlled the cameras directly.
1:25:32 So, talking to Brando and he was like, okay, look, manā heās like,
1:25:36 I know they do a guard change aroundā itās 2:30 a.m.
1:25:39 duringā around that time.
1:25:41 Heās like, you gotta be in and out of a building around this time.
1:25:45 I was like, wellā and heās like, also,
1:25:48 thereās gonna be someone always watching these cameras.
1:25:50 I was like, okay, thatās fine.
1:25:52 Heās like, what are you gonna do with the cameras?
1:25:54 So, I show him, and I start connecting to all these cameras,
1:25:57 and at the time there was an accessā
1:26:00 I think they were still running firmware from 2005,
1:26:03 and thereās an access buffer overflow that allows you
1:26:05 to control and gain access to every one of these cameras.
1:26:08 Still running that.
1:26:09 They hadn't patched them.
1:26:10 Jump in, and them from there I can access the shitty little interface.
1:26:14 I show him; I was like, look what happens if I modify these two values.
1:26:18 The values is brightness and contrast, and you can edit both of them.
1:26:22 Itās usually for when a viewer wants to look at the camera.
1:26:24 Oh, itās too dark or too bright.
1:26:27 They can edit these.
1:26:28 In UI, you can edit them a little bit, but programmatically,
1:26:31 you can edit them all the way from 0 to 255 values.
1:26:35 So, you can make them go all black or all white.
1:26:39 So, I show him.
1:26:40 I was like, watch.
1:26:41 We can make their cameras go boom.
1:26:43 Watch; I show the camera.
1:26:45 It goes distinctly black for a second, and then I undo it.
1:26:49 Heās like, oh.
1:26:50 I was like, yeah.
1:26:52 [Music] Heās like, alright, goth guy, alright.
1:26:55 I see what you're cooking here.
1:26:57 So, heās like, well, how are you gonna get these into an area
1:27:00 thatā how are you gonna do this in a way thatā¦?
1:27:03 You're gonna have to be carrying a laptop with you.
1:27:06 Itās gonna just be awkward.
1:27:07 I was like, thatās a good point.
1:27:08 So, in this engagement, I had a shuttle device with me,
1:27:11 a little, tinyā computers are the size of a shoebox.
1:27:14 A lot of pen testers use them for leave-behind devices.
1:27:17 On that shuttle device I put a Bluetooth radio on it.
1:27:22 So, with the Bluetooth radio, I was like, okay,
1:27:25 Iām gonna walk around the building and Iām gonna
1:27:28 get measurements of where Iām at with the Bluetooth.
1:27:30 Itāll signal their noise ratio, and when Iām in front of those areas,
1:27:33 Iām gonna map out what cameras those are at, and Iām
1:27:37 gonna make sure that I can get access to this.
1:27:40 So, I tested out the Bluetooth range.
1:27:42 I had to put a big antenna on this thing to get the Bluetooth receiver on it.
1:27:46 That worked, so I could have the Bluetooth
1:27:48 showā I go in front of these two cameras.
1:27:50 The two cameras that point outside to the patio, I could have them identified.
1:27:54 There was a camera on the inside there,
1:27:56 and then there was a camera facing the server room.
1:27:59 So, those are the cameras I needed to black out.
1:28:02 So, my app sends a signal to the Bluetooth.
1:28:06 The shuttle device would take that signal and relay it,
1:28:09 and when I receive those, it would send
1:28:11 the packets to those cameras to make the values,
1:28:14 brightness or contrast, to 255 or 0.
1:28:16 It was completely random.
1:28:17 Itās flipped back and forth between them to make
1:28:19 it look like a black and white screen,
1:28:21 sort of like an effect that was like the camera was malfunctioned for a bit.
1:28:24 So, I was like, man, I haveā I could look at these cameras.
1:28:28 I could test to see if this works.
1:28:29 Not sure if this is really gonna work, but we're gonna try it.
1:28:32 JACK: So, he set everything up to try to break
1:28:34 into the building overnight and not be seen at all.
1:28:37 The front door might have extra security and he didnāt want to take the risk,
1:28:41 so his whole plan was to sneak up to the building,
1:28:44 black out the cameras, get in, and gain access to the server room.
1:28:48 Keep in mind, everyone already was on high alert from this kid.
1:28:52 They thought he was very suspicious,
1:28:53 and he was going to have to do something over the top to get in.
1:28:58 Thatās when he realized his point of entry should be the balcony.
1:29:02 GREG: So, that night, man, I came in, 2:30 in the morning, climbed up the tree.
1:29:07 I get onto the balcony.
1:29:09 I push openā they had a security door on the balcony
1:29:12 that they would lock before you can get to the badge-reading door there.
1:29:17 I pry that open, I hit the badge key, go into the building.
1:29:22 The alarm starts beeping.
1:29:24 I hit the building alarm code, and lucky for me,
1:29:27 the girl had not changed her alarm code.
1:29:29 I was in.
1:29:30 [Music] I look at the cameras and I
1:29:33 remember being so nervous about this and being like,
1:29:35 oh man, this isā hopefully this will work or Iām gonna get tackled very soon.
1:29:41 So, I make my way over to the server room, and my secondary badge,
1:29:46 the other one I have from the IT guy, works for that one.
1:29:48 Badge cloned.
1:29:49 Got into there.
1:29:49 Went to the server room, and from there, boot-rooted all the machines.
1:29:52 So, if you're unfamiliar with boot root, back in the day,
1:29:56 this wasā you plug a USB device into the machine, you turn off the server.
1:30:02 The machine would then boot off the USB device as a recovery device,
1:30:06 and from here you would replace a Windows component.
1:30:09 Sticky Keys would be a ideal favorite.
1:30:12 So, you replace Sticky Keys with command shell, and then you reboot the machine.
1:30:16 So, the machineā after you do that, the machineā you reboot the machine.
1:30:21 It goes into the password login prompt, and you hit Shift five times.
1:30:25 That would then launch Sticky Keys,
1:30:27 which has now beenā become a command prompt instead,
1:30:30 and now you have a command screen on it,
1:30:32 and then you can run commands as elevated privileges like you're on a system.
1:30:37 So, youād have elevated command.
1:30:38 So, from there I exploited all the machines.
1:30:41 I dropped a flag that said I was here,
1:30:44 and then I went into their stores and put flags on all of those.
1:30:48 JACK: Heās done it.
1:30:49 Heās successfully hacked into the servers Mission Impossible style.
1:30:53 So, he starts to go out, but he notices something.
1:30:56 GREG: Those paintings.
1:30:57 So, I proceed to go down the staircase, and I go down to the paintings.
1:31:02 I just quickly grab a sticky pad and put little happy faces,
1:31:06 like a little sticky page,
1:31:08 and start putting them right next to all these paintings.
1:31:11 Thereās a little placard for each of these paintings
1:31:14 telling you essentially who made these paintings,
1:31:17 what did it symbolize, in some cases how much they were worth.
1:31:21 I stick little happy faces on it that says, I stole this.
1:31:24 JACK: Huh.
1:31:25 So, itās typical for a physical pen tester to leave a token behind to prove
1:31:29 that they were there in a server room or a desk drawer or something.
1:31:33 I mean, just think about how you would feel if you went to bed and then
1:31:36 woke up and there was a sticky note
1:31:38 on your bathroom mirror that said, Greg was here.
1:31:40 Just a small note like that can say a lot, can't it?
1:31:44 Here, what Greg was doing was proving that he had access
1:31:47 to these paintings and he had time to go right up to them,
1:31:51 put notes on them, and security never saw him do it.
1:31:54 So, he wrote āI stole thisā on a bunch of sticky notes,
1:31:57 and just kept putting the sticky
1:31:59 notes on painting after painting after painting.
1:32:01 GREG: I remember 6:05; I get a call.
1:32:05 Greg, Greg.
1:32:06 Yeah?
1:32:06 Was this you?
1:32:08 Whatās the happy face?
1:32:10 Whatās that mean?
1:32:11 How did you do�
1:32:13 What is�
1:32:14 It doesn't matter.
1:32:15 The CEO wants to talk with you today.
1:32:19 Get in here, like 8:00.
1:32:21 Heās like, I don't know, man.
1:32:23 Heās really upset.
1:32:25 We have to figure outā I was like, okay, okay.
1:32:30 In the meantime, physical security hadā they had a incident
1:32:36 'cause they were looking over and they were like,
1:32:38 well, someone walked in and put all these happy face stickers on there,
1:32:41 and they walked out the building.
1:32:43 They're like, what does this mean, āI stole thisā?
1:32:46 I remember they are coming aroundā and I get to the building.
1:32:50 They escort me to the board room.
1:32:53 The board room has this massive table on it.
1:32:59 Me, in my awkwardness, I pickā I remember sitting and picking the exact opposite
1:33:04 of where I imagine every oneā the exact corner of it.
1:33:07 The physical security is like, no, get over here, get over here.
1:33:11 First, give us your ID again.
1:33:12 We're gonna run some background checks on you again just to make sure.
1:33:14 JACK: Physical security knows to treat those paintings
1:33:17 with a very high level of security.
1:33:19 So when the CEO came in and he saw his paintings had sticky notes on them,
1:33:24 he simply asked, who did this?
1:33:26 What does this mean?
1:33:28 When security had no idea, then the CEO is like, okay, well, find out.
1:33:33 Then when security looked at the cameras,
1:33:35 they saw they were glitched out during that time,
1:33:38 and they had almost no evidence of who did it.
1:33:41 This made the CEO furious.
1:33:43 What do you mean no security footage?
1:33:45 Find out who put these sticky notes on this.
1:33:48 The cameras around the building were just all black or white because Greg hacked
1:33:52 into them to prove he could sneak
1:33:54 into the building late at night with nobody noticing.
1:33:56 GREG: The VC came in.
1:33:57 The VCO came in and was like, what the fuck?
1:34:00 What is this?
1:34:01 What do you mean, stole my paintings and little happy faces on them?
1:34:05 Thatās what kicked off the security team alert.
1:34:07 I remember I was sitting there,
1:34:09 and then my contact leans over to me and heās like,
1:34:13 look, again, I have never seen him cancel meetings
1:34:16 and move so and to see someone like this.
1:34:20 So, I don't think itās gonna go well.
1:34:22 Then I look over to Brando, and Brando is just likeā you know, heās like,
1:34:28 maybe we flew a little bit too close to the sun here,
1:34:30 a little Icarus just a little hard, but whatever.
1:34:32 [Music] So, the CEO comes in with this single security team.
1:34:36 They hand me back my ID, and he looks at me,
1:34:42 and Iā you can tell the thoughts of this goth
1:34:48 kid in his board room is not what he expected
1:34:53 and not what he was expecting to meet for when heā
1:34:59 and he looks over and heās like, you hired this guy?
1:35:02 My contact who worked at the company was just like, yeah.
1:35:05 Looking at him, heās like, alright.
1:35:08 Heās like, so, walk me through what you did.
1:35:13 For the next ten minutes, I retell him the story of exactly how I did it.
1:35:18 This VC previously had been very technical.
1:35:20 He was a code developer.
1:35:21 He worked on software.
1:35:22 So, he starts going and he starts asking me very intelligence
1:35:24 questions aboutā we start having a back-and-forth about, oh, okay, so whyā¦?
1:35:28 Heās like, so, two questions for you.
1:35:32 First, what were you gonna do with the paintings?
1:35:37 I was likeā I was dating a girl out of Brooklyn at this time, and I was like,
1:35:41 you know, I was thinking of taking them to Pratt
1:35:44 University and maybe fencing them at the university there.
1:35:46 Thereās gotta be someone who knows some weird
1:35:48 connections at Pratt Artā Pratt Institute of Art.
1:35:51 He starts laughing.
1:35:52 Heās like, alright.
1:35:53 Heās got a plan.
1:35:55 I was like, okay.
1:35:57 Heās like, I really like those paintings.
1:35:59 He was like, I can't believe you wouldā I was like, yeah,
1:36:02 I absolutely would have stole them right out fromā nothing to do.
1:36:06 Heās like, alright.
1:36:07 So, then heās like, alright.
1:36:09 So, my next question is what are you doing next year at this time?
1:36:15 Thatās how I became their reoccurring red teamer for four years until they
1:36:19 got tired of me breaking into the buildings and doing all the things,
1:36:24 and hired me as full time.
1:36:26 So, after this I got introduced to a lot
1:36:29 of the various levels of executives for this, and I
1:36:33 got to pen test all their personal houses and got
1:36:37 to show them howā why physical security is important,
1:36:41 gaining access to all their penthouse suites, all their large houses.
1:36:47 I did that for quite some time afterwards.
1:36:51 (Outro): [Outro music] A big thank you to Greg Linares, AKA,
1:37:01 Laughing Mantis, for coming on the show and sharing these stories with us.
1:37:05 Please consider supporting this show by visiting plus.darknetdiaries.com.
1:37:08 If you do, you'll get eleven bonus episodes and an ad-free version of the show.
1:37:13 By becoming a supporter is the most direct way that you can
1:37:16 help make sure this show continues running and delivers you more episodes.
1:37:21 Please visit plus.darknetdiaries.com.
1:37:22 This episode is created by me, CAPTCHA America, Jack Rhysider.
1:37:27 Our editor is the super subnetter,
1:37:29 Tristan Ledger, mixing done by Proximity Sound,
1:37:32 and our intro music is by the mysterious Breakmaster Cylinder.
1:37:35 Iāve been working on a new dance lately.
1:37:37 It requires the most efficient use of muscle
1:37:40 memory in order to spin at the perfect RPM.
1:37:44 I call my dance the algorhythm.
1:37:46 This is Darknet Diaries.