Darket Diaries
Darket Diaries

149: Mini-Stories: Vol 3

In this episode we hear EvilMog (https://x.com/Evil_Mog) tell us a story about when he had to troubleshoot networks in Afghanistan. We also get Joe (http://x.com/gonzosec) to tell us a penetration test story. Sponsors Support for this show comes from Varonis. Do you wonder what your company’s ransom

Featured Speakers

Jack Rhysider HostEvil Mog Guest

Topics Discussed

Episode Summary

Executive Summary: The episode contrasts legendary confidence scams by Victor Lustig with two real-world cybersecurity stories: Evil Mog’s wartime communications work in Afghanistan and Joe Sarkisian’s penetration test that uncovered both a hidden workplace camera and a network outage caused by overly aggressive scanning. Across both stories, the show emphasizes technical skill, communication, and the human impact of security work.

Main Topics: Victor Lustig’s legendary scams (Priority: 5/5): A retelling of Victor Lustig’s early-1900s cons, including fooling a bank into a favorable deal, extorting them into dropping charges, and the famous Eiffel Tower scrap-metal scam in Paris. Privacy and deletion services (Priority: 2/5): A sponsor segment for DeleteMe highlights the real-world risks of exposed personal data and the value of proactive privacy management. Evil Mog’s path into tech and aviation (Priority: 4/5): Evil Mog explains how glider flying, military cadet programs, and computer training in the Canadian military shaped his early career. Afghanistan communications support during war (Priority: 5/5): Evil Mog describes deploying as a contractor in Afghanistan to maintain morale, voice, and internet services so soldiers could contact family from forward bases. Life-saving video call for a traumatized soldier (Priority: 5/5): He coordinated a remote video call between a soldier in Kandahar and his wife in a Toronto hospital during childbirth, helping stabilize the soldier after an IED incident. Penetration testing methods and tools (Priority: 4/5): Joe Sarkisian explains assumed-breach testing, using Responder to capture hashes, Hashcat for cracking, Nmap for discovery, and how these techniques are used to assess risk. Operational mistakes and human judgment in security work (Priority: 5/5): Joe recounts finding an inappropriate hidden camera and another incident where a junior tester’s Masscan flood disrupted a client’s network, showing why restraint and communication matter.

Key Arguments: Skilled scammers succeed by exploiting trust, timing, and social pressure more than technical tricks alone. Privacy and personal data exposure can create real-world harm, so proactive removal services are valuable. In hostile environments, maintaining communication can be as important as combat support because it sustains morale and mental health. A timely, compassionate intervention can meaningfully affect a person in crisis and may even save a life. Penetration testing is not just about tools; judgment, communication, and knowing when to stop are essential. Aggressive scanning on a live network can cause serious disruption, so testers must calibrate their techniques to the environment. Security consultants may discover issues beyond pure IT flaws, and handling them requires careful escalation and professionalism.

Data Points: Liberty bonds scam amount: $32,000 - Victor Lustig brought in Liberty Bonds to a bank and manipulated the deal. Bank payoff: $1,000 - The bank allegedly paid Lustig to keep the Liberty Bonds scam quiet and drop charges. Eiffel Tower construction year: 1887 - The transcript says the Eiffel Tower was built for the 1887 World’s Fair. Eiffel Tower scam year: 1925 - Lustig exploited the tower’s repair needs in 1925. DeleteMe discount: 20% off - Sponsor offer for listeners using promo code DD20. SpyCloud exposure figure: 63.8 billion - Sponsor segment cites distinct identity records circulating on the dark web. Corporate users infected: nearly half - SpyCloud report claim about infostealer malware exposure. Organizations able to detect historical exposures: 38% - SpyCloud report claim about detection capability. War zone deployment year: 2008 - Evil Mog describes working in Regional Command South in Afghanistan in 2008. Bandwidth available: 6 megabits for 1,000 people - He says this was the limited bandwidth available for morale, voice, and internet services. Junior tester experience: 4 to 6 months - Joe’s junior pen tester had only a few months on the job. Security incident impact: 5 to 10 minutes - A Masscan flood caused the client network to slow or go down for this period. Pen test success rate on full network compromise: 95% - Joe estimates they can fully own client networks year over year with high frequency. Password cracking success: 50% to 60% - He estimates cracking a significant portion of AD hashes within about four hours.

Pivotal Quotes: "I think by giving him that level of support immediately, I think I changed the guy’s life way for the better." — Evil Mog: Reflecting on the impact of arranging a video call between a traumatized soldier and his wife during childbirth. "What are you doing to our network?" — Client point of contact: The bank client confronts the junior pen tester after Masscan traffic disrupts the network. "I found under-the-desk camera footage of, and then he cuts me off completely. And says, stop right there. I’m calling HR." — Joe Sarkisian: Joe reports discovering inappropriate hidden camera footage during a pen test.

Implications: The episode shows that security work blends technical depth with ethics, empathy, and communication. Tools can expose risk, but judgment determines whether the outcome is helpful, harmful, or life-changing.

🔓 Sign Up for Unlimited Episode Search

About Darket Diaries

Explore true stories of the dark side of the Internet with host Jack Rhysider as he takes you on a journey through the chilling world of hacking, data breaches, and cyber crime.

View all episodes from Darket Diaries