Episode Summary
Executive Summary: The transcript follows Greg (Laughing Mantis) and his path from a poor, computer-obsessed goth kid to a noted hacker, malware writer, and red teamer. It blends childhood stories, a notorious school macrovirus incident, early vulnerability research at eEye, and later penetration tests involving physical security, Wi‑Fi compromise, and dramatic data exfiltration. The recurring theme is curiosity, persistence, and how hacker skills evolved into professional security work.
Main Topics: High school typing-class mishap and graduation scare (Priority: 4/5): A lighthearted family anecdote about Greg repeatedly arriving late to typing class, being threatened with non-graduation, and being saved by an improvised credit transfer from another school. Early malware writing and school arrest (Priority: 5/5): Greg describes writing macro malware in middle school/high school, changing grades/attendance in Excel, triggering crashes, and getting arrested as a minor before the case was dropped. Goth identity, instability, and resilience (Priority: 3/5): The conversation explores Greg’s goth/industrial identity, expulsion from home, life in a group home, and how outsider identity became part of his survival and self-concept. Transition from hacker curiosity to professional security (Priority: 5/5): Greg recounts becoming a musician, then a software developer, then being hired by eEye to find zero-days, where his hacking instincts were redirected into security research. Microsoft Office 2007 zero-day hunt (Priority: 5/5): A major storyline centers on a failed initial report, intense all-hands fuzzing of Office, and eventually finding a real vulnerability in Visio that saved the team’s reputation. Red team and physical security operations (Priority: 5/5): Greg shares multiple penetration tests involving network bridging, man-in-the-middle credential theft, badge cloning, camera tampering, booting into systems, and exfiltrating data via hidden hard drives. Corporate espionage and insider-threat lore (Priority: 2/5): The episode includes a speculative story about a plant inside eEye/Microsoft and other anecdotal intelligence-gathering tales, emphasizing the murky history of zero-day markets and corporate spying.
Key Arguments: Hacking began as curiosity and experimentation, not malice; Greg repeatedly frames his early work as learning how systems behave when pushed outside intended use. Professional security work was, at the time, driven more by honor, reputation, and discovery than by formal bug bounty compensation. Security failures often come from overlooked layers: attendance rules, physical access, default passwords, flat networks, and legacy devices can be as exploitable as software bugs. Red team success depends on persistence and creativity; many wins came from patiently combining small footholds rather than exploiting a single obvious flaw. Culture and identity matter: being an outsider (in Greg’s case, goth/industrial) shaped both his self-image and how others perceived him in security environments. The transcript argues that corporate and state-level espionage around vulnerabilities is plausible and likely underreported, even if specific stories are hard to verify.
Data Points: Age at arrest: 14 - Greg says he was arrested as a minor for a school computer crime in Arizona. Time in group home: Age 14 to 18 - After being arrested and kicked out, he lived in a government group home through high school. School attendance window: 9 days - He says it took nine days to build the Excel macrovirus that manipulated grades and attendance. Microsoft Office version: Office 2007 - The eEye team focused on finding a vulnerability shortly after Office 2007 released. Fuzzing campaign duration: About 3 days - The team worked around the clock for roughly three days before finding the real Office vulnerability. Credit earned via transferred class: 1/2 credit - The typing-class graduation issue was resolved by finding an extra half-credit PE class. Hard drives purchased: Over 80 - During the DNA exfiltration engagement, Greg bought more than 80 external hard drives to hide data inside a printer. Office vulnerability type: Visio zero-day / integer overflow-related legacy pointer issue - The final successful finding was in a different Office component than originally assumed. Duration at eEye before finding a real issue: First major success after initial false alarm and intense retry - He first reported a debuggable-only false positive, then found a real vulnerability under pressure. Tour count / recurring work: 4 years - After a successful VC red team, Greg became a recurring red teamer for four years.
Pivotal Quotes: "I don't want to be in this class. I don't want to be in this school." — Greg: Explaining his attitude as a high school student who was already mentally done with school. "I was in school for nine days." — Greg: Describing how quickly he created the Excel macrovirus that changed grades/attendance and led to his arrest. "That was the only people I targeted." — Greg: Explaining that his early malware ideology focused on targeting pedophiles, which he framed as morally defensive rather than random harm.
Implications: The episode shows how hacker talent can emerge from curiosity, then be redirected into security, but also how thin the line is between research, intrusion, and crime. It highlights the importance of layered defense, physical security, and ethical guardrails.
About Darket Diaries
Explore true stories of the dark side of the Internet with host Jack Rhysider as he takes you on a journey through the chilling world of hacking, data breaches, and cyber crime.