skip to content
blog.0x6a0x72.com
posts tags author rss
Jun 13, 2026 #Initial Access#Red Teaming#Active Directory#Penetration Testing

Pwned by a Profile Picture: How a Web Upload Toppled an Entire Domain

A full technical walk-through of a chained attack that moved from a client-side validation bypass on a public ITSM portal to complete Active Directory compromise—with no zero-days required.

Read article →
Jyotirmoy Roy / feed Published with ShadowNote