/trophies

Highlights from vulnerabilities I've discovered and original exploits

trophies

alt text
Collection of vulnerabilities I've discovered and original exploits

alt text
Password Hash Disclosure
https://nvd.nist.gov/vuln/detail/CVE-2018-9334
https://www.securityfocus.com/bid/104677/info

GlobalProtect User Stored Password Decryption
https://github.com/billchaison/ClobberProtect

GlobalProtect client VPN tunnel crash

alt text
Release 10.4.000000, Security Fix, PuTTY Log Password Disclosure
https://thycotic.force.com/support/s/article/SS-Release-Notes

alt text
Xerox Cloning File Password Decryption
https://github.com/billchaison/zer0cks

alt text
Allworx Admin Password Reset
https://github.com/billchaison/Alldorx

alt text
WinSCP Stored Password Decryption
https://github.com/billchaison/WinSCoPe

alt text
Polycom RealPresence Desktop Password Decryption
https://github.com/billchaison/reelpresence

alt text
LogRhythm INI File Password Decryption
https://github.com/billchaison/GotNoRhythm

alt text
VyOS Root Privilege Escalation
https://github.com/billchaison/VyOS-Get-Root

alt text
Ericsson Password Decoder
https://github.com/billchaison/ED

alt text
Key Systems admin privilege escalation
https://github.com/billchaison/KeyStoned

alt text
Incognito BCC username disclosure and privilege escalation
https://github.com/billchaison/Incog-Neato

alt text
Trimble NetRS diagnostic easter egg, config file access, root privilege escalation (LFI, command injection), and back door binary
https://github.com/billchaison/Tremble

alt text
Digi Wireless Router Password Decoder
https://github.com/billchaison/Dig-it

alt text
Motorola NC1500 Backdoor Password
https://github.com/billchaison/nc1500

alt text
Nokia hash2 Password Decrypter
https://github.com/billchaison/Nuke-ia

alt text
ForeScout SecureConnector Protected Uninstaller Bypass

alt text
VMWare Horizon LSASS Dumping

alt text
Emerging Technologies Bandwidth Manager, unauthenticated credential disclosure, XSS