<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Penetration Test on Giacomo Lenzini</title>
    <link>https://giacolenzo2109.github.io/tags/penetration-test/</link>
    <description>Recent content in Penetration Test on Giacomo Lenzini</description>
    <generator>Hugo -- 0.152.2</generator>
    <language>en</language>
    <lastBuildDate>Mon, 03 Nov 2025 20:00:00 +0000</lastBuildDate>
    <atom:link href="https://giacolenzo2109.github.io/tags/penetration-test/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>From Misconfiguration to RCE: A Deep Dive into Nextcloud Security ☁️</title>
      <link>https://giacolenzo2109.github.io/blog/nextcloud-rce/</link>
      <pubDate>Mon, 03 Nov 2025 20:00:00 +0000</pubDate>
      <guid>https://giacolenzo2109.github.io/blog/nextcloud-rce/</guid>
      <description>&lt;p&gt;During a recent penetration test, I came across a misconfigured &lt;strong&gt;Nextcloud&lt;/strong&gt; instance. With the appropriate permissions, it was possible to achieve &lt;strong&gt;Remote Code Execution (RCE)&lt;/strong&gt; in two distinct ways by leveraging built-in Nextcloud functionality. This post walks through the attack surface and outlines defensive measures.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Nextcloud&lt;/strong&gt; is an open-source platform for file storage, collaboration, and communication. It allows users to sync files, share documents, manage calendars, and collaborate securely across devices and teams. In many ways, Nextcloud resembles popular cloud services such as Google Drive or Dropbox, but it offers the key advantage of complete data ownership and enhanced privacy.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
