Secure Coding the Heck Out of Your Web Apps

In web development, writing secure code isn’t just a “nice-to-have” – it’s absolutely critical. One tiny vulnerability can blow up in your face, exposing sensitive user data, trampling on privacy, and, let’s be real, absolutely trashing your reputation. I want to walk you through some of the most common web application vulnerabilities I see out there, share how we tackle them, and give you some pointers on what I zero in on during a good old-fashioned code review....

September 1, 2025 · 16 min

BadSuccessor: From OU Access to Domain Admin

With the dMSA trust model explained, let’s get into the part 2, on how attackers weaponize it. The vulnerability—dubbed BadSuccessor—abuses the migration logic behind dMSAs to create a forged link between any service account and a privileged user. No actual migration required. No permissions over the target needed. Just write access to an Organizational Unit and a little Active Directory knowledge. I’m going to break down how attackers create fake dMSAs, forge migration attributes, and abuse Kerberos PAC inheritance to escalate privileges—all while staying nearly invisible to traditional detection....

August 1, 2025 · 9 min

dMSA Trust Model & Vulnerability

Microsoft’s introduction of Delegated Managed Service Accounts (dMSAs) in Windows Server 2025 was supposed to improve security by replacing those messy legacy service accounts we’ve all been dealing with for years. But in late May 2025, security researchers found a devastating flaw in the dMSA implementation—they’re calling it “BadSuccessor”—and it can lead to complete domain takeover.This would be a 3 part blog with the first part digging into dMSA design and PAC flaw....

June 17, 2025 · 6 min

GPOddity: Understanding the Advanced Privilege Escalation Attack in Active Directory

Introduction Active Directory (AD) security continues to be a critical concern for organizations worldwide. Among the numerous attack vectors that threaten AD environments, GPOddity stands out as a particularly sophisticated technique that leverages Group Policy Objects (GPOs) and NTLM relaying to achieve privilege escalation. First documented by security researchers at Synacktiv, this attack can bypass many common security controls and lead to domain-wide compromise. In this technical deep dive, we’ll explore how GPOddity works, why it’s dangerous, and how security teams can defend against it....

May 21, 2025 · 10 min

Dattebayo! My HTB Seasonal Conquest

Prologue Hey there, This blog is not gonna be about the technical nitty-gritty and would be more on my experience and the challenges I faced. Buckle up for a tale of triumph, tribulation, and teamwork – all with a dash of Naruto sprinkled in (dattebayo!). This is the story of my 13-week HTB seasonal conquest! Yess, Naruto Fan here !! The Mission: Reach for the Holo! HTB uses a ranking system based on the percentage of flags captured during the season....

April 14, 2024 · 4 min

GCC 2024: My Experience

Prologue Last week, I alongside with 3 other Indian Students, Sejal, anikait and Rajarshi represented India to participate in GCC 2024 at Thailand. We had an amazing experience representing our country at the Global Cybersecurity Camp (GCC) 2024 in Thailand. This blog isn’t about the technical nitty-gritty, but rather about the incredible memories and fun we had during that unforgettable week. A big shoutout to VueNow and Traboda for sponsoring this amazing trip!...

February 28, 2024 · 13 min