160: Greg
Episode
97 min
Read time
2 min
Topics
Fundraising & VC, Software Development, Philosophy & Wisdom
AI-Generated Summary
Key Takeaways
- ✓Early vulnerability discovery: Manual fuzzing involves opening files in hex editors, modifying values outside normal parameters (like changing font size from 1638 to 9999), then testing in debuggers like Ollie to identify crashes that enable arbitrary code execution through memory manipulation and pointer control.
- ✓Layer two network attacks: ARP poisoning, DHCP spoofing, and man-in-the-middle attacks remain effective penetration testing methods decades later. These techniques capture plain-text credentials during login downgrades from HTTPS to HTTP, providing initial access to employee accounts containing building codes, badge IDs, and onboarding documentation.
- ✓Physical security bypass methodology: Clone RFID badges using Proxmark devices placed behind legitimate readers, map camera locations via Bluetooth signal strength measurements, exploit default passwords in legacy Access camera systems (firmware from 2005), then manipulate brightness/contrast values to 255 or zero programmatically to create blackout effects during infiltration.
- ✓Social engineering through observation: Walking building perimeters during tours reveals critical intelligence: balcony access points near trees, server room locations relative to entry points, and high-value assets like art collections. Combining this reconnaissance with stolen credentials and cloned badges enables after-hours access without triggering human security responses.
- ✓Microsoft Office zero-day hunting: Attach debuggers to applications, modify document files at binary level in hex editors, then test for crashes with controlled data pointers. However, verify exploits work without debuggers attached, as Microsoft implemented debug-only code paths specifically to catch security researchers using this exact methodology.
What It Covers
Greg Glenerys shares his journey from teenage hacker arrested at 14 for creating grade-changing malware to professional penetration tester, including discovering zero-day vulnerabilities in Microsoft Office 2007 and executing elaborate physical security breaches at major tech companies and venture capital firms.
Key Questions Answered
- •Early vulnerability discovery: Manual fuzzing involves opening files in hex editors, modifying values outside normal parameters (like changing font size from 1638 to 9999), then testing in debuggers like Ollie to identify crashes that enable arbitrary code execution through memory manipulation and pointer control.
- •Layer two network attacks: ARP poisoning, DHCP spoofing, and man-in-the-middle attacks remain effective penetration testing methods decades later. These techniques capture plain-text credentials during login downgrades from HTTPS to HTTP, providing initial access to employee accounts containing building codes, badge IDs, and onboarding documentation.
- •Physical security bypass methodology: Clone RFID badges using Proxmark devices placed behind legitimate readers, map camera locations via Bluetooth signal strength measurements, exploit default passwords in legacy Access camera systems (firmware from 2005), then manipulate brightness/contrast values to 255 or zero programmatically to create blackout effects during infiltration.
- •Social engineering through observation: Walking building perimeters during tours reveals critical intelligence: balcony access points near trees, server room locations relative to entry points, and high-value assets like art collections. Combining this reconnaissance with stolen credentials and cloned badges enables after-hours access without triggering human security responses.
- •Microsoft Office zero-day hunting: Attach debuggers to applications, modify document files at binary level in hex editors, then test for crashes with controlled data pointers. However, verify exploits work without debuggers attached, as Microsoft implemented debug-only code paths specifically to catch security researchers using this exact methodology.
Notable Moment
After three days of continuous work with his entire team sleeping under desks to find a vulnerability and save the company's reputation, Greg discovered a legacy integer overflow in Microsoft Visio that bypassed SafeInt protections, forcing a Microsoft developer to return from vacation to address the critical security flaw.
You just read a 3-minute summary of a 94-minute episode.
Get Darknet Diaries summarized like this every Monday — plus up to 2 more podcasts, free.
Pick Your Podcasts — FreeKeep Reading
More from Darknet Diaries
175: Bayrob
Jun 2 · 96 min
The James Altucher Show
From the Archive: Ramit Sethi on Building a Rich Life, Dream Jobs & Online Businesses
Feb 14
More from Darknet Diaries
174: Pacific Rim
May 5 · 90 min
BiggerPockets Money Podcast
The New FIRE? Why Time Freedom Beats Early Retirement
Feb 13
More from Darknet Diaries
We summarize every new episode. Want them in your inbox?
Similar Episodes
Related episodes from other podcasts
The James Altucher Show
Feb 14
From the Archive: Ramit Sethi on Building a Rich Life, Dream Jobs & Online Businesses
BiggerPockets Money Podcast
Feb 13
The New FIRE? Why Time Freedom Beats Early Retirement
The Peter Attia Drive
Nov 24
The impact of gratitude, serving others, embracing mortality, and living intentionally | Walter Green (#288 rebroadcast)
We Study Billionaires
Apr 26
TIP810: Berkshire Hathaway 2026 Valuation w/ Chris Bloomstran
The School of Greatness
Apr 15
Why Your Past Doesn't Determine Your Future | Dan Martell
Explore Related Topics
This podcast is featured in Best Tech Podcasts (2026) — ranked and reviewed with AI summaries.
Read this week's Software Engineering Podcast Insights — cross-podcast analysis updated weekly.
You're clearly into Darknet Diaries.
Every Monday, we deliver AI summaries of the latest episodes from Darknet Diaries and 192+ other podcasts. Free for up to 3 shows.
Start My Monday DigestNo credit card · Unsubscribe anytime