Darket Diaries
Darket Diaries

42: Mini-Stories: Vol 2

Three stories in one episode. Listen in on one of Dave Kennedy's penetration tests he conducted where he got caught trying to gain entry into a datacenter. Listen to a network security engineer talk about the unexpected visitor found in his network and what he did about it. And listen to Dan Te

Featured Speakers

Jack Rhysider Host

Topics Discussed

Episode Summary

Executive Summary: This mini-stories episode of Darknet Diaries follows three real-world security stories: Jack’s Raspberry Pi file-sharing site was quietly compromised but contained, Dave Kennedy’s retail and headquarters penetration tests exposed easy physical and social-engineering failures, and Clay’s university/client incident showed how an SQL injection escalated to root and was remediated through rapid incident response and forensics. A later story describes an insider-threat case where a toxic employee abused his head-of-security access to surveil staff and misuse company resources.

Main Topics: Jack’s Raspberry Pi honeypot-style compromise (Priority: 5/5): Jack recounts how a low-stakes file-sharing site he left running for years was eventually exploited. Because it was isolated, the breach caused no lateral movement and became a learning exercise in observing attacker behavior. Retail penetration testing and physical security bypass (Priority: 5/5): Dave Kennedy describes testing a large retail chain by blending in, stealing merchandise, using a tap device to access network infrastructure, and exploiting weak store and headquarters access controls. Social engineering and RFID badge cloning at corporate headquarters (Priority: 5/5): The team gains access to the HQ and later the data center by piggybacking, impersonation, badge cloning, and simple phone/social tactics, demonstrating how physical controls can fail even when technical defenses exist. Incident response to a root-level server compromise (Priority: 5/5): Clay discovers an unauthorized root shell on a Linux server, traces the likely SQL injection entry point, cracks the root password, kills the session, hardens access, preserves evidence, and rolls the system back. Insider threat and abusive surveillance by a promoted security lead (Priority: 4/5): Vis’s story shows a company trying to force out a problematic employee by promoting him to head of security, only to discover he was using that role to surveil staff, move infrastructure, and spend heavily on a corporate card. Security culture: fixing systems, not just ‘winning’ tests (Priority: 4/5): Across all stories, the show emphasizes that security work should improve defenses, document findings, and teach clients how to remediate rather than merely demonstrate compromise.

Key Arguments: Isolation and segmentation can turn a compromise into a controlled learning opportunity; Jack’s Pi was breached but could not be used to pivot elsewhere. Physical security is often easier to defeat than assumed; visible professional behavior, piggybacking, and badge cloning can bypass weak access controls. Social engineering remains highly effective when attackers know org structure, jargon, and trust relationships. Incident response should prioritize identifying the entry point, preserving evidence, and ensuring eradication before restoring service. Root access on a server is a critical escalation that can require password recovery, session termination, access restriction, and full rebuild or rollback. Toxic insiders with broad privileges can cause more damage than outside attackers, especially when management avoids direct action. Security consultants should provide actionable remediation guidance and organizational learning, not just dramatic breach stories.

Data Points: Raspberry Pi website hosting duration: about 1 week per upload - Jack’s file-sharing site automatically deleted files after roughly a week. TrustedSec / Binary Defense staff size: about 162 employees - Dave mentions current size of the companies he founded. Dave Kennedy’s age at CSO role: 26 or 27 - He became chief security officer at Diebold at a very young age. Headquarters break-in timing: 2 days later - After being caught once, Dave’s team returned and re-entered the HQ. Data center access method: RFID badge cloning - The team cloned a badge to gain access to the data center. Clay’s password recovery tool: John the Ripper - He used it to crack the root password from /etc/shadow. Cracked root password: Mark2002 - Clay recovered the root password during the incident response. Time root access was present: a few days - Clay determined the attacker had likely been on the server for only a few days. Corporate credit card abuse: almost 200 grand a year - The insider-threat subject charged massive expenses to a corporate Amex. Estimated proportion of attacks from insiders: 60% - Vis references insider-originated threats as a large share of attacks. Ransomware prevalence: 85% of organizations - Referenced in the SpyCloud sponsor segment. Stolen identity records circulating: 63.8 billion - Referenced in the SpyCloud sponsor segment. Corporate users infected by infostealer malware: nearly half - Referenced in the SpyCloud sponsor segment. Organizations able to detect historical identity exposure: 38% - Referenced in the SpyCloud sponsor segment.

Pivotal Quotes: "A hacker was in my house." — Jack: Jack describes discovering the Raspberry Pi compromise and realizing someone had exploited his home-hosted server. "I immediately start thinking to myself, oh crap, what we do have a compromise. It is a root-level compromise." — Clay: Clay realizes the seriousness of finding an unauthorized root shell on the server. "We promoted him to the head of security." — Narrator / Vis story: The company’s misguided attempt to make a problem employee quit by giving him more authority.

Implications: Physical, social, and technical controls all fail when organizations assume good intentions or skip basics. Segmentation, monitoring, evidence preservation, and decisive HR/security action are essential to contain breaches and insider abuse.

🔓 Sign Up for Unlimited Episode Search

About Darket Diaries

Explore true stories of the dark side of the Internet with host Jack Rhysider as he takes you on a journey through the chilling world of hacking, data breaches, and cyber crime.

View all episodes from Darket Diaries