From Misconfiguration to RCE: A Deep Dive into Nextcloud Security ☁️

During a recent penetration test, I came across a misconfigured Nextcloud instance. With the appropriate permissions, it was possible to achieve Remote Code Execution (RCE) in two distinct ways by leveraging built-in Nextcloud functionality. This post walks through the attack surface and outlines defensive measures. Nextcloud is an open-source platform for file storage, collaboration, and communication. It allows users to sync files, share documents, manage calendars, and collaborate securely across devices and teams. In many ways, Nextcloud resembles popular cloud services such as Google Drive or Dropbox, but it offers the key advantage of complete data ownership and enhanced privacy. ...

November 3, 2025 · 6 min · GiacoLenzo2109

Spatial VDP: How I Rocked-Boosted a NASA XSS from P5 to P2 🚀

A few months ago, I read an intriguing article by Valerio “MrSaighnal” Alessandroni, detailing how he earned a letter of acknowledgment from NASA for reporting a vulnerability. That story stuck with me. NASA’s Vulnerability Disclosure Program (VDP) is a non-monetary initiative that invites security researchers to report vulnerabilities in NASA’s public-facing systems. Unlike traditional bug bounties, the reward is purely ethical hacking glory – but with a cosmic twist. For valid P3 or higher vulnerabilities, researchers receive: ...

May 13, 2025 · 9 min · GiacoLenzo2109