We were just by a cool looking domains so that we could have like a hundred character along the host so that it says like i.am.n.your.computer.today. And just these we would have like a whole message. I'm not sure y'all know this but two of the most respected hackers in the CTPB community bus factor and xs s doctor are now running monthly hackalongs on the CTPB discord. Okay, you've got to check this out. CTPB.showslash discord. We find bucks almost every time we hack. It's crazy. And oftentimes it's not even the people running the hackalongs. It's the community members that are hacking along with us. You definitely increase your chance of finding a bug by being on these hackalongs. So check them out. Join bus, xs s doctor and yours truly. And let's pop some bugs. Let's go back to the show. Sup guys got that this week in bug bounty segment for you. Yes, we hacked trapped another great blog. Alex Brumens. I tell you man, what a researcher. And this article that he released that I want to cover real quick called Python pitfalls has some crazy, crazy stuff in it that I've definitely missed in prior assessment. So check this out. The first one is in pythons OS dot path dot join, which I've seen many times. So in the example here, he says OS dot path dot join passes in slash user slash uploads and then the payload received from the user, right? Well, if you give it just an absolute path, it just ignores the prefix, right? So if you give it as arguments, I'm trying to put this in audio for you guys. OS dot path dot join slash user slash uploads is the first argument. And the second is slash at C password. That will resolve to slash at C password. It'll just ignore the prefix, which is super crazy to me. So yeah, don't even worry about past reversals. You can just put in the absolute path. Very odd. And then there's also this one down here. It's the same sort of situation, which is apparently URL lib dot parse dot URL join does the exact same thing, but for domains. So consider this. You have URL lib dot parse that URL join. The first parameter is HTTP colon slash slash example dot com. And then the second parameter is HTTP colon slash slash evil dot com. So you're providing an absolute URL. The output of that is evil dot com. It just removes the whole example dot com piece, which is nuts to me. So Python's got some crazy weird quirks. Apparently you should just be eating absolute file paths and absolute your eyes everywhere into Python. And it just will just accept it. So check out this article. We'll link it in the description. There's lots of other good stuff in here like pickle de serialization and stuff like that. Okay. So that's that. Next is actually a quick announcement that I wanted to remind you guys. We talked about it on the Google Cloud episode, but Google Cloud VRP is offering a bonus to all critical thinking podcast listeners. If you mention the podcast in any rewarded report between now and the end of April, you will get an extra reward either cash or swag. So definitely want to do that. So drop some love for us in those cloud reports you guys are putting in and get yourself a swag. All right. That's it. Let's go. Let's jump to the main show. Dude, come in. Man, I've been looking forward to this episode for a long time. And this is a special episode for me as you guys know because Tommy is a part of my hacker origin story, especially in the Bug Bounty world. So dude, I owe you a debt forever for introducing me to Bug Bounty that day. And the reason that happened was, yeah. True. But the reason that happened was you just showed up at my VCU College Cybersecurity Club. And we're just talking about Bug Bounty random. We had, do you remember how that happens? Whoever the president was, I don't remember his name. Parker, yeah. Yeah. So he had emailed me or reached out to me on Twitter. I don't remember which one it was. And he had asked me if I would come and talk to you guys about it. And I was like, yeah, I guess I had absolutely no idea what to expect. I wasn't expecting like 10, nothing. I could stop with kids standing in a, what was it? It was like a computer lab. Yeah, computer lab. We grabbed a corner and stuck like a server rack in there. Yeah. And yeah, I wasn't expecting what it ended up being. But it ended up working out. I had to let both hacker one Bug Croud, I guess all three. Hacker one Bug Croud and Senate. I had to let all three of them know that it was going to be doing it. Nice. And then they sent them to send me some stickers and swag and stuff to get out. I think hacker one was the only ones that actually did. Yeah, you sent this. He gave us some good stuff. Bug Croud and Senate did or they couldn't end time, something out. But yeah, he emailed me or deemed me on Twitter. That's so fun, man. And since y'all were local, I was like, yeah, anytime. Because it's like 10 minutes from my house. Sure, I'll pop in there. Yeah. Whenever. Well, it's funny because I was running, you know, he's my co-president. And I was running the labs at that time, you know, and then you just showed up, you know, and I was like, he didn't even tell you about it. He didn't even tell me. Yeah. Oh, man. He didn't even come. Yeah. He didn't even show up. Shout out to Parker, man. I don't know if you're listening, but that was the most poorly organized thing that had the greatest impact. So yeah, definitely grateful for that. Well, you know, how we do it here on the pod. I guess we didn't even really talk about this beforehand. Typically on the podcast, what we do is have guests bring a vulnerability that they want to talk about, you know, and give us a little summary just to, you know, prove some expertise. Obviously, talking to the law, guys, we don't have much to prove here. A legend. But if you have anything you want to bug, you want to run by us or you can talk about your more recent fuzzing stuff or. Well, the fuzzing, I can't talk about the bone jet. It hasn't been long enough to wear my body to disclose them. Right. And I don't really want to make Google mad. Yeah. I like them being nice. I guess my favorite bug is still from Yahoo in 2018. That bought me my GTR. I was in Las Vegas in October 2018. I had like moved out there halfway for most of 2018. And I was waiting for my friend Steve. We were going to go do something tonight. I don't remember what it was, but he was taking a shower and he was like, I don't know what this come across the wrong way. But he took forever to get ready like a girl. It took him almost two hours to take a shower, do his hair and everything. It's like, dude, no. But I was bored and I went and took out my computer and I was sitting on his kitchen table. And I didn't want to start hacking on anything new because it's like, I only had a little bit of time. I don't want to give that. I could have had two hours. Yeah. And I don't want to get into something and then have to stop it. This morning having to walk away from looking at Peter was driving me nuts. I'm so sorry, dude. Like literally he popped an RCE on one of his bugs as he was walking out the door. Yeah, I literally did it and then I had to walk out the door. But I was worried about doing that back when I was at his house. So I went and opened up my hacker one reports and just picked a random SSR from Yahoo. And decided to start playing with it. And I had all kinds of success in coding the IP addresses in different ways to bypass because they used a blacklist. They didn't use an allow list. They used the blacklist and blacklist are very, very, very bad. Well, I don't even know why it worked, but I was super snowed. So I decided that I was going to take the AWS metadata IP and instead of encoding the entire thing, I took just the first 169 and octal encoded that left the rest of the IP the same. And it worked for some reason. I have absolutely no idea why, why logically it shouldn't have worked. And I was just trying things because I was sure in the past time. Well, it worked and I got the AWS credentials again. So then I went back into my reports and I pulled every single SSRF that I had against Yahoo from the last three years. It worked on every single one of them. So I went and found 18 new reports each for each one of them was a unique location and everything. But they needed to go and update their gen I list again. And they paid me 10 grand for each one. So I got the 180 grand and then that's not four days later, I flew back here to Richmond and sat outside of the dealership that had my GTR until they were open at 10 30 in the morning and told them that it was mine now. That's crazy. So you had, you went back to all of your previous reports. So that's one, I think that's.
great takeaway for the listeners as well. It's like if you do have a short amount of time, perhaps, to hack, go back and look at a report that you think you may be able to bypass or something like that because then you don't have to spend time finding something interesting. Yeah, exactly. It's a great way. And I mean, things change. So even if it's not bypassing the old vulnerability, they might have added new functionality to the exact same little area that you can quickly play with. And you already know at least enough about it to find some vulnerabilities. So anything that's different there, it's less of a learning curve to translate from not doing anything to instantly be know, excuse me, to get in there and hack. Right, right. Make sure you don't bump your mic when you're when you're doing that. Yeah, dude, totally. I think that, I think that that technique is really interesting too because obviously, so just to speak it out, you know, plain and clear, you had an SSRF, you were going to hit 169.254.169.254, which is the AWS metadata endpoint, which was going to drop back the access credentials. Yeah, because I had already done it in the past. So I already knew the exact path and the key name and all that stuff. So I was just trying to find a new way to represent the IP address that they had an account it for. Nice. And the way you did that was taking that first 169. Just the first one. Because if you did any of the other ones, it wouldn't work. Or if you did the entire IP, it wouldn't work. It had to be the first 169 for some reason. I'll have to look that up. I'm not sure. But I imagine what happened to there is that when you had that first octet encoded with four characters rather than three, right? Yeah, it's like, it's like, oh, two, it was like, oh, five, two, six or something. Something crazy like that. Like it doesn't even, when you're looking at it, it doesn't even look like it's a valid IP address. But it was according to Yahoo, it wasn't. And actually just so recently within the last two weeks, I saw some other kid on Twitter post that he did the exact same thing, not the Yahoo, it was for somewhere else. But he did the exact same thing like just a couple of weeks ago, when it's still working. So it's still something that is valid today. It's still one of the things that I try anytime I find something that I'm going to test for us. Well, nice man. Good, good bug. I think that you were the first person. And I don't know if you were the first person to discover it at all, but you were definitely the first person I heard talk about the AWS metadata URL as well. And also this octal encoding. So for a lot of the Bug Bounty community, I think that was you know, you were the introduction into that. For the octal maybe, like I remember the first time I hit the EWS server was actually on Yahoo as well. I was sitting in AWS reinvent up in DC. Yeah, that's right. Yeah. I had gone up there because me and a friend of mine here locally, Josh, we had started a company here in Richmond for security. And we wanted to go up there as part of the company. It was right before or right when I was leaving my previous job and getting ready to do bug bounties full time. And that's where they taught me about the metadata server. I had no clue what it was. And I'm sitting in a in a talk there with my laptop next to Josh. And then they told us about the IP and that it could be used to get the access access credits and everything. And I was like, hold up. So then actually sent Sam ZLZ a message because we had been hiking on Yahoo. And there was this place in their small business. You could used to be able to go and buy hosting and domains and stuff from Yahoo small business. And there was a place on one of their main front pages where you could give it a URL and it would go take a picture of it for you. And we used that to take a picture of AWS access credentials. Of course. And that was the first time I'd ever gotten into work. It's so funny. You talking about this because I don't remember very much from that era at all of like what was going on in life and stuff like that. I remember everything that you just said like it was yesterday. Man, like the Yahoo domain stuff. I remember as well. Eight of US stuff. I was like, wow, this is the most interesting thing I've ever heard in my brain just like clamped on it like, you know. So very good times back in the day watching you and Sam. Oh, it was a lot of fun. It was a lot of fun. And they had stoop like we weren't even finding anything crazy. It was just stupid, simple excesses and stuff like that because it it's exceptionally hard, especially when you've got a website builder as part of your product. It's exceptionally hard to do that in a safe way. And yeah, it took Yahoo a while before they were able to do it. That was good scope. It was good scope, man. I was sad when they took it out. Yeah. I was real sad. So, so, you know, pulling on that thread a little bit like you, I've already talked about how you're, you know, a part of my origin story as a hacker, but also you were a strong influence on Sam, Sam Curry and Corbin Leo and some of the other earlier on hackers that kind of popped up in the scene and started, you know, going to live hacking events and stuff like that. So, I mean, was that something that you were always trying to, you know, do intentionally or was that just a part of you being early on in the bug bounty scene, you think? A little bit of both. I'm older than most of y'all by quite a bit. And it's been really important to me to try and get younger hackers, including all the way down to kids like in middle school involved in it. I got curious when I was in like late elementary early middle school. So, I know about when kids start getting interested. So, that's why I like going and speaking at middle schools. I haven't spoken in an elementary school. I don't think that would be appropriate because I'm not sure that the kids in elementary school are quite knowledgeable enough about computers as a whole like they know how to open up robots or Minecraft. That's about it. But once they're in middle school, they're actually have the ability to take classes, programming classes, typing classes and that kind of thing. And they're actually using computers more. And I don't want them to make the same mistakes I did. It's, I have been having this conversation a lot the last couple of weeks. But when I started, we didn't have virtual machines. We didn't have a lab that you could go like try hack and try to hack and all of that kind of stuff. We didn't have any of that. Our practice was the real world. We had to go and hack real systems. And if you wanted a challenge, you had to go and make really stupid mistakes in government military systems. Yeah. Yeah. Okay. So, let's, let's go down that path a little bit here. So, that was a part of your origin, right? You were a black cat earlier on and got caught and kind of reformed there. Do you want to give us like the five minute version of that story so that we can have that context? Yeah. IRC was a fun place in the 90s. We like to take channels from each other. So we built very, very large botnets to DDoS people. And yeah, you're, I don't even know if you're old enough to remember. There was this kid in Canada named Mafia boy back in 99 2000. He's credited with the first large scale DDoS attack when he DDoSed like, eBay and like, I don't remember all the sites, but it was any of the big sites that were on the internet back in like 2000. And he was actually the kid. We were fighting on Fnet for our channels. He was a member of TNT. And I was with TDK, those damned kids. And we were constantly fighting over the channels with him. So that botnet that he used against like all the Fortune 500 companies all the time, he hit us with it a lot and it would take us offline a lot. But I spent a long time doing that. I changed in about 2000. Thought it'd be fun to deface websites. So I started doing that. When you were doing the botnetting, how were you getting these compromising these machines? Was it just rats? So you like, no, no, no, there was no concept of that. No, like the only rat there was at the time was like sub seven. And then CDC, the cold of the dead fell put out a back office. But and there's they were only windows based. When I was a hacker, we had a rule in our groups, you weren't allowed to hack windows. It was too easy. It was too easy, dead ass. Don't need to cuss, but you weren't allowed to hack windows at all. We felt that hacking windows was too easy. But every system back thing could be hacked. Literally, there was no such thing as a secure system. Right. Because these things were designed with how thinking that somebody might want to break into whatever the internet, the internet was still fairly new. It was 10 years ish old, maybe a little bit less. So it was it was a completely different world. There was no such thing as a web vulnerability. I don't even think we had databases. Like for you to store. You didn't have databases. No, it wasn't a concept. It was stored on disk. Like if you were to go to a website and purchase something, they would actually save your name, address, credit card number, and all of that into a text file on the web server.
Like on the web server, all you had to do was break into the web server and go find like cc.txt and you had a list of everybody's legitimate info. That's crazy dude. What a time this was before we had those little three digit codes on the back. Like I remember being a kid and we had credit card generators where you could literally open up this tool, click a button and it would give you a credit card number in an expiration date. It didn't need the three digit code because that didn't exist yet. They created it because of this fraud time period. I bought probably a hundred thousand domains. No domains for like a dollar a piece just by clicking this little button and say, hey, generate me a credit card. No. It would just generate one. You didn't need any name or anything like that. It was all you needed was the 16 digits and the four digit. What a time man. Yeah, because they weren't connected like they are now to, I don't even know the payment process companies anymore, but they weren't connected to them in real time to be able to actually validate them and everything like that. So I think most of the companies would just kind of like if it was the proper format and looked real, then they would accept it and then they would find out a couple of days later that oh, it wasn't valid or something like that. So when it was with four domains back then to go and IRC, we always wanted a BNC. And it was just a B host. It allowed us to hide our ISP and IP address behind it. And you used to have to pay companies each month for them to create you a B host because then they would create you the B host. And if you paid them the five dollars a month or whatever, they would make that B host reversing us to a certain IP address. So that way you could go on IRC with it and everything and it all looked right and we would just buy a cool looking domains so that we could have like 100 character long B host. So that it says like i.am.n.your.computer.com. And just these we would have like a whole message as our host name. Wow, dude. What a time. So after the IRC era, you kind of moved into website to basement, right? Imagine that was your intro into like web vulnerabilities and stuff like that. No. Just don't know web vulnerabilities. Okay. There's no such thing. Okay. So like there wasn't like websites back then were written in either HTML static files or yeah, it was it was like I don't even I don't remember if we even use JavaScript. Yeah. Like I'm trying to remember. So would you just like use some network level exploit to get access? Yeah, yeah, it was always it was always we would route them through telnet SSH. F2P. Brutum through telnet. Yeah, telnet every telnet. Solaris, which is son of us. Yes. Whatever you want to call it. All versions of BSD free BSD net BSD BSD, Open BSD. I think there was one more to it. I think there was like five of them. Did you just leave telnet open like or would you have to use a telnet exploit or what? You would use a telnet exploit, which got to remember something. Everything had telnet back then. We SSH was new. SSH was new in the mid mid 90s. I want to say mid to late 90s was when it was starting to be adopted and it was significantly more common for them not to have SSH than it was for them to have SSH. So everything was telnet. So the whole process was use a telnet exploit or whatever they exploit you wanted to use. Whether it was telnet, we RPCs, RPCs on Unix boxes, listen on port 111. I think it is every single RPC that listened on that port had a remote root exploit, every single one. So the printers name bind what underpins our name, that had tons of vulnerabilities back in the day. That was a huge target for us. We always wanted to compromise name servers. But we would compromise them. Because everybody was using telnet, we would install packet sniffers, key augers on it so that we could get the telnet credentials of anybody that connected to that machine and used it to connect to others. We would target university computers of that. Taiwan, Korea and Hong Kong. Those three countries were, they were always farther behind like most of the rest of the world. Like we're running Linux 5.2, they're still running like 4.1 for example. So they were always running super old operating systems that always had vulnerabilities. Anytime you needed shells, because our rule was you don't hack from your own system. You never hack from your own system. So you would get either take the risk that first time and hack something overseas and get the access to that box or you would get somebody to give you access to a box overseas. And anytime we needed shells, we would scan the entire class A of 200. And 210. Because there you were guaranteed to get a few hundred root shells. Wow. We were scanning those. We would write auto-rooters that would scan through these things that are you just like helping on by a telnet and then you're running the exploits from there. That's all we would do is now starting in the late 90s and early 2000s, we weren't using telnet anymore. We were using back-to-word versions of SSH. So that way it was encrypted. And we would have our root kits installed so they couldn't see anything that we were doing and have our hidden directories and everything. And we would just use those essentially as a jump box. We would use those to do the hacking and do the connecting because back then we figured that it would just be a lot harder for them to, the websites that we hacked would trace it back to that Korean or the Hong Kong or the Taiwan East server. And then we were banking on the fact that they weren't technologically advanced enough to be able to trace it from their back to us. So I mean, that sounds like a good playman. How did you guys get caught? I love people tell. Yeah, people talk. Yeah, that's what it always just about came down to. Calhade got arrested because of Defcon in '01 at the Alexis Park. You know, they have the little scavenger hunt, well, the scavenger hunt that year took you to a pay phone that was 24-carat-plated gold on the wall. He ripped it off the wall and took it to him instead of taking them to it because you got to remember something. You didn't have camera phones back then. So you couldn't just take a picture with your phone and show them you found it. So instead of taking them to it, he ripped it off the wall. You got arrested at Defcon. We all went home a week later. He puts on our website, he makes Rafa makes a graphic for him and then he puts it on Calhade put it on our website and it was bragging about him getting arrested at Defcon for ripping the pay phone off. The FBI monitored our website, so they saw his post. They went to Las Vegas and said, "Hey, tell me who you arrested during this week for doing this." Oh, no. They gave him his information in Tennessee, so they went to Tennessee and he was 15 years old. I had broken into the. Wait, Calhade was 15 years old at this time? Yeah. What? How did he get. Did he live in Las Vegas? How did he get to Defcon? That's what I'm getting ready to explain. Oh my God. This is crazy. I'd broken into the Utah DMV computer systems so I could actually create fake IDs, but mine, if you got pulled over by cop and handed him your ID, you were okay. I would actually put you into their system and all of us had an ID that said we were 22. I wasn't, but 17, almost 18. Oh my gosh. And your parents were just like. Oh, they didn't care. They didn't just go on. No. Yeah. I was going to conference five. No, I didn't even. It wasn't even that. It was just I left. You just left. From the time I was like 13. From about 13 on, I could pretty much do whatever I want. I got expelled from school in 2000. And my punishment was I went on vacation for a month in New Mexico with other hackers. Oh my gosh. So. Well, that is one way of doing it, I guess. So okay. So he gets caught. Yeah. After the FBI site, or the FBI monitors that site, they track him down. Yeah. He was only 15. Yeah. He had pictures on his computer of him and his girlfriend who was also 15. So yeah. People don't understand that that still counts as child pornography. Right. So they threatened him to charge him with possession of child pornography. And though it was him and his girlfriend, consensual and all of that, they threatened to charge him unless he told him on us. So he's holding everybody. He didn't know enough about me to know where I lived or anything.
but he knew enough about one of our other members, Noid, and Noid actually lived over in Charlottesville. - Oh really? - Yeah, me and Noid went to King's Nominion and stuck a few times together. And they caught Noid when he was boarding an airplane to go, he was Brazilian, and he was boarding a plane to go back to Brazil because we had found out Calvary had gotten busted, and they caught him when he was getting ready, like literally getting ready to board the plane. - Wow. - He knew enough about me. - Right. - So out of the 13 members of the group, there was only one that didn't tell. - Wow. - It was Rafa. - Wow dude, that is a crazy time. Just trying to like put all of that together in my head. It's like, you guys were so young. - Yeah. - That's nuts and boarding planes and like crafting these fake IDs and like, that's nuts man. - Yeah, it was a fun time. I got a lot of fun back then, and I wouldn't change it. - So you got caught, you went away for a little while. How long were you in prison and? - The first time two and a half years. - And then I came home, and when I got exposed from school, they banned me from touching the computer because one of my charges during the expulsion was for a computer hacking as well. So they banned me from computers. And then when I got released in '06, I'm not a fan of people telling me I can't do something. - Right. - So I didn't listen. I stayed off a computer for like a month. By February, I was back on the computer. - And so you got to be torture man, like, - Yeah, I can imagine. - Especially being like, I'm ADHD. The only thing that can keep my interest is computers and hacking and security. So it was like, I was working bullshit jobs as construction. I was a chef for a little while and it was just boring. I hated it. And I started getting back on the computer again. I started, I joined another group called Core Project under a different name that time. And defaced a few websites again. One of them was Yahoo. They got real mad at me. It was biz.yahoo.com. And for that one, I wasn't allowed on computers. My probation officer would show up at my house randomly, like at least once a month. He had come over like a week before. So I was like, he's not gonna, he had never come again for at least three or four weeks in between visits. So I figured that was good. I was sitting on my computer one day and I had my computers set up in my room so that I, there was the walls are like this. My computers were right here and I was sitting right here facing this way. But literally right beside me, I had two giant windows like double the size of this window right here. So that I could look straight out into my driveway. And my driveway was pretty long. He had to come into the driveway and then turn and come down a little bit, turn again and then come back. So you'd have some time. I had some time. I see him pull in like starting to pull into the driveway and I panic. I jump up out of the chair, start taking laptops, weren't as prevalent as back then. So it was always desktops. So I start ripping everything apart. I take the keyboard and the mouse, throw it onto my bed. As I'm taking the tower out, I don't remember where I hit the tower but I hit the tower somewhere in the house, came back, got the monitor, hit that somewhere else. Things are heavy as shit at that time too. Yeah, they were. I forgot to grab the keyboard. Freaking keyboard, man. I left the foot of my bed. Proveation officer comes into the house and one of their things that they do is a inspection. So they walk through every single room of the house and look through every, they aren't allowed to actually search, search, but they can come in and anything that is within their view. They're allowed to use against you. So damn it. Did you get any walking through the whole house and open in the closet so you could peep his head in and everything? Let me get up to my room. And the keyboard was sitting on my bed and he used that as saying there was enough probable cause to say that. To search or something or to consider me in violation of probation. Because there was no reason to have a keyboard. If I didn't have a computer. So he violated me on my probation. And the funny thing is he gave me my little violation hearing for like the next week. I went to it. I had been doing a lot of drugs, but I was using these drinks and pills that are supposed to clean your system. You know what's happening to take a drug test three times a week. And I was taking these and they never said that to anybody. They never said nothing to me, right? When I went to court for my violation, they called me out. I had to feel 17 tests in a row for cocaine. - Yeah, you're kidding me. - I passed them all for weed. And I took every test high. So the drinks and pills I was using, it was these like cleaning things that you take it. You drink 32 ounces of water and you're clean for six hours. No, I was taking those. They're just like little detox things. And they worked for weed. They didn't work for coke and I had no idea until I show up and the judges like, "Yeah, well, you've got 17 violations for a failed drug test for cocaine." - Oh, crap. - And then for having-- - And they never told you once. - They didn't tell me-- - No, I was there. - Until I was there. So then they gave me another year. So I went back to prison for a year, or a little longer a year. And then I got out again in in late 2008, I think it was. So then at that time I was good when I came home that time. I didn't go back to hacking. I got an Xbox and started playing Call of Duty, which I wasn't all to do. I wasn't all to have a game system. - I was gonna say like, dude, that's computer violation. - I then, I started playing a browser-based game. My sister had come up from Florida to visit with her fiance at the time. And he was playing this game called Evony. - Oh, yeah, dude. - Yeah, so he showed it to me and was telling me about how people were finding exploits and stuff like that and they were making money selling resources. So I was like, I'll give it a try. I wrote the first box. - You said you were good, dude. Hold up. You said you were being good. - I was just playing games. I wasn't hacking anything. - Oh, sure. But I wrote the first box for Evony. And then there was a business. Two doors down for me at this time. And they got broken into and the only thing that was stolen was computers. The cops in Hanover, they know my history. I've been running in with them for a very long time at that point. And they swore up and down it was me. Rafa was also doing like at hacking again from Venezuela. And he had somebody in America working with them. They swore that was me. So they watched me, the FBI watched me for six months and could not get any evidence against me. So then they used the burglary at the business. Two doors down as an excuse to raid me and look for those computers and then find anything else that could have happened. So I was up playing Evony until 5.30 in the morning on October 8th of '09. I went to bed and lay down between 5.30 and 6. And the next thing I know it's 6.15. And I hear something banging on the door. So I went downstairs and I peeped around the corner because we had those glass things beside the doors. You can see outside. And I could see people standing out there but they're beating on the door saying, police, get out the house. I live at the time. I live like two miles from a jail. And people escape from it every once in a while. And when they do, they search our areas. And I thought somebody does escape from the jail and they were like in my backyard. Oh my gosh. So I go and open the door and they bush through that door. They bush through the door with their M16s. They handcuffed me. And this is in October. It was cold as hell. I'm in just sweatpants because I was in bed. They've got me handcuffed for over an hour, laying off, face down on the floor in my living room while they secure the house. And then they found few computers. I think you can hear it here. Some Xboxies and stuff like that. So they sent me back for a year and a half that time. But it was the reason they sent me back for a year and a half was because they were trying to build a case against me for doing stuff with Rafa again. And I kept trying to tell them every time y'all've ever come and rested me for something. Once y'all get to the point where you show up at my house, it's too late to deny it. They know it was you if they ended up at your house. If you're actually the one that did it. So I've always been honest. Like you come and kick my door and say, hey, where you hacking this? You just kicked in my house.
I'm gonna admit it because I'm gonna try and not get as much trouble. You have a least enough that led you here. I kept trying to tell them that it wasn't me. And they didn't want to believe me. So they gave me 16 months, 15, 16 months, that time to build the case. And then four months into my sentence, they came and visited me and apologized. They found a person that had broken into the business to do or stand. And they had found the person that was working with Roth. That was like him with Roth. So I asked them, "Hey, does that mean you're gonna let me out of here?" And they were like, "Well, you were still in violation of your probation for having the game system, cell phone, and the computers, but they killed my probation." And they removed the limitation that I was banned forever from a computer. And they removed that from me, I kind of is like their apology. That's percenting me back. That's a great, a great completion error. And they ended up working out because otherwise I wouldn't have been able to do by Bounties or anything. I still probably would have done it, but I would have just gotten control. And then you would have this year in prison every couple years of situation. It's like, if I get in trouble again for computer crimes, it's life. That's why I. That's why you're really. That's why yellow people all the time about scope. They don't understand. The only reason Bounties are illegal is because the company says, "Yes, you can do this if you follow these rules." If you follow. If you deviate from those rules, what, in any way, shape or form, there is absolutely nothing you can do to prevent a CFA violation. All it takes is one pissed off, chief legal officer one day, or one company to be having a bad time. And then you go out of scope and them just say, "All right, you know what? Screw it." And they go after you. And it's like, just because it hasn't happened yet, doesn't mean that it can't. And I'm not willing to take the risk that it would be. Let me ask you your take on this then, because you've, you've hacked with Sam a good bit. Sam does a bunch of like. Just, I'm gonna hack this company and do a write-up about it under the name of security research. And he, you know, I've talked to him about it at length and he's like, I'm pretty sure it's under this like fair usage policy of these websites, you know, for security research purposes. And I say, "Dude, I wouldn't do that." If they explicitly have a VDP or bug bounty program, you're legal. If they don't and you do not have written permission, it can't even just be them. You know a friend that works there and he said, "Yes, you can, no. You have to have written all, it's no different than a pen test. If you're going to go pen test the company, you wouldn't pen test them without having scoping documents over what you're allowed to hack, what you're limited and everything, it's no different." So, there's a lot of people that will pick a random website. And my big problem is when these. No, not saying Sam would do this because I'm absolutely certain Sam is smart enough to know that if he finds a vulnerability doing this, the first thing he does is email
[email protected] and not
[email protected] or legal or support trying to scare people. That's a good idea. I'm always the. how lot of me and my biggest pet peeve is when people claim to be experienced security researchers and their first email for something like that goes to privacy or legal or randomizing email addresses. It's like, "No, you're not an experienced researcher or anything." Because any researcher knows logically the first thing you do if you find a vulnerability. Check if they have a program on a platform if they don't email security@. "Why am I going to email their legal team to tell them that they're asking for a good advice?" Yeah, exactly. No, it's bad, man. Okay, so I guess that's a good transition though into Bug Bounty. When did you first hear about Bug Bounty and. yeah, let's. 2014 is when I first heard about it. That's when I created my accounts on Acro-1 and Bug Ground, but I didn't do it. So at that time. Do you remember how you heard about it? I want to say it was Twitter. Twitter? Because I was extremely active as an A-N-On. But not in. I didn't do online ops. I wasn't did all seeing my website. I still consider myself an A-N-On, but I disagree with the route most of them went. I don't think breaking into. If your target is P-Fizer, for example, I don't think you hurt P-Fizer by breaking in and stealing their customer data and releasing that. Right. You hurt the end user exactly and Anon on this. That's my biggest complaint about A-N-On's. Is that they accept the lateral damage. The lateral damage is a lot different than what I would do. But. So you heard about Bug Bounty via Twitter. That's Twitter. And then. Made my accounts. It made my accounts, but it wasn't worth it. Because it had only been at that point a couple of years since it told me it was life in prison. I got caught hacking again. Never heard of Bug Groud, never heard of hacker one. And it seemed too good to be true. And then. Late 2015, I started seeing a post on Twitter that were Bug Bounty Raidups. Like such and such getting paid X amount of money for vulnerability they found in everything. And then finally, early 2016 and like January, February, I was like, "Arch, you know what? I'm bored as hell at work. Let's give it a shot." I opened up hacker one, tried to register. And it said that an account already exists with my email. I didn't even remember signing up for the account. So I recovered the email or recovered the account logged into it and went to the little directory of the programs. And I saw Yahoo. So I was like. It said, "Hmm. Let's give it a shot." I knew a little bit about Yahoo. And yeah, just started. Gave it a shot. Yahoo gave my first bounty in March 2016, $300. And then my next bounty is after that were for. Hex Pentagon. Wow, dude. And I'm pretty sure I finished first in Hex Pentagon. And. So. Hex Pentagon. They advertised it a bit, gave us 30 days from all of May of 2016 to hack on the fuse house and stuff like that. It was supposed to be like a limited event and all kinds. They would invite us to it. We assumed that if you got an invite to the program, that they had already done, whatever they needed to, to clear you. Found out after it ran and after they owed me like 30 grand for vulnerabilities that you had to pass a background check in order to actually collect the bounties. I got pissed. Yeah. I went to Twitter and. Bented my frustration. Oh no. About finding that out. No, I didn't enough working out. One of the people that was running the program, she saw my post and hit me up in a DM. She was like, "I 100% understand your frustration. Give me 24 hours." And 24 hours later, she hit me up and said, "You now pass background checks and you are going to get paid." So now if you do a background check, I'm going to be a passer. Wow. That's kind of crazy. Yeah. Wow. I'm glad you got that redemption opportunity there. Yeah. I was super mad because I spent the whole month because I had just gotten into it. Totally. I just got into it and they weren't letting us hack the US military. Yeah. And from my experience in the 90s and early 2000s, the US government military were some of the easiest to hack into. So I was really looking forward to doing that for bug bounties. It's also one of the reasons I stayed on Sinek for as long as I could. I only did government military targets on them. I left them when their new legal team decided to ban me from legal, from government military targets. Oh, man. You keep getting it, man. That's crazy. Wow. All right, man. Well, how has the bug bounty industry changed since that time? Like, I imagine back then it was very fresh. I mean, do you think things are more difficult now? Obviously there's more mass adoption, but. I don't know that it's more difficult. It's definitely different because there's so many more companies that are doing it. There's a lot more competition, but I'll be honest. 99% of the competition is not actually competition for anybody that has any kind of skill. Right. The vast majority, and I don't mean any disrespect to the people, but the vast majority of people that I see on InfoSek Twitter and X, whatever you want to call it, they're never going to succeed because they, I don't think they have the right type of thinking like anybody can run an exploit. But yeah, I feel like you've got to have a certain
and logical way of thinking to figure out how to break. 'Cause computers do everything logical. They do exactly what they're told based on certain conditions and part of being a hacker who's figuring out how to break that logic of what they're expected to do and just most people aren't. They just can't do it. - Yeah, I think there's something special about it. I've been trying to figure out exactly how to call it, but the only thing I've landed on is like, reasonable attack vector ideation. Like being able to look at a system, look at the security boundaries, look at the implementation and just have enough understanding about computers in general and about the logic of that app to come up with a reasonably feasible attack vector. - Yeah, but the problem is, the problem is a lot of times are successful attacks, there's no reasonable reason. They should have succeeded. Like there's absolutely no reason that this should have worked, but it does. But that's just one of those things that even when we know something's not going to work, we still do it anyway 'cause we have to see it. At least for me personally, I have to see it for myself. And it doesn't make sense while a lot of it works, but I think there's more competition. There are tons of really great accrues out there, but the only thing is, like there's so many programs out there that you can realistically find a couple of programs that you want to focus on yourself and make decent money if you really wanted to. But I will probably get to that so I'll leave. - Yeah, well, I wanted to swing back around to SSRF and what attracted you to SSRF is vulnerability originally because I think at the time, SSRF was not as popular of vulnerability early on in the Bug Bounty Arena, in the offensive security world. And then you kind of went down this path and really raked Yahoo over the calls with the hat. - Yeah, the main reason was because I have a lot of fun beating denialist, like whatever you want to call it. SSRF is one of those vulnerability classes that historically the main way they try to fix it is to blacklist whatever it is that-- - Okay, sure. - That we're working on. - Yeah, exactly. And there's just so many different ways that you can bypass it, that it's just fun and it's a challenge. It was back then. It's not so much anymore because at this point, I've got a couple of dozen different ways that I encode IP addresses. And if I find something, I'll script something to run through and test every one of my variations and things like that. And if it doesn't work, then I'll move on. Well, depending on the target, if it's a target that's a big enough target and everything, then I might pass it off to AI at that point and say, "Hey, I've tried all of this, see if you can come up with absolutely anything that should not work that ends up working." - Yeah. - But my main reason for us to Sarah was because I was beating the blacklist. It's just fun. - Do you have feels freaking good, man? It feels good to get around the list like that. - Yeah, it's like, there's no other way to describe it than it's similar to a high 'cause you get that dopamine rush and it's just like-- - Yeah. - You know other people looked at that exact same endpoint too. And when you are like, none of them were able to figure this out and you were, which just one of those things is just that much better. - And that the programmers sat there and said, "Oh, I'll get 'em with this." - Right. - "Redge Axe, you know?" And then they don't escape a dot or something, you know? - Yeah, but they forget the little question or the thing's-- - Exactly. - Yeah, it's crazy, man. It's crazy. It's a lot of fun. Sweet dude. So you mentioned AI. How are you using AI nowadays in your workflow? I know you're just, well, adding a little context. You're just coming back from a little bit of a bug bounty hiatus and I know you're focusing more on fuzzing now. How do you see AI in your workflow? - I'm using it a lot for the exploit development aspects of it. - Yeah. - Imagine that's really helpful. - It is extremely helpful. I am having it do most of the exploit development, but I've got some restrictions on my AI. They're never allowed to delete files. Every couple of minutes, they have to do a brain dump into a file so that way I can read through it 'cause I don't want them doing things 100% for me. I want to learn how to do it. So I've got them doing little brain dumps explaining why they did something, what they've tried that's failed. Like I don't want just the information I won't succeed it. I need to know what you tried that failed as well so that I can learn for the next time that I'm doing this and everything. I've started to use it a little bit when it comes to writing my harnesses for the fuzzing. Trying to, I've been targeting Chrome. It's no secret that I've been targeting Chrome. I've, before I would go in and find the functions that I wanted to fuzz and I would just write a very, very basic fuzz that would just call the API for that function and fuzz that but now I've written into several instances where I found a vulnerability but it wasn't reachable in current. So I've got AI now where it builds my harness to essentially mimic the exact same flow it would go through if I were to load it via a webpage. - Okay, so you just gave me a bunch of information that we're not gonna air but so I guess the TLDR of the situation is you are focusing on a sub-technology within Chrome. - Right now, yes, because I'm trying to learn it. I've never done browser hacking before. So I'm trying to learn it like I haven't even started to learn about the IPC, how they're passing things from one sandbox to the next one and all of that kind of stuff and I haven't done almost everything that I've done so far has been within the renderer itself. I do have a separate vulnerability that I actually need your help with 'cause I need you to learn Windows, I think. - I do, I'm running Windows there. - So I need you to test a vulnerability for me. - Thank you. - I'm like 99% sure that I've got to use after free in Chrome. It's only reachable on Windows. I tried installing a Windows VM and-- - No. - Yeah, I did. I couldn't figure out where the start been. - Well, okay, so you're using AI right now to build these harnesses that trigger certain code paths within the Chrome code base. - Yeah, that follows the same path 'cause when it comes to Chrome, it's like they've got all of these kind of protections and validation so that as soon as you open up your website, as soon as it starts to load and everything before the first bit of it's loading, they're running all kinds of checks. Like if there's script tags making sure that the JavaScript is legitimate, if there's image tags making sure there's valid video, I mean, images in there, video tags, valid video, and that kind of thing all through all of that. And figuring out that just because there's a vulnerability behind all of that, the vast majority of them are blocked by the validation that Chrome does before it ever can reach the vulnerable code path. So I've got mindset up so that it actually sends my, what do you call it? - Corpus. - Yeah. - My current test file, it sends it through the harness and the harness is designed to first go through Chrome's validation and then through the next step and then the validation of whatever's in the actual area because if it's gonna fail those, I can't actually exploit it. - Do you have that isolated or are you hooking into Chrome and like loading up HTML files or whatever in Chrome and then? - It depends. In some instances, I slated some instances, I'm just running like a pure C or C++ program that calls the exact same methods that Chrome does in the same order. - I see. - And then I'm sure most people have seen by now the CSS zero day that came out like last week that was exploited in the wild. I'm fuzzing for similar things to that right now where I'm actually doing it within browser as well. One of my AMD machines, I've got 32 Chrome instances that are running and then within them, I wrote some little custom JavaScript things that run in the webpage on each side that's doing all kinds of testing it. It hasn't found anything yet. I'm not even certain that it's going to work, but-- - But we give it a shot. - Yeah, I mean, you don't know if it's gonna work until you try it. So I've got it right. - Nice man. Yeah, that definitely sounds like AI is helpful for all that because it requires a lot of isolation of code within the Chrome code base. It requires-- - And it's a huge code base. It's a huge, freaking ass. And that's something that is helpful is making sure that you're not going to get a job.
making sure you understand the AIs we have access to are good at different things. So like for example, if I want to look at the entire Chrome code base, I'm only going to use Gemini. Gemini with your paid subscriptions and the paid max or whatever, it is that you get like up to two million tokens of context. You need that context to be able to not forget when you're trying to have it trace through hundreds of files. Did you clone down the code base? Are you having it like navigate? Okay. Yes. I've got it all down. I've got probably six different or like six unique checkouts of Chrome. I've got an A Santa Chrome, an M Santa Chrome, a UB Santa Chrome, a normal vanilla Chrome, a debug Chrome and exploit dev Chrome. Oh, I eat. It's heavy, man. That's a lot of code. It's heavy and it's hard as hell to actually build Chrome from source. Oh my gosh. There's so many problems, independencies. So I try and keep absolutely everything in its own folders. So that way, because I mean, when you're fuzzing, if you find a crash and you might need a Santa address sanitizer in order to find it, well, if your libraries and stuff weren't most recently compiled with a sand, you might have compiled them with M Santa memory sanitizer. Instead, you have to go through the entire process of rebuilding it again. So I've got a different-- It takes time to-- Yeah, it takes hours, depending on your system. So I've got a different folder for each different version of it. And then I've got-- When I go through the process initially on a new target, I go through everything that it takes to build it for every version that I need. And then I build shell scripts that will essentially be able to-- because when you're fuzzing, you've got to-- You change things a lot. Like every time I find a vulnerability, I patch it locally. I don't want to sit there and spend the next two days discovering the exact same vulnerability over and over. So I patch it locally. And then continue fuzzing. And then because it lets me get farther into the code base. Because everybody else that's fuzzing it, if you're not patching it, you're going to keep getting stuck at that exact same spot. You're going to have no way to know if there's more vulnerability. And with the patch reward program, you submit that patch, you get an additional bonus. Exactly. You know that code is getting implemented but not even just that because Google actually has it so that even if I find a vulnerability, for example, in a third party library that Chrome uses, but it's not reachable in Chrome, I can still go to the upstream maintainer. Yeah. Report the vulnerability. Put a patch in for it. After 30 days, if they accept my patch and merge my patch in, after its been merged in for 30 days with no problems or anything like that, you can go file it to Google. Because they've got the concept of open source for what's called. Yeah, the open source of your p thing. Yeah. Anything that you can like you fix that is a material enhancement to the overall security of anything that Google uses, then you can get, I think it's up to like 15 grand. You can get depending on what the bones are and stuff. So yeah, I haven't I haven't looked thoroughly at this VRP very much, but yeah, there's a ton of open source projects that they yeah, look at this. One of them, uh, supply chain compromises can get up to 31k. Yeah. Dang. Yeah. And they like Google's got running. I'm looking at you, man. Lupin go do this. Run depy on this shit. Um, yeah, dude, they've, uh, they've got a lot of stuff trying to care for the ecosystem, I think. Yeah. Um, and then Microsoft is now trying to do the same. Oh, really? Microsoft just made their announcement a couple weeks ago. I guess been a month or so ago now, maybe a little bit more where they're going to start actually paying for third party vulnerabilities and stuff that they had previously because they want to also try and help, uh, increase the security. I've heard, I've heard Microsoft's up in their game. I'm excited to see more from them. I'm going to end up right now. I've been doing Google. My goal is to try and be top three or five for Chrome VRP through through this year. And once I find a couple more bones to at least see myself up there. Crazy, though, man, because some of these guys just drop like, you know, fully, fully built out, you know, straight RCE and just one, you know, but like, and then it gets like 250 K or whatever it's like. Yeah. So the max that mine, the one that I've been working on can get is like 55 because it's within the renderer, but the one that I'm going to have you help verify whether it's actually reachable or not, that one could be more because it's in a, or they call it, uh, high-proved, sandbox process. There we go. So that one can get a little bit more up to like 85. How are you, how are you determining what segment section, what sandbox all of this is in? Are they? Oh, it's in the code. You just know, um, like, uh, there's the GPU sandbox. There's the renderer sandbox. And then there's the actual Chrome process itself. And I've, most of my vulnerability so far, have been in the renderer process. I've got one in the GPU process. Um, actually found it because I was trying to figure out if there was a way to escape the sandbox with the vulnerability that I've been working on. There's not, I need a completely separate vulnerability for it, but I did find what I'm 99% sure is another vulnerability. It can't be used for this kind of chain, but it could be a completely different unique, reportable one. So you've got AI helping you parse the code base, build out these harnesses, build out these shell scripts, sort of helping you get into browser-based hacking. Um, do you, I mean, do you find yourself doing a lot of the hacking via these AI agents nowadays for this stuff? Or are you doing, uh, stuff you're doing manually versus having the AI agents go do it? So I'm not gonna lie. I spend a lot of time having AI agents go do stuff nowadays. Well, they're doing a lot like say I get a new crash. Um, they'll be doing a lot of the RCA for me, like helping me trace through the exact flow of whatever it was they got there because they're so much faster like I can do it. But they can do it in two minutes where it would take me an hour or two. So I naturally will have them do a lot of that. Um, I haven't gotten back into web hacking much yet. I'm trying to. I'm just struggling to get motivated and find a program that I want to actually do. Google's fun, man. Google is fun to hack on it, especially for web. It is like, it's challenging, you know, oh, yeah, it's very hard because they're not using a lot of just straight JSON. You're dealing with a lot of proto JSON. You're dealing with a lot of like, you know, just a raise that don't have any keys. You know, like, you know, let's talk about what kind of Amazon, like, I mean, Amazon, Google GCP and stuff. I've toyed around with going back to Amazon and doing someone. Amazon had a ton of success hacking with Sean and Jonathan. Jonathan. Yeah. For a couple of those AWS events we were doing made a decent amount of money. So I've thought about going back to that. It's just hard to get motivated to want to do that. And I'm having a lot more fun doing the fuzzing right now. And if you're having fun with it, you know, that's that's the main game for us at this point, I think, right? Yeah. Because it's like, I, I don't want to say web stuff is too easy, but it's not as much of a challenge. So my goal, like, I want to attend home one time. Do you want to compete? I really want to do that. That's why I am main, the main reason that I'm looking at fuzzing and buying more exploitation and stuff is because I want to do it just one time, just to prove to myself that I can do it. Yeah. So, dude, we should, we should, we should do it, man. I've talked about it on the plot a couple of times and I've had a couple guys from PonoOn. But, you know, obviously the binary exploitation piece, which is a lot of PonoOn is not a forte for me, but I have done a little IoT stuff and there is a good amount of IoT. And web stuff is actually really applicable to some of the IoT systems it is for sure because a lot of times it's going to be your front door that you're going through. Yeah. Yeah. Yeah. So some of the guys I was talking to were saying, like, yeah, definitely, like you need to have a good skill set in reverse engineering and binary exploitation. But also, like, if you have a really good web guy, you know, then that would be helpful for a PonoOn team because because definitely there are those exploits out there. The thing is, it's just got to be on nothing to give you our seat, which is like, you know, let's all order. Say, yeah. Yeah. Yeah. They don't, my big problem with it is that it's generally got to be unauthenticated RCE, but also unsan boxed and everything like that. If you want to go and pop chrome for it, you don't get many points if it's RCE and the renderer. He needs
that actual sandbox escape, full system compromise and stuff. - It's tricky, man. - Yeah, my goal is to compete and pound to own at least once. - Yeah. - And I want to get the max bounty one time for good. Well, I want the 250 for a full sandbox escape to our CEO. - That would be sick, dude. That would be super sick. Well, maybe we'll do a Richmond Poon to own team, man. Me, you, Turbo, you know, that would be a fun one. All right, dude. Well, that was quite a run. I have to say, those stories are very unique. And thank you for the part you played in the Bug Bounty ecosystem, man. And for me personally, like, really, I know I keep saying it over and over again, but when I think back to that day and that stupid little lab in VCU, like crazy to think that that was such a jump-script point in my life. - Yeah, and it's, it's like we didn't do nothing, but sit there for what, about an hour, just talking about-- - Looking at about bounty reports, yeah. - Talking about the different types of bounties and bugs and companies and stuff like that. It's crazy how everything kind of evolved from that. It's, uh-- - Yeah. It's nice. It's fun. Yeah. - Dude. - Thanks so much, man. - Move, man. - Thank you. - And that's a wrap on this episode of Critical Thinking. Thanks so much for watching to the end, y'all. If you want more Critical Thinking content, uh, or if you want to support the show, head over to ctbb.shows/discord. You can hop in the community. There's lots of great high-level hacking discussion happening there. On top of the masterclasses, hackalongs, exclusive content, and a full-time hunter's guild if you're a full-time hunter. It's a great time to trust me. All right, I'll see you there. [BLANK_AUDIO]