Super Cool Presentation by Jup1t3r

Jup1t3r (Jup1t3r)

SAINTCON 2025 · Day 3 · Main Track 1

Overview

In a refreshing departure from typical technical conference talks, Jup1t3r, a prominent figure in the cybersecurity community and a founder of SAINTCON, delivered a deeply personal and engaging presentation titled "Super Cool Presentation by Jup1t3r." Rather than dissecting a specific vulnerability or tool, Jup1t3r invited the audience on a journey through his origins as a hacker and cybersecurity professional, tracing his evolution from a curious child in rural Utah to a recognized expert working with organizations like DARPA, the FBI, and CISA. The talk masterfully illustrates how an insatiable curiosity, fueled initially by a desire to "just play video games," can organically lead to profound technical expertise and significant contributions to the security landscape.

Watch on YouTube

Visual summary for Super Cool Presentation by Jup1t3r by Jup1t3r
Visual summary for Super Cool Presentation by Jup1t3r by Jup1t3r

Key moments

  1. 0:00 Introduction: My origin story and career summary
  2. 2:00 Growing up in Gunlock: boredom and early tech curiosity
  3. 3:26 First Apple 2e computer and learning to code
  4. 4:24 Discovering the modem and Bulletin Board Systems (BBS)
  5. 4:56 Playing Trade Wars and early online community
  6. 6:25 Breaking into a library card catalog via command prompt
  7. 7:03 First internet access: learning Gopher protocol
  8. 8:00 Discovering vulnerable backbone phone switches on the internet

Super Cool Presentation by Jup1t3r

Speakers: Jup1t3r (Jup1t3r)

Conference: SAINTCON

YouTube: https://www.youtube.com/watch?v=5tRar2TftE0

Overview

In a refreshing departure from typical technical conference talks, Jup1t3r, a prominent figure in the cybersecurity community and a founder of SAINTCON, delivered a deeply personal and engaging presentation titled "Super Cool Presentation by Jup1t3r." Rather than dissecting a specific vulnerability or tool, Jup1t3r invited the audience on a journey through his origins as a hacker and cybersecurity professional, tracing his evolution from a curious child in rural Utah to a recognized expert working with organizations like DARPA, the FBI, and CISA. The talk masterfully illustrates how an insatiable curiosity, fueled initially by a desire to "just play video games," can organically lead to profound technical expertise and significant contributions to the security landscape.

This talk is particularly relevant for anyone in the cybersecurity field, regardless of their current role or experience level. It underscores the foundational importance of curiosity, experimentation, and community in developing robust security skills. Jup1t3r's narrative demonstrates that the path to becoming a cybersecurity expert is often non-linear, built on a series of small discoveries and unconventional learning experiences. His story serves as a powerful reminder that the "hacker mentality"—defined by a relentless drive to understand, explore, and sometimes subvert systems—is not only beneficial but essential for navigating the complex challenges of modern digital security. The talk culminates in a series of actionable recommendations, encouraging attendees to find their passion, seek mentorship, contribute to community, and continually expand their skill sets, all while retaining a playful, exploratory spirit.

Background

▶ Watch: Introduction: My origin story and career summary (0:00)

Jup1t3r's journey began in the seemingly unremarkable, isolated town of Gunlock, Utah, a setting that, paradoxically, became a crucible for his early technological exploration. Growing up in an environment where "everybody's related and they all know each other," opportunities for mischief were limited, but boredom was a fertile ground for a mind inclined towards technology. This intrinsic boredom, coupled with a strong innate curiosity, laid the groundwork for his future in cybersecurity. His initial foray into technology was through the nascent world of video games, starting with the iconic Atari 2600, which provided early lessons in interaction and system behavior.

A pivotal moment arrived when his father, who worked in technology, brought home an Apple 2e computer. This introduction to personal computing ignited Jup1t3r's passion for coding. Lacking formal instruction, he taught himself by meticulously copying lines of BASIC code from magazines found in his middle school library. This painstaking process, often performed longhand due to restrictions on taking periodicals home, imprinted upon him the critical importance of syntax and precision in programming—a foundational lesson for any aspiring technologist. The slow, deliberate act of typing code, debugging errors caused by simple misspellings like "M in input," honed his problem-solving skills and fostered a deep understanding of how software operates at a fundamental level. This early, self-directed learning epitomizes the "hacker mentality" he advocates for, driven by pure curiosity and the desire to make systems do what he wanted, primarily to play new games.

Key Findings

▶ Watch: First Apple 2e computer and learning to code (3:26)

While Jup1t3r's talk isn't about traditional "findings" from a research project, it presents a compelling series of personal discoveries that shaped his understanding of technology and security. These "key findings" are more accurately described as pivotal insights and realizations gleaned from his relentless experimentation and exploration.

One of his earliest and most impactful discoveries was the power of connectivity through a modem. This device transformed his isolated world, allowing him to connect to Bulletin Board Systems (BBSs) and interact with a broader digital community. The game Trade Wars became a central obsession, fostering not only competitive spirit but also an understanding of networked interactions and resource management within a digital environment. The realization that he could "log into other computers and explore some things" was a profound shift, demonstrating the permeable boundaries of early networked systems.

A significant "finding" came with the exploration of the Washington County Libraries card catalog system. What appeared to be a simple information portal turned out to be a gateway to deeper system access. By experimenting with the Control-Break command, Jup1t3r and his friends discovered they could "break out" of the interactive catalog interface and gain access to a command prompt. This exploit revealed a fundamental vulnerability in system design—unrestricted access after exiting an application. More importantly, this particular system was one of the few known devices in their area directly connected to the nascent internet. This discovery provided access to early internet protocols like Gopher, a text-only precursor to the World Wide Web, opening up new vistas of information and, naturally, more games.

His most audacious early "finding" involved backbone phone switches. Through Tnet (Telnet) and information gleaned from BBSs, Jup1t3r and his peers discovered that many critical telecommunications devices lacked robust security. Often, only a simple password, or sometimes no password at all, was required to gain access. Their primary tool for navigating these complex systems was the question mark (?) command, which provided command completion and help. This simple feature allowed them to map out entire phone switch architectures, leading to the astonishing claim that they "practically owned the entire 602 area code for a while." This period was also marked by the discovery of toll bypass techniques, where they learned to "bridge calls together" to connect to distant BBSs without incurring long-distance charges, a significant financial barrier in the pre-internet era.

Later, with the advent of PC games like Diablo, Jup1t3r's curiosity shifted to memory manipulation. Facing the inherent difficulty of early games, particularly in "hell mode," he discovered memory editors like SoftICE. This tool allowed him to directly modify the hexadecimal values of memory addresses, granting "infinite money, infinite life, infinite power" within games. This wasn't merely cheating; it was a deep dive into how games stored and managed their internal states, leading him to create and distribute executable "fixes" or cheats on BBSs and early internet sites. This demonstrated an early understanding of reverse engineering and payload creation.

Finally, his engagement with early game consoles, specifically the Xbox, further solidified his understanding of hardware modification. Learning from online communities, he discovered methods to "modify the device, take a resistor off, change a jumper," and gain root access. This allowed for the installation of larger hard drives (e.g., a 4 GB hard drive, significant for the time) and the ability to run pirated games. These experiences, though recreational, provided invaluable lessons in electrical engineering, operating system internals, and the physical security of devices. Each of these "findings," from simple code copying to complex system manipulation, built a cumulative knowledge base that would later define his professional career.

Technical Deep Dive

▶ Watch: Playing Trade Wars and early online community (4:56)

Jup1t3r's narrative, while personal, is rich with specific technical details that illustrate the evolution of hacking and cybersecurity. His early experiences with the Apple 2e involved painstakingly copying BASIC code from magazines. This process inherently taught him the rigid rules of programming languages, where a single misplaced space or a mistyped character (like "M in input") could render a program non-functional. This hands-on, trial-and-error approach to coding provided a visceral understanding of syntax analysis and compiler/interpreter behavior, even if the terms weren't known at the time.

The introduction of the modem opened a new frontier: remote system interaction. Connecting to Bulletin Board Systems (BBSs) meant engaging with remote servers over telephone lines, learning about serial communication protocols and the limitations of early data transfer speeds. Games like Trade Wars and Battle Chess were not just entertainment; they were practical lessons in networked application interaction, understanding client-server models, and persistence of data across sessions.

The infamous card catalog exploit was a rudimentary form of privilege escalation or shell escape. The Control-Break command, typically used to interrupt programs, was found to "break out" of the library's interactive application and drop the user directly into the underlying operating system's command prompt. This vulnerability exposed the lack of proper chroot or jail environments, allowing unauthorized access to the system's core functionalities. From this command prompt, they discovered the system's connection to the internet and explored early protocols like Gopher, which functioned as a hierarchical, text-based information retrieval system, a precursor to HTTP.

The most technically advanced early exploits involved backbone phone switches. Jup1t3r and his friends utilized Tnet (Telnet), an insecure but widely used plaintext remote access protocol, to connect to these critical telecommunications devices. The vulnerability stemmed from weak or default credentials and the absence of robust access controls. Their primary method of navigating these complex, proprietary operating systems was the question mark (?) command. This command, still prevalent in modern network device CLIs (e.g., Cisco IOS), provided context-sensitive help and command completion, allowing them to map out the command structure and available functions without prior knowledge. This technique effectively served as an early form of command injection or fuzzing to discover system capabilities. Their "ownership" of the 602 area code was a testament to the widespread lack of security on these critical infrastructure components.

Furthermore, they developed toll bypass techniques by manipulating these phone switches. This involved instructing the switch to bridge two separate calls, essentially creating a free long-distance connection. For example, they would call the switch, then command the switch to call another remote number (e.g., a popular BBS in another state) and connect the two lines. This demonstrated an understanding of call routing, session management, and signaling protocols within the telephone network, effectively exploiting the billing logic of the system.

With the rise of PC gaming, Jup1t3r delved into memory editing. Tools like SoftICE, a low-level debugger and memory editor, allowed direct manipulation of a running program's memory space. In games like Diablo, this involved identifying specific hexadecimal memory addresses corresponding to game variables such as health, money, or item counts. By changing the values at these addresses (e.g., setting a health value to its maximum or an inventory count to 999), they could achieve "infinite" resources. This required an understanding of memory architecture, data types, and how applications stored their state in RAM. The creation of executable "fixes" or cheats meant compiling small programs that would automatically perform these memory modifications, essentially developing early game trainers or patchers, which were then shared across BBSs and early internet sites. This experience directly relates to reverse engineering, exploit development, and binary patching.

His later foray into console modding with the original Xbox involved physical hardware manipulation. This included techniques like removing specific resistors or changing jumper settings on the motherboard. Such modifications were designed to bypass security checks, enable bootloader access, and ultimately gain root access to the console's operating system. This allowed for the installation of custom firmware, larger hard drives (specifically a 4 GB hard drive was mentioned, a significant storage capacity for the time), and the ability to run unsigned code, including pirated games. This required knowledge of electrical engineering fundamentals, hardware security bypasses, and embedded system hacking.

Finally, Jup1t3r's involvement with the DARPA Cyber Grand Challenge and the subsequent AI X2C project represents a leap into cutting-edge cybersecurity. This initiative focused on AI-based capture-the-flag competitions and developing AI-capable response systems for active threats. The goal of AI X2C is to move beyond traditional Endpoint Detection and Response (EDR) systems that merely detect signatures and kill processes. Instead, these AI systems are designed to "see something wrong as it's coming through and it's changing the traffic on the fly to actually mitigate and process and manage cyber security issues." This involves real-time threat intelligence, machine learning for anomaly detection, automated remediation, and potentially network traffic manipulation to neutralize threats proactively. This showcases a full circle, from manually exploiting systems to designing AI that can automatically defend them.

Demo / Proof of Concept

▶ Watch: Breaking into a library card catalog via command prompt (6:25)

Jup1t3r's "Super Cool Presentation" did not feature a live, real-time technical demonstration or proof of concept in the traditional sense. His talk was a narrative journey, illustrating past exploits and technical endeavors through storytelling rather than active display.

However, throughout his career, Jup1t3r has been actively involved in creating and demonstrating proofs of concept. His early days of hacking phone switches and developing game cheats (like the Diablo infinite money glitch) were, in themselves, practical proofs of concept. These were executable demonstrations of how systems could be subverted or manipulated to achieve an unintended outcome. Later, in his role in founding the Utah Saint community, he describes holding early "security summit" meetings where they "were demonstrating that, hey, here's the man-in-the-middle attack for a TNET session." This explicit mention indicates that his contributions to the community included practical, hands-on demonstrations of vulnerabilities and attack vectors to illustrate the emerging need for security. His work with the Defcon CTF competition and the DARPA Cyber Grand Challenge further involved the design and execution of complex, game-based proofs of concept for security vulnerabilities and automated defense mechanisms, albeit within a controlled competitive environment. While the talk itself lacked a live demo, the speaker's history is replete with instances of building and showcasing functional proofs of concept to educate and advance the field.

Defensive Implications

▶ Watch: Discovering vulnerable backbone phone switches on the internet (8:00)

Jup1t3r's journey, from a curious kid exploiting early systems to a leader in cybersecurity, offers profound defensive implications, particularly regarding understanding system fundamentals, fostering a security-conscious mindset, and building resilient communities.

Firstly, his early exploits highlight the critical importance of secure-by-design principles and defense-in-depth. The vulnerabilities he exploited in the card catalog (Control-Break to command prompt) and phone switches (weak/no passwords, reliance on question mark for navigation) underscore that basic security hygiene, such as robust access controls, proper sandboxing (chroot environments), and strong authentication, are paramount. Defenders must understand that seemingly innocuous applications can become gateways to deeper system access if not properly isolated and secured. This means regular vulnerability assessments and penetration testing are essential, even for seemingly low-risk, legacy systems.

The toll bypass techniques demonstrated how attackers could subvert billing logic and network routing. This implies that defenders need to scrutinize not only the security of individual devices but also the interconnectivity and business logic of their entire infrastructure. Understanding how different systems communicate and how services are charged or consumed can reveal unexpected attack vectors.

His experience with memory editors like SoftICE and Xbox modding emphasizes the need for memory protection mechanisms and hardware tamper detection. Modern operating systems and hardware have evolved to include features like ASLR (Address Space Layout Randomization) and DEP (Data Execution Prevention) to mitigate such attacks. However, defenders must ensure these features are enabled and actively monitor for attempts to bypass them. For embedded systems and IoT devices, physical security and tamper-resistant designs become crucial, along with secure boot processes.

Perhaps the most significant defensive implication comes from his emphasis on curiosity, experimentation, and community. Jup1t3r explicitly states that defenders should "be curious, help, and explore boundaries" and "have that hacker mentality." This means security teams should be encouraged to understand how systems can be broken, not just how they should work. Fostering an internal "red team" mentality or engaging with external penetration testers who think like the adversaries Jup1t3r once was can reveal blind spots.

His work with DARPA's AI X2C project points to the future of defense: proactive, AI-driven threat mitigation. Defenders should be preparing for a landscape where AI not only detects threats but actively neutralizes them in real-time by "changing the traffic on the fly." This necessitates investing in AI/ML-based security solutions, understanding their capabilities and limitations, and developing the expertise to manage and tune such advanced systems. It also suggests that threat intelligence will become even more critical, feeding these AI systems with the latest attack patterns and vulnerabilities.

Finally, Jup1t3r's role in building the Utah Saint community highlights the power of collective defense. Sharing knowledge, tactics, and experiences within a trusted community (like the Scon Discord server or the bi-weekly cybersecurity briefings) is a force multiplier for defenders. No single organization can tackle all threats alone; collaboration and information sharing are vital for staying ahead of evolving attack techniques. Defenders should actively seek out and contribute to such communities, leveraging shared intelligence and expertise.

Key Takeaways

  • Cultivate Curiosity and Play: Jup1t3r's entire career stemmed from a desire to "just play video games" and an insatiable curiosity about how things work. This hacker mentality—exploring boundaries and experimenting—is fundamental to understanding and securing complex systems.
  • Foundational Technical Skills are Paramount: Early experiences with coding (Apple 2e BASIC), network protocols (modems, BBS, Telnet, Gopher), and system internals (Control-Break, phone switches, memory editing with SoftICE, console modding) provided a deep, practical understanding that transcended theoretical knowledge.
  • Community is a Force Multiplier: Finding and contributing to a community of like-minded individuals (like Defcon, School of Root, DDT, and Utah Saint) is critical for learning, sharing knowledge, and evolving skills. It provides mentorship and collaborative opportunities.
  • Embrace Continuous Learning and Skill Expansion: The cybersecurity landscape is constantly changing. Jup1t3r's journey shows a consistent pattern of expanding his passion to adjacent skills and projects, from electrical engineering for console modding to AI for threat mitigation.
  • Security is an Evolving Discipline: From early days where firewalls were a novel concept to today's AI-driven defenses, the field has transformed dramatically. Staying current, understanding emerging threats (like AI X2C), and adapting defensive strategies are essential.
  • Give Back and Share Knowledge: Once expertise is gained, sharing it with others, as Jup1t3r did by founding Utah Saint and organizing conferences like SAINTCON, strengthens the entire community and elevates collective security posture.

About the Speaker(s)

Jup1t3r is a seasoned cybersecurity professional and a pivotal figure in the Utah cybersecurity community. His career path, as detailed in his talk, is a testament to the power of self-directed learning, curiosity, and community engagement. He has worked on significant projects with various government and national organizations, including DARPA, the FBI, the National Guard, and CISA, demonstrating his broad expertise and contributions to national security efforts.

His origins as a "hacker" began with early explorations of computers and networks, from coding on an Apple 2e and engaging with BBSs to exploiting phone switches and developing game cheats using tools like SoftICE. He was an active participant and later a leader in the Defcon Capture The Flag (CTF) competition, initially as part of the School of Root team and subsequently with the DDT team, which ran the Defcon CTF from Defcon 16 through Defcon 20. His involvement extended to cutting-edge research, including the DARPA Cyber Grand Challenge and the AI X2C initiative, focusing on AI-based active threat mitigation.

Beyond his technical exploits, Jup1t3r is celebrated for his community-building efforts. In 2001, he initiated what would become the Utah Saint (Security Advisory and Incident Network Team) community, a group dedicated to sharing cybersecurity knowledge among professionals in Utah. This community formalized into a nonprofit in 2014, leading to the creation of the annual SAINTCON conference in 2015, which he co-founded. He also contributes to the community through a bi-weekly cybersecurity briefing, sharing insights on current trends and tactics. The nickname "Jup1t3r" originated during his time with the Defcon CTF, where teams adopted planet names.

All talks from SAINTCON 2025