Penetration tester · Bug bounty hunter · Italy
Jacopo Tediosi
Full-time penetration tester. In his free time he hunts for vulnerabilities in real systems and contributes to open source, most of all to OctoPrint, the open source software that runs 3D printers from a web browser.
Everything is built in layers.
So is every way in. The work is finding the one layer nobody checked, then reporting it so it gets fixed.
Unlocked.
Next: the bug that reached every Akamai edge node, and ranked #7 in PortSwigger's Top 10 web hacking techniques of 2022.
Scroll to print · move to turn the bed
March 2022 · with Francesco Mariani
The bug that reached half the web.
Testing a private bug bounty program on a site behind Akamai, Jacopo and his friend Francesco noticed one odd reply and dug in instead of moving on. It turned out to be a flaw in Akamai itself, affecting nearly every site Akamai serves. What mattered next was getting it fixed.
- 21 Mar 2022An unusual reply catches their eye during a routine test.
- ReportedAkamai has no bug bounty program, so they report it to Akamai first, privately.
- CustomersWhile the fix rolls out, they warn Akamai's customers one by one. Airbnb blocks it on its own firewall in under 24 hours.
- 05 Oct 2022Akamai publishes an official advisory. Microsoft and Apple send private thanks.
- Feb 2023The technique ranks #7 in PortSwigger's Top 10 web hacking techniques of 2022.
- Whitejar private program€5,000
- PayPal$25,200
- Airbnb$14,875
- Hyatt Hotels$4,000
- Valve (Steam)$750
- Zomato$450
- Goldman Sachs$100
- Starbucks"not a major issue"
- PlayStationcould not reproduce
- Marriottcache out of scope
"We are white hats," Jacopo wrote, "but we were still not willing to work for free." Some programs paid well, some closed the report, and every one of them was told. This is that receipt.
Recognition came from the field itself: #7 in PortSwigger's Top 10 web hacking techniques of 2022.
Read Jacopo's full write-up ↗Nine advisories in the software that runs 3D printers.
Jacopo is most active in the 3D printing community, so he turned his eye on the software behind it. Since 2024 he has reported nine vulnerabilities in OctoPrint and its plugins, each fixed and published with a CVE. Tap a line to read what it allowed.
He also built octoscanner, a static analysis tool that checks OctoPrint plugins for security issues and deprecated code. Earlier, in 2020: CVE-2020-8115, a reflected XSS in Revive Adserver.
Built in the open.
January 2018 · the first one
A login link that trusted the wrong address.
His first bug bounty, as a student. Altervista, the Italian host of about three million sites, let its forum log people in with a link. Jacopo found that the address check could be fooled, so a stolen sign-in code could be sent anywhere.
+ Jacopo Tediosi
- 02 JanStarted looking
- 03 JanFound it, sent proof to the security team
- 04 JanPatch online, name on the thanks list
Found something? Need someone to look?
For security testing enquiries, responsible disclosure, OctoPrint plugins or a talk, write to Jacopo directly or let the terminal take your brief.