Ashish Dhone ./blog

May 24, 2026 · 5 min read · 8 views

How I Hacked My College - Part 2

A simple challenge turned into a real-world demonstration of why cybersecurity matters. In this part, I share how a vulnerable search functionality led to a Blind SQL Injection attack that exposed critical college database information and how responsible disclosure helped secure the systems before any real damage could happen.

Ashish Dhone

Ashish Dhone

Offensive Security Researcher

In the first part, I shared how a weak SSH configuration gave me access to the college server. This part is about something even more serious: SQL Injection.

This story was not just about finding vulnerabilities. It started with a challenge.

One day, a senior member from the system department told me, “You can’t really do anything. You just sit in college and do small things.” I didn’t argue or try to prove anything at that moment. Instead, I went back and continued my research.

🔒 Subscriber Only

Continue reading for $5/month

Get full access to this post and every future write-up — bug bounty reports, red teaming guides, and offensive security deep-dives.

Supports USD & INR · Cancel anytime

5 reads

⚡ Enjoy this write-up?

Get every post like this — $5/month

Bug bounty reports, red teaming guides, and offensive security write-ups. New content every week. Cancel anytime.

Subscribe now →

Supports in USD & INR · Secure checkout via Dodo Payments

Want personalised guidance?

Book a 1-on-1 strategy call with me — offensive security, red teaming, SOC career path, or breaking into cybersecurity.

Book a session on Topmate →