2000 character limit reached
The Postman: A Journey of Ethical Hacking in PosteID/SPID Borderland
Published 22 Jul 2025 in cs.CR | (2507.17007v1)
Abstract: This paper presents a vulnerability assessment activity that we carried out on PosteID, the implementation of the Italian Public Digital Identity System (SPID) by Poste Italiane. The activity led to the discovery of a critical privilege escalation vulnerability, which was eventually patched. The overall analysis and disclosure process represents a valuable case study for the community of ethical hackers. In this work, we present both the technical steps and the details of the disclosure process.
Paper Prompts
Sign up for free to create and run prompts on this paper.