<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Niccolò Parlanti | Research</title><link>https://niccoloparlanti.com/research/</link><description>Offensive security research and field notes.</description><item><title>A mask shall not answer questions about what it hides.</title><description>LIKE-wildcard injection: a public leaderboard masked account numbers in its output but let search filters test the hidden digits.</description><link>https://niccoloparlanti.com/bug-code/a-mask-shall-not-answer-questions/</link><guid>https://niccoloparlanti.com/bug-code/a-mask-shall-not-answer-questions/</guid><pubDate>Mon, 07 Sep 2026 00:00:00 GMT</pubDate></item><item><title>A signature shall not vouch for what the parser swallowed.</title><description>Unauthenticated XXE in SAML: local DTD reuse turned a signed error response into a server-file disclosure channel.</description><link>https://niccoloparlanti.com/bug-code/a-signed-response-is-not-a-safe-response/</link><guid>https://niccoloparlanti.com/bug-code/a-signed-response-is-not-a-safe-response/</guid><pubDate>Mon, 07 Sep 2026 00:00:00 GMT</pubDate></item><item><title>A template shall not promote its author.</title><description>Server-side template injection: brace-free QWeb syntax passed the WAF, then exposed privileged database reads and writes.</description><link>https://niccoloparlanti.com/bug-code/a-template-is-not-an-administrator/</link><guid>https://niccoloparlanti.com/bug-code/a-template-is-not-an-administrator/</guid><pubDate>Mon, 07 Sep 2026 00:00:00 GMT</pubDate></item><item><title>An identifier shall not choose the route.</title><description>Path-only SSRF: a product ID redirected a backend request to an internal staff directory, then a decoding error exposed the response.</description><link>https://niccoloparlanti.com/bug-code/an-id-shall-not-rewrite-the-route/</link><guid>https://niccoloparlanti.com/bug-code/an-id-shall-not-rewrite-the-route/</guid><pubDate>Mon, 07 Sep 2026 00:00:00 GMT</pubDate></item><item><title>Remember the device. Forget the password.</title><description>Recoverable password storage: a remember-me cookie retained a Base64-encoded password for 180 days, readable by page scripts.</description><link>https://niccoloparlanti.com/bug-code/remember-the-device-not-the-password/</link><guid>https://niccoloparlanti.com/bug-code/remember-the-device-not-the-password/</guid><pubDate>Mon, 07 Sep 2026 00:00:00 GMT</pubDate></item><item><title>The shopper shall not set the clock.</title><description>Pricing logic abuse: a guest-writable shopper context activated a scheduled future discount in the product response and basket.</description><link>https://niccoloparlanti.com/bug-code/the-shopper-shall-not-set-the-clock/</link><guid>https://niccoloparlanti.com/bug-code/the-shopper-shall-not-set-the-clock/</guid><pubDate>Mon, 07 Sep 2026 00:00:00 GMT</pubDate></item><item><title>When an echo endpoint becomes a script runner</title><description>A missing Content-Type header, Go’s MIME detection, and the browser behavior behind CVE-2026-43644.</description><link>https://niccoloparlanti.com/research/podinfo-content-type/</link><guid>https://niccoloparlanti.com/research/podinfo-content-type/</guid><pubDate>Sun, 06 Sep 2026 00:00:00 GMT</pubDate></item><item><title>The moment JSON stops being data</title><description>Following a constructor name into dynamic code generation in TeleJSON.</description><link>https://niccoloparlanti.com/research/telejson-constructor/</link><guid>https://niccoloparlanti.com/research/telejson-constructor/</guid><pubDate>Sun, 06 Sep 2026 00:00:00 GMT</pubDate></item><item><title>A valid token shall speak for one account only.</title><description>Account impersonation through email normalization: distinct authenticated subjects resolved to the same application account.</description><link>https://niccoloparlanti.com/bug-code/a-token-is-not-an-account/</link><guid>https://niccoloparlanti.com/bug-code/a-token-is-not-an-account/</guid><pubDate>Sun, 06 Sep 2026 00:00:00 GMT</pubDate></item><item><title>An invitation shall admit its recipient. Nobody else.</title><description>Privilege escalation through invitation hijacking: a missing recipient check assigned an administrator role to a different account.</description><link>https://niccoloparlanti.com/bug-code/invitation-is-not-identity/</link><guid>https://niccoloparlanti.com/bug-code/invitation-is-not-identity/</guid><pubDate>Sun, 06 Sep 2026 00:00:00 GMT</pubDate></item><item><title>A service shall not lend its privileges to strangers.</title><description>Missing API authentication: cloud-identity-backed processing and a signed diagnostic link exposed internal error data.</description><link>https://niccoloparlanti.com/bug-code/service-identity-is-not-permission/</link><guid>https://niccoloparlanti.com/bug-code/service-identity-is-not-permission/</guid><pubDate>Sun, 06 Sep 2026 00:00:00 GMT</pubDate></item><item><title>My experience with eJPTv2</title><description>Preparation, practice, and lessons from my first penetration testing certification.</description><link>https://niccoloparlanti.com/research/ejpt/</link><guid>https://niccoloparlanti.com/research/ejpt/</guid><pubDate>Wed, 03 Jul 2024 00:00:00 GMT</pubDate></item><item><title>Evading Deepfake Classifier with Adversarial Attacks</title><description>An in-depth analysis of white-box adversarial attacks against deepfake-image detectors, exploring the vulnerability of AI-driven systems.</description><link>https://niccoloparlanti.com/research/projects-evading-classifier/</link><guid>https://niccoloparlanti.com/research/projects-evading-classifier/</guid><pubDate>Sun, 28 Jan 2024 00:00:00 GMT</pubDate></item><item><title>Cryptographically enforced access control</title><description>Desing and implement a Cryptographically Enforced Access Control using CP-ABE</description><link>https://niccoloparlanti.com/research/projects-cryptographically-enforced-access-control/</link><guid>https://niccoloparlanti.com/research/projects-cryptographically-enforced-access-control/</guid><pubDate>Wed, 08 Nov 2023 00:00:00 GMT</pubDate></item><item><title>THS challenges: cryptography</title><description>Working through cryptographic puzzles, from assumptions to solutions.</description><link>https://niccoloparlanti.com/research/ths-crypto/</link><guid>https://niccoloparlanti.com/research/ths-crypto/</guid><pubDate>Tue, 12 Sep 2023 00:00:00 GMT</pubDate></item><item><title>THS Challenges Writeups - Misc</title><description>Writeups of the challenges of THS  - Misc</description><link>https://niccoloparlanti.com/research/writeups-ths-challenge/</link><guid>https://niccoloparlanti.com/research/writeups-ths-challenge/</guid><pubDate>Sun, 10 Sep 2023 00:00:00 GMT</pubDate></item><item><title>Vulnerabilities Identification and Exploitation</title><description>An extensive report on security testing practices for identifying, assessing, and exploiting vulnerabilities in web applications, detailed with real-world data and code examples.</description><link>https://niccoloparlanti.com/research/projects-vulnerability-assessment/</link><guid>https://niccoloparlanti.com/research/projects-vulnerability-assessment/</guid><pubDate>Thu, 15 Jun 2023 00:00:00 GMT</pubDate></item><item><title>Dante CTF: web challenges</title><description>An earlier set of hands-on web security challenges and their solutions.</description><link>https://niccoloparlanti.com/research/dante-web/</link><guid>https://niccoloparlanti.com/research/dante-web/</guid><pubDate>Mon, 05 Jun 2023 00:00:00 GMT</pubDate></item><item><title>Dante CTF Writeups - Forensics</title><description>Writeups of the Dante CTF 2023 - Forensics</description><link>https://niccoloparlanti.com/research/writeups-dante-ctf-2023/</link><guid>https://niccoloparlanti.com/research/writeups-dante-ctf-2023/</guid><pubDate>Mon, 05 Jun 2023 00:00:00 GMT</pubDate></item><item><title>Image watermarking with DWT, SVD, and DCT</title><description>Embedding of a watermak using DWT-SVD and a DWT-DCT tranform.</description><link>https://niccoloparlanti.com/research/projects-watermarking/</link><guid>https://niccoloparlanti.com/research/projects-watermarking/</guid><pubDate>Tue, 18 Oct 2022 00:00:00 GMT</pubDate></item><item><title>FastTicket Web App</title><description>A site that shows ticket offices, bus stops and tramway stops in the Florence area, using geolocation and routing programs to guide the user to the chosen destination.</description><link>https://niccoloparlanti.com/research/projects-fastticket-webapp/</link><guid>https://niccoloparlanti.com/research/projects-fastticket-webapp/</guid><pubDate>Fri, 08 Apr 2022 00:00:00 GMT</pubDate></item><item><title>Todo List</title><description>TodoApp is a user-friendly and feature-rich task management application that helps users stay organized, increase productivity, and effortlessly manage their tasks and to-do lists.</description><link>https://niccoloparlanti.com/research/projects-todolist/</link><guid>https://niccoloparlanti.com/research/projects-todolist/</guid><pubDate>Sun, 24 Oct 2021 00:00:00 GMT</pubDate></item><item><title>Kruskal Algorithm</title><description>Theoretical report on connected components and kruskal algorithm, with tests and related analysis.</description><link>https://niccoloparlanti.com/research/projects-kruskal/</link><guid>https://niccoloparlanti.com/research/projects-kruskal/</guid><pubDate>Wed, 08 Sep 2021 00:00:00 GMT</pubDate></item><item><title>Edit distance with and without N-grams</title><description>This project implements the Edit Distance algorithm with and without N-Gram support, providing a versatile tool for string similarity and comparison tasks in various domains.</description><link>https://niccoloparlanti.com/research/projects-editdistance/</link><guid>https://niccoloparlanti.com/research/projects-editdistance/</guid><pubDate>Sun, 05 Sep 2021 00:00:00 GMT</pubDate></item></channel></rss>