<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Giacomo Lenzini</title>
    <link>https://giacolenzo2109.github.io/</link>
    <description>Recent content on Giacomo Lenzini</description>
    <generator>Hugo -- 0.152.2</generator>
    <language>en</language>
    <lastBuildDate>Mon, 03 Nov 2025 20:00:00 +0000</lastBuildDate>
    <atom:link href="https://giacolenzo2109.github.io/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>From Misconfiguration to RCE: A Deep Dive into Nextcloud Security ☁️</title>
      <link>https://giacolenzo2109.github.io/blog/nextcloud-rce/</link>
      <pubDate>Mon, 03 Nov 2025 20:00:00 +0000</pubDate>
      <guid>https://giacolenzo2109.github.io/blog/nextcloud-rce/</guid>
      <description>&lt;p&gt;During a recent penetration test, I came across a misconfigured &lt;strong&gt;Nextcloud&lt;/strong&gt; instance. With the appropriate permissions, it was possible to achieve &lt;strong&gt;Remote Code Execution (RCE)&lt;/strong&gt; in two distinct ways by leveraging built-in Nextcloud functionality. This post walks through the attack surface and outlines defensive measures.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Nextcloud&lt;/strong&gt; is an open-source platform for file storage, collaboration, and communication. It allows users to sync files, share documents, manage calendars, and collaborate securely across devices and teams. In many ways, Nextcloud resembles popular cloud services such as Google Drive or Dropbox, but it offers the key advantage of complete data ownership and enhanced privacy.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Spatial VDP: How I Rocked-Boosted a NASA XSS from P5 to P2 🚀</title>
      <link>https://giacolenzo2109.github.io/blog/nasa-vdp/</link>
      <pubDate>Tue, 13 May 2025 00:00:00 +0000</pubDate>
      <guid>https://giacolenzo2109.github.io/blog/nasa-vdp/</guid>
      <description>&lt;p&gt;A few months ago, I read an intriguing &lt;a href=&#34;https://blog.keephack.ing/2025-02-17-Houston-We-Have-a-vulnerability/&#34;&gt;article&lt;/a&gt; by Valerio &amp;ldquo;&lt;strong&gt;MrSaighnal&lt;/strong&gt;&amp;rdquo; Alessandroni, detailing how he earned a &lt;strong&gt;letter of acknowledgment from NASA&lt;/strong&gt; for reporting a vulnerability. That story stuck with me.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;NASA&amp;rsquo;s Vulnerability Disclosure Program (VDP)&lt;/strong&gt; is a non-monetary initiative that invites security researchers to report vulnerabilities in NASA&amp;rsquo;s public-facing systems. Unlike traditional bug bounties, the reward is purely ethical hacking glory – but with a cosmic twist.&lt;/p&gt;
&lt;p&gt;For valid P3 or higher vulnerabilities, researchers receive:&lt;/p&gt;</description>
    </item>
    <item>
      <title></title>
      <link>https://giacolenzo2109.github.io/whoami/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>https://giacolenzo2109.github.io/whoami/</guid>
      <description>&lt;h1 id=&#34;who-am-i&#34;&gt;Who am i&lt;/h1&gt;
&lt;p&gt;I am a 25-year-old guy graduate in cybersecurity, currently working as an &lt;strong&gt;Offensive Security Specialist&lt;/strong&gt;. In my role, I perform various types of penetration tests to strengthen the security posture of organizations. In my spare time, I actively participate in &lt;strong&gt;Bug Bounty&lt;/strong&gt; programs and engage in Capture The Flag (CTF) challenges and practice on various vulnerable labs (HackTheBox) to enhance my skills in ethical hacking and red teaming. I am also passionate about sports, having practiced kickboxing for 13 years, including 10 years at a competitive level. Currently, I practice CrossFit to maintain my fitness and discipline.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
