Sounds like your friend is breaking the law. I suggest you don't follow his lead - accessing computer systems without appropriate authorisation is illegal, and we wont tolerate discussion of illegal activities here, so Im asking everyone to keep this in mind when responding.
If you want to know whether what your friend says about it being likely that you can get caught doing this type of thing is true, my answer is Yes. He is right about that. Especially if you are an amateur.
Once you get enough experience in the area of penetration testing you will understand that capturing information from a compromised server is not really that complicated. However given the context of this thread, and given how hard it is to tell someone without the proper background knowledge "How to Hack" I am obviously not going to go into detail about it here.
If you want to learn about the subject that's good, there's plenty of information here and on the Net for this. Make sure you learn on your own test systems though, and don't go breaking into other peoples systems without permission.