Ashish Dhone ./blog

May 25, 2026 ยท 5 min read ยท 6 views

How I Hacked My College - Part 3

The final part of the series covers how a vulnerable file upload functionality led to Remote Code Execution (RCE) on college infrastructure. What appeared secure initially was bypassed through weak server-side validation, highlighting how small security mistakes can lead to critical system compromise.

Ashish Dhone

Ashish Dhone

Offensive Security Researcher

This is the final part of the series and probably the most impactful one achieving Remote Code Execution (RCE).

More than finding vulnerabilities, this journey was about changing how cybersecurity was viewed within the college environment. In many educational institutions, security is often ignored until a serious incident occurs. My goal throughout this assessment was to demonstrate why proactive security matters before real attackers exploit these weaknesses.

I also want everyone reading this to understand how important data security really is. Whether it is a college, company, or third-party service provider, your personal information is often handled by multiple systems behind the scenes. If those systems are not secured properly, the consequences can be severe.

๐Ÿ”’ Subscriber Only

Continue reading for $5/month

Get full access to this post and every future write-up โ€” bug bounty reports, red teaming guides, and offensive security deep-dives.

Supports USD & INR ยท Cancel anytime

4 reads

โšก Enjoy this write-up?

Get every post like this โ€” $5/month

Bug bounty reports, red teaming guides, and offensive security write-ups. New content every week. Cancel anytime.

Subscribe now →

Supports in USD & INR ยท Secure checkout via Dodo Payments

Want personalised guidance?

Book a 1-on-1 strategy call with me โ€” offensive security, red teaming, SOC career path, or breaking into cybersecurity.

Book a session on Topmate →