- Hate to break some hearts but the Jester did not create this pastebin as so many claim.
- More Updates as 07/21
- Emails show that Hugo sold the domain prvt.org to Xavier in 2009. Old whois on prvt.org shows:
- Domain ID:D87859570-LROR
- Domain Name:PRVT.ORG
- Created On:25-Jun-2002 16:38:43 UTC
- Last Updated On:26-Jun-2011 01:23:02 UTC
- Expiration Date:25-Jun-2012 16:43:58 UTC
- Sponsoring Registrar:GoDaddy.com, Inc. (R91-LROR)
- Status:CLIENT DELETE PROHIBITED
- Status:CLIENT RENEW PROHIBITED
- Status:CLIENT TRANSFER PROHIBITED
- Status:CLIENT UPDATE PROHIBITED
- Status:AUTORENEWPERIOD
- Registrant ID:CR25623846
- Registrant Name:hector monsegur
- Registrant Street1:90 avenue d #f
- Registrant Street2:
- Registrant Street3:
- Registrant City:new york
- Registrant State/Province:NY
- Registrant Postal Code:10009
- Registrant Country:US
- Registrant Phone:+1.9173889070
- Registrant Phone Ext.:
- Registrant FAX:
- Registrant FAX Ext.:
- Registrant Email:xavier@openplans.org
- Admin ID:CR25623848
- Admin Name:hector monsegur
- Admin Street1:90 avenue d #f
- Admin Street2:
- Admin Street3:
- Admin City:new york
- Admin State/Province:NY
- Admin Postal Code:10009
- Admin Country:US
- Admin Phone:+1.9173889070
- Admin Phone Ext.:
- Admin FAX:
- Admin FAX Ext.:
- Admin Email:xavier@openplans.org
- Tech ID:CR25623847
- Tech Name:hector monsegur
- Tech Street1:90 avenue d #f
- Tech Street2:
- Tech Street3:
- Tech City:new york
- Tech State/Province:NY
- Tech Postal Code:10009
- Tech Country:US
- Tech Phone:+1.9173889070
- Tech Phone Ext.:
- Tech FAX:
- Tech FAX Ext.:
- Tech Email:xavier@openplans.org
- Name Server:NS77.DOMAINCONTROL.COM
- Name Server:NS78.DOMAINCONTROL.COM
- Name Server:
- Name Server:
- Name Server:
- Name Server:
- Name Server:
- Name Server:
- Name Server:
- Name Server:
- Name Server:
- Name Server:
- Name Server:
- DNSSEC:Unsigned
- The DNS server are not afraid.org like Xavier requested in the emails though.
- Newer whois information shows that they domain server are afraid.org
- From http://k0s.org/hg/config/file/ae0ffe7c9040/.mutt/aliases
- we get
- author k0s <k0scist@gmail.com>
- date Mon Feb 15 20:42:02 2010 -0500 (17 months ago)
- parents 1e6a394db7ec
- 1 alias design topp-design-discussion@lists.openplans.org
- 2 alias dev opencore-dev@lists.openplans.org
- 3 alias it xavier@openplans.org, ladorval@gmail.com, rmarianski@openplans.org
- 4 alias ops operations-discussion@lists.openplans.org
- 5 alias ra Rob Miller <robm@openplans.org>
- 6 alias rm Rob Marianski <rmarianski@openplans.org>
- 7 alias ui opencore-ui@lists.openplans.org
- 8 alias wfh wfh@lists.openplans.org
- Some new info:
- from http://net-square.com/httprint/signatures.txt
- we find:
- ## 04/04/04
- ## contributed by Xavier Kaotico: sabu-at-mad-dot-scientist-dot-com
- #GoGoGadgetWebserver/0.3
- #9E431BC86ED3C295811C9DC5811C9DC5811C9DC5505FCFE84276E4BB630A04DB
- #0D7645B5811C9DC5811C9DC5CD37187C811C9DC5811C9DC5811C9DC5811C9DC5
- #6ED3C295E2CE69236ED3C295811C9DC5E2CE69272576B7696ED3C2959E431BC8
- #6ED3C2956ED3C2952A200B4C68D17AAE68D17AAE6ED3C2956ED3C295E2CE6923
- #E2CE69236ED3C295811C9DC5E2CE6927E2CE6923
- searching for sabu@mad.scientist.com we find
- http://www.sourcefiles.org/System/Administration/Networking/routekill-0.1b.tar.bz2.shtml
- Xavier Monsegur (monsegur@mad.scientist.com) - NYC Python user - xavier@nycpug.org - hector?
- http://pastebin.com/JDJ45jGG -more great stuff here
- domain scientist.com.
- mad.scientist.com. MX 15 mailin-01.mx.aol.com.
- mad.scientist.com. MX 15 mailin-02.mx.aol.com.
- mad.scientist.com. MX 15 mailin-03.mx.aol.com.
- mad.scientist.com. MX 15 mailin-04.mx.aol.com.
- from http://marc.info/?l=freshmeat-news&m=119041475103440&w=2
- we see that sabu has an acocunt at freshmeat http://freshmeat.net/users/Sabu02/
- Also found http://developer.berlios.de/users/sabu/ when searching for Xavier Katico and Sabu.
- Just found Rafael Xavier (Kaotico) from https://users.opensuse.org/users/browse?page=215
- Which helps us find http://www.myspace.com/rafael.xavier.lima
- Google Group profile: http://groups.google.com/groups/profile?enc_user=_Flu6BMAAADLBp6cYldUPQJf0mUQ4OYWCrTwKYbraL2wE_wkV0bY1A
- sabu «foo@adsl-68-126-128-176.dsl.scrm01.pacbell.net» is on [irc.blessed.net/0] - Other: Here - Name: foo
- from 05/09/11 irc.botnet.biz #tr0ll Sabu makes an announcement about the start of LulzZec here
- [19:53] kayla also, word on the internet 306 fox.com employess passwords are getting leaked on http://twitter.com/#!/LulzSec soon after a destruction of many of their linkdins
- [20:19] Sabu http://twitter.com/#!/LulzSec
- [20:19] Sabu it begins
- [20:25] Sabu ecw sabu was a leet fuck
- [20:47] -->| Sabu (sabu@16170E25.B1424923.1A0A31BA.IP) has joined #tr0ll
- [23:33] -->| Sabu (sabu@bot-E5C834DD.recklesstheory.com) has joined #tr0ll
- http://steamcommunity.com/id/sabu
- From http://gfy.com/showthread.php?t=313680&page=2
- XSecurityAudit Posts:
- Went by 'Sabu'. Had lots of fun in pr's deadend, gd, mirageme (I miss MaXiMuM warez and all those guys). access, storm101 and so on. I met a lot of great people and they all disappeared with time. It's actually where I gained my interest in Security. sup to all those who have posted in here thus far from that era. (95-99)
- The below info comes from http://pastebin.com/911rucP3
- This looks like more sabu info that was just dropped. It looks
- credible. I am still going through it though.
- http://archives.neohapsis.com/archives/fulldisclosure/2005-12/1042.html
- Leads to email address: compromise@gmail.com
- Skype account alias is "defekt.tm","mujahadeen_bu"
- Skype account profile picture is same as that of anonymousabu on Twitter
- Flickr: http://www.flickr.com/photos/38442511@N00
- Flickr alias is Xavsec - in line with Xavier's security blog.
- See http://www.networksecurityarchive.org/html/FullDisclosure/2006-07/msg01304.html
- From: Xavier <compromise@gmail.com>
- Author: Xavier de Leon - xavier@tigerteam.se
- Also, see x@confinement.org. Alias:"xsecurityaudit"
- Go Google this: [xsecurityaudit site:gfy.com] and spend some time with
- the cached results
- On here he mentions "expect mail from xavier@"
- Regularly ending sentences with "mate" as in Twitter feed. Mentions NYC.
- Porn related site.
- From here down comes from an anonymous source with some modifications by me. Good work btw :)
- Here's the research and the path followed so that everyone else can start digging too:
- Nicknames: Sabu, leon, Xavier
- We have to consider that Sabu may be borrowing any and all names he's using, including Xavier de Leon and Xavier Kaotico.
- Knowns:
- - The nickname Sabu
- - The channel #pure-elite on LulzSec's private IRC network.
- A search for sabu and pure-elite yields this:
- http://darkmoondesigns.livejournal.com/17146.html
- with a comment by Sabu's then-girlfriend as follows:
- "t-- email xavier (sabu@pure-elite.org) and tell him whats up, maybe he can figure it out for you. he builds his own computers and such, he's awesome with hardware."
- The comment dates from 2003-02-13 06:06 am UTC, which is well before LulzSec, so the information is probably correct.
- From:
- http://bytes.com/topic/python/answers/19521-gathering-variable-names-within-function
- We can again see that Sabu is using the name Xavier with the account sabu@pure-elite.org. He also likes Python.
- Looking for Xavier and Sabu, we now come across the site:
- http://sentinix.berlios.de/develteam.shtml
- Which gives the name Xavier Kaotico, the website sabu.net, and the email address xavier@sentinix.org. Also, looking at the sentinix main page, we see a mention of TigerTeam.se (this comes later).
- Briefly, searching on the email address tells us that the AOL Instant Messenger name "Encryption" is registered to xavier@sentinix.org.
- Looking at sabu.net, we see that there's confirmation of involvement in Sentinix and something called #pure-elite, which Sabu refers to as "My child; My birth; My manifestation."
- Now we look up Xavier de Leon of TigerTeam security and find all of the following:
- http://osvdb.org/browse/by_creditee_name?letter=X
- - See Xavier de Leon of TigerTeam security
- http://www.blogger.com/profile/00785855826635701771
- - Blogger profile of Xavier de Leon, includes a blog on the now-defunct confinement.org, if anyone wants to purchase a domain whois history report for confinement.org there is no telling what interesting information that may provide. Written with Tia Marie and B.
- http://xavsec.blogspot.com/
- - Xavier's security blog
- http://web.archive.org/web/20070208195048/http://tigerteam.se/profiles_en.shtml
- - A now defunct security team of which Xavier was a part.
- An Introduction to Shellcoding by TigerTeam
- https://docs.google.com/viewer?a=v&q=cache:4NUqKnj6u3oJ:www.rootsecure.net/content/downloads/pdf/intro_to_shellcoding.pdf+xavier%40sentinix.org&hl=en&gl=uk&pid=bl&srcid=ADGEESgyv3_eDZoPeqLT7DzLKymRsLg2BNNvoMya4lFANwvb-eRSzqPYUjgMLJGgfEjigKN1AurFXoKV8OClnSetafgapyx0M8HCWu_ccFSp-R7mdcJMiDDIU8YGaVIY86N0Cq8Ogtb8&sig=AHIEtbSOQIk71B4M9nmyRNDLIPaVihVi6Q
- Which includes the text "In mid 2004 tigerteam.se opened up – my own consultancy firm in
- cooperation with Xavier de Leon (a security expert in New York City)." This is dated information, but we can assume from it that at some point, Sabu did indeed live in NYC.
- Looking for social networking profiles reveals only the following, registered to xavier@pure-elite.org:
- http://profiles.friendster.com/582074
- Which says that Sabu is 30, in a relationship, and living in New York, NY. Again, with the exception of the age, all of the information is dated. It also lists his occupation and interests:
- Occupation:
- Independent Consultant
- What I enjoy doing:
- Python programming, Network and System security, Speed Chess, Intellectual Conversations, and techie geek stuff.
- All of which is consistent with previously gathered information.
- Summary at this point:
- Name(s): Xavier Kaotico, Xavier de Leon
- Email: sabu@pure-elite.org, xavier@pure-elite.org, xavier@sentinix.org, xavier@tigerteam.se
- Age: 30 as of 2011-06-21
- Location: Possibly New York City, NY (has lived there)
- Websites: sabu.net, pure-elite.org, confinement.org
- Profession: Independent IT consultant
- Interests: Python programming, Linux, network security, exploit development
- Sabu is also purported to be ex-Hackweiser--an old website defacement group. If this is true, the defacement of chickenchoker.com includes a rant about Puerto Rico and describes Sabu as a Puerto Rican. See: http://web.archive.org/web/200102020250/http://chickenchoker.com/
- "Hello, i am "Sabu", no one special for now...lately i've been seeing ALOT of Brazilian and asian defacers just come out a leash their skills, i didn't see any Puerto Rican hacker's, or well: "defacer's", show up, so i guess i'll be your Puerto Rican defacer for now huh? elite... "
- Now for some bonus research, looking at pure-elite.org, we see that there is also a member called "aries". aries is referred to as the leader of pure-elite.
- http://othersidemod.hyperboards.com/index.php?action=view_topic&topic_id=10&start=1
- "Ok, i work at a place called pure-elite..pure-elite.org for the website. I am in their cs clan which consists of artists coders and dj's so you can email me at plagu3@pure-elite.org or bioslippery@hotmail.com and the boss of pure-elite is aries@exalted.org. Tell aries that i told you to email him an explain that you could use some help our mirc is irc.pure-elite.org and #pure-elite ok peace"
- http://web.archive.org/web/20011026084425/http://www.pure-elite.org/projects.html
- Additionally, on pure-elite.org, we see that aries is also a Python and PHP programmer, having written a CMS called Lotus. Everything indicates that aries and Sabu are not the same person, HOWEVER... Let's look up aries just to be sure.
- aries has a DeviantArt at http://aries.deviantart.com and his AIM name is "kill aries". The first comment is by mindwerks:
- "~mindwerks Jun 15, 2006
- well i didn't leave the name "aries" my email was out of date and i forgot the password so i have no way to access it ... don't play with the computer much anymore anyways ><"
- Now we visit mindwerks' DeviantArt and discover that he lives in New York. So Sabu and mindwerks/aries both live(d) in New York, were in a Counter-Strike clan together, and coded together in pure-elite.
- BIG REVEAL: I'm betting they knew one another in real life.
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
RAW Paste Data