Hackers claim it only took a 10-minute phone call to shut down MGM Resorts
engadget.com
engadget.com
Then they flat out refused to put parking charges onto my tab without ID. Yet if I had gone back to the room and merely pulled a single drink out of the minibar, I could have run up a $60 charge no problem!
Please tell me that was a mini bottle of aged whisky and not Diet Coke.
The concept isn’t evil in itself, it’s just that the pricing applied to it is predatory.
The warning is there for your convenience more than anything else and is often out of an abundance of caution. I’ve seen similar ones where you can pick up and put it back within a certain time and not be charged - I’m pretty sure all these machines have a grace period to avoid spurious charges in case it gets bumped/etc, so it is safe to pick up items and put them back within a reasonable timeframe.
In practice feel free to pick up (and even replace items, if it’s literally the same and they won’t be able to tell) and just play dumb and contest the charges at the front desk, they’ll have to waive them if they can’t decisively prove you actually took any items.
My solution was to go to the convenience store (still located in the casino) which was expensive (a guy in front of me nearly had a meltdown at paying $15 for a can of lager) but at least had no "restocking fees." A Target with more sensible prices is about a 10 minute walk from MGM Grand, however, in case anyone here ever winds up there.
So, basically, drunk people and children.
Yet if I had gone back to the room and merely pulled a single drink out of the minibar, I could have run up a $60 charge no problem!
Right, but pulling a drink out of the minibar requires a room key which, in turn you couldn't get without ID.So both cases depend on ID.
Is it the kind of minibar connected to the phone line, where every item presses down a dedicated knob thus touching the item releases the signal to the system? The only time I saw something like this was in a hotel in US of A and viciousness of it infuriated me.
Before sensors, people would grab a $5 can of soda at 2am, drink it, swing by the convenience store in the morning and get a 12-pack for $6, and put a single can back in the minibar. On paper it's a 1:1 swap, so it's not really stealing, but hotels wanted their profits, so they invested in the sensors.
I'm sure other hotels just check what gets restocked and charge you accordingly, but hotels that really want to juice you will get every dollar they can.
[0] https://www.reviewjournal.com/local/local-las-vegas/minibars...
It's not stealing at all.
I always stuff my own drinks into the minibar fridge between the hotel supplied ones, something like this would really piss me off.
If virtual it can be automatically as part of the guest check in flow.
That's a lot of hostile innovation no one needs neither asked for. Almost like the infamous US prison technology.
Turn your cost center into profit center! (by charging your guests $5 for touching a Snickers bar)
On checkout, I had a huge bill for a bunch of things in the minibar. I guess I jostled the items enough that it tripped whatever switches or sensors they used. I complained to the front desk, and luckily they refunded all of it.
Also, who drives without ID?
The car park machine, "popped to the desk," driving or wandering Las Vegas without ID, the identity procedure... I'm comfortable with my assessment that there is something not entirely correct with the story. You are welcome to disagree.
Nothing about this sounds too far fetched to me, based on my experiences at other hotels/resorts. Maybe this only happens to you if you have a sketchy appearance or due to other biases; if you are clean cut and of a non-prejudiced race, maybe you won’t run into this crap.
> maybe you won’t run into this crap
What "crap"? He didn't have ID. The employees should simply hand out keys on the honor system?
What crap? Being treated with suspicion just for the way you look. “Have ID, don’t care, maybe it’s fake”. :sigh:
* We return late to the MGM self park one night. I was told I could "use my key" to get in/out. Stupidly I put my key into the credit card slot (rather than scan the barcode, as you're meant to) and it eats it.
* We return to the hotel room using my wife's key because we're tired.
* The next morning we decide to use the Grand's pool. I leave everything except the remaining room key and my phone in the safe because we're going to the pool and I would not leave anything poolside that I couldn't tolerate being stolen.
* On making it to the lobby, my wife decides she wants Starbucks. I decide to spend my time attempting to get my key replaced. I therefore turn up to the desk with my remaining room key, my phone, but no driver's license or passport. In Europe this would literally be zero problem, hence my attempt.
* I was able to use a combination of answering numerous questions about my room, my identity, and how much I'd spent on the room to convince them to give me a second key.
* I later returned to the desk with my ID to add parking to my folio.
Sometimes workers get tired of dealing with persistent people who absolutely insist that they are correct (which in this case they were), and realize that they don't get paid analyst wages, they get paid front desk wages, and they say "Okay, this looks right to me. Here you go."
No I don't mean all of that. He wrote "In Europe this would literally be zero problem, hence my attempt." I'm curious, if you can get a hotel room key in Europe without ID, how does that work? Does the phone work as proof?
In the UK, at least, it's unusual to show a driver's license for anything (except buying alcohol if you look young) because many drivers don't carry them, whereas in the US I had to show it every time I even checked into a hotel and even occasionally when buying things with a credit card.
Helpdesk: "Sure!"
Hacker: "Thanks! What mail server should I use again? And what's the VPN IP? I need to RDP to fix some kind of outage."
Helpdesk: "[redacted]"
Hacker: "Thanks so much! Have a nice day!"
So many good stories. RIP.
None of us were brave enough to try it.
You want invisible? Be female, 40+, short but otherwise average build, any skin colour but white, black hair, generic cleaning staff outfit, and one of those carts with mops and buckets. Now you're invisible (racist, classist, and misogynistic biases exist, might as well use them).
(As a 2m tall person I can't blend in anywhere.)
I didn't ask whether they actually worked for that company, or the outfit was part of their pen-testing toolkit.
They spooled up a truckload of copper, gathered their cones, and drove off. They were seen by hundreds of witnesses in the middle of the day, but nobody suspected anything.
At least over the population we test, your chances of getting in jail are big enough that you shouldn't try it. But you certainly can collect anecdotal evidence that it works.
I have to admit that I actually used that on occasion.
9/11 changed that fact.
In theory, basically all of these required an exhibitor pass to get in to. Sometimes I’d have one, sometimes it would be with someone already at the show who I was supposed to call to come out and let me in, etc.
I used to make a game out of getting in without using or having a pass.
One of the easiest strategies was just to have a slightly large or unwieldy looking box and find a well enough travelled side door. In the context of a trade show or something, somebody hauling stuff in through a side door was 100% expected. Nobody would blink an eye at holding the door for you. Often there’d be a security person inside but if you just walked confidently and like you knew where you were going they wouldn’t chase you down just to ask you to put down all your stuff and dig your pass out.
Same strategy has worked to drive right past vehicle barriers. They’ll tell you can’t drive in there. Tell them you’re there for <namedsponsor> and you’re not carrying all these boxes in the back seat from a mile away. Quick radio call and “drive slow through the crowd please, be really careful”. Wasn’t even there to deliver anything, that area just has shit all for parking.
After showing up in a group of ten people carrying <namedsponsor> swag and gear, wearing <namedsponsor> clothing, in a <namedsponsor> wrapped vehicle and having every staff member have to present a pass and submit to a glance through of everything they were bringing in… one of my main contacts was always shocked every time I’d do this.
Make way more money now doing way more interesting work, but that role definitely had some fun parts.
I Broke Into The International Security Convention https://www.youtube.com/watch?v=qM3imMiERdU
I Broke Into The U.S. Security Convention https://www.youtube.com/watch?v=NmgLwxK8TvA
The best time was just as camera phones were being adopted. I had a paying friend already on site, and got him to send me a picture of the wristband. Sky blue, yellow toggle.
I head to a haberdashers, grab some ribbon and a few appropriately sized beads and laugh my way in through the front gate.
No way that'd work these days, but my favourite hack to date.
Good times.
Its amazing where you can get with some "proper dress" and confidence. Lots of cases of using a hivis vest and lanyard to get into free concerts, gaining rooftop access, etc.
He called the branch manager saying he was from NationsBank IT and was going to do a pre-merger inspection. He showed up, asked for the root passwords of the boxes in the branch, logged in, left a MOTD message, then left.
Needless to say they beefed up the training on that once the merger closed.
I had (still have) serious doubts that they have the expertise and discipline (as well as all the vendor systems it relies on) but I will have to give them credit if true and they can get back to 100% without paying a ransom.
At the same time, the source of this article may be completely fabricating all his/her claims, there's obviously no confirmation of any of it at this point.
“THESE are true stories from the dark side of the internet… I’m Jachary Sider.”
Will be very curious to see what systems were affected