This Blog has Moved!

This blog is moving to


Thank you for visiting! Content will remain here for archival purposes.
Showing posts with label Th3j35t3r. Show all posts
Showing posts with label Th3j35t3r. Show all posts

@th3j35t3r Domain Seized by DHS, Arrested at Blackhat?

UPDATE: It appears that jesterscourt.cc is restored. This appears to all have been a hoax on the Jester's part.


It has been brought to light that The Jester's domain, jesterscourt.cc, has been seized by the Department of Homeland Security (DHS).

At the same time, Jester has gone dark on Twitter, with no new posts since July 31. Jester had already made multiple posts showing that he was attending the Blackhat conference in Las Vegas.

Does this mean Jester has been arrested at the Blackhat conference? This would explain the sudden siezure of his domain, and why his Twitter feed has gone dark.

This wouldn't be the first time a hacker was arrested at a Las Vegas conference. In 2001 a Russian hacker was arrested at DEFCON.


It's important to note that Jester has before faked his own "retirement" in the Smedley Manning incident.

Identity of @th3j35t3r Revealed

While this post is not directly related to security...I felt it was worth sharing with others.

Who is th3j35t3r?  That's the million dollar question now isn't it?

For those not familiar th3j35t3r is a cyber-activist known for attacking known terrorist websites as well as Westboro Baptist Church and factions of Anonymous.

There have been many attempts to identify the true identity of th3j35t3r...but according to him none have been correct.

The endless attempts to find th3j35t3r's true identity has become a humorous game for him...to the point that he has set his Twitter background picture to supposedly contain an encrypted version of his full identity.

Anonymous and Steganography - Blindly Distributing Terrorist Messages?

As previously warned multiple times by Th3J35t3r and myself - Anonymous may be unwitting pawns in a much larger chess game.

While their public support of terrorist organizations is being dismissed with "anyone can claim to be Anonymous" their blind distribution of encrypted files containing information from outside entities may not even be known to the inner-most circles of the organization.

What encrypted files? One of the most common means of distributing Anonymous related information is through social media - especially through the distribution of image files.  Little known to many outside the security field is that images can be used to hide information through a process called Steganography.  For those not familiar with the topic here is an excellent whitepaper on how Steganography works as well as how to detect it.  I have started using the StegDetect program from Outguess.org and have found some interesting results.

I recently started analyzing several images being re-posted by the Twitter handle @YourAnonNews.  Out of 51 images analyzed I found two images which returned "positive" as having embedded data, as well as two additional images which generated errors during analysis (possibly obfuscated?).

The first picture with a positive hit was an internet meme of the TV show "Game of Thrones".

Root @th3j35t3r with Google Chrome

Today we're going to have a lesson on password strength and software vulnerabilities.

Disclaimer: Th3J35t3r's site has served targeted malware in the past designed to capture data... especially from members of Anonymous. Perform these steps at your own risk!

There's something interesting afoot on The Jester's website...


In the upper right corner there's a little "Pi" symbol.  If you've ever watched the movie "The Net" you know that interesting secrets are beneath the Pi symbol.






After clicking on the Pi icon you are presented with a UNIX style login prompt.





The login prompt allows you to login with the username "guest" and no password.  However any attempts to login with "root" are met with a password prompt.