EDBT 2026 Demo / reviewers in the wild / expert
Lorenzo Pisu
dblp:357/1014
· DBLP profile ↗
7ranked-venue papers
4as first author
7since 2021 · last 2026
0009-0001-0129-1976ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 1 first-author · 4 since 2021Computer networks · 1 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | An Analysis of Modern Web Security Vulnerabilities Inside WebAssembly Applications
Lorenzo Corrias, Lorenzo Pisu, Davide Maiorca, Giorgio Giacinto |
ICISSP (1) | 2 |
| 2026 | Race against time: investigating the factors that influence web race condition exploitsabstractRace conditions (RC) pose a critical security threat to web applications by exploiting the non-deterministic behavior of multithreaded request handling. This can lead to unpredictable outcomes such as data corruption, Time of Check to Time of Use (TOCTOU) vulnerabilities, and deadlocks. While previous research has identified poor design practices that contribute to RC vulnerabilities, no existing studies have explored the factors that influence the severity or impact of race conditions. This paper introduces a comprehensive methodology for testing and quantifying how different variables affect the exploitability of race conditions in vulnerable web servers, providing a framework for future research to investigate this issue more thoroughly. In addition, we present an experimental evaluation of our methodology under various conditions. Specifically, we examine six RC exploitation tools using four different attack techniques across both HTTP/1.1 and HTTP/2 protocols. To provide a complete overview of race conditions across all HTTP versions, we also introduce the first race condition attack tool for HTTP/3, named QUICker. Furthermore, we assess how the choice of database management systems and programming languages used in web application deployment can affect susceptibility to race condition attacks. This study offers key insights into how these factors influence the exploitability of RC vulnerabilities. Federico Loi, Lorenzo Pisu, Leonardo Regano, Davide Maiorca, Giorgio Giacinto |
Comput. Secur. | 2 |
| 2026 | An Assessment of the Overlooked Dangers of Template EnginesabstractTemplate engines play a pivotal role in modern web application development by enabling the dynamic rendering of content, products, and user interfaces. Today, they are essential for any website that handles dynamic data, from e-commerce to social media. However, their widespread adoption also makes them attractive targets for attackers seeking to exploit vulnerabilities and gain unauthorized access to web servers. This paper presents a comprehensive assessment of the risks associated with template engines, with a particular focus on the consequences of Server-Side Template Injection (SSTI) and the ease with which such vulnerabilities can escalate to Remote Code Execution (RCE), a critical security concern in web application development. Lorenzo Pisu, Davide Maiorca, Giorgio Giacinto |
ACM Trans. Web | 1 |
| 2025 | Evaluation of Resource-Aware HTTP/3 Proxies for Smuggling Resilience in IoT EnvironmentsabstractThe growing integration of IoT devices into Edge and Fog infrastructures, alongside the increasing adoption of low-latency QUIC-based protocols like HTTP/3, has intensified the need for lightweight, resource-efficient security mechanisms to counter emerging threats such as request smuggling. Within this context, proxy-based architectures offer an optimal trade-off to strengthen network security while accommodating the limited computational capacity of IoT devices. In this direction, this paper presents a comprehensive experimental evaluation of the impact of different proxies for HTTP/3 services on resource usage when deployed on platforms such as the Raspberry Pi (RPi), considering diverse traffic patterns, operational conditions, and device configurations. The results highlight that proxies can achieve a promising balance between security and resource overhead, confirming their viability for integration into distributed IoT-based Edge and Fog networks. Lorenzo Pisu, Giovanni Pettorru, Leonardo Regano, Davide Maiorca, Giorgio Giacinto, Marco Martalò |
GLOBECOM | 1 |
| 2025 | {{alert('CSTI')}}: Large-Scale Detection of Client-Side Template InjectionabstractTemplate engines are software components that enable the creation of reusable HTML elements containing special keywords that can dynamically alter the page’s rendering based on the presented data. This technology is widely used in server-side applications and frameworks, and in recent years, it has also gained adoption on the client side through JavaScript frameworks and libraries. Client-Side Template Injection (CSTI) is a vulnerability that occurs when user input is reflected inside a template and rendered as part of it, allowing attackers to inject malicious instructions. This can trick the template engine into executing arbitrary JavaScript code, potentially leading to Cross-Site Scripting (XSS). Despite the widespread adoption of template engines in production websites, a comprehensive study of their characteristics remains absent. In our study, we begin by providing an overview of the main features of template engines, highlighting attributes that play a crucial role in escalating CSTI to XSS. We then use these extracted characteristics to develop a systematic methodology for detecting CSTI vulnerabilities. Based on this methodology, we create an automatic CSTI detection tool, CSTI-Alert. By running CSTI-Alert on the Tranco top 1 million domains, we identify 532 CSTI-vulnerable domains, with 72% directly leading to XSS through GET parameters or CSRF. Finally, we discuss potential approaches to defend against CSTI based on the result of semi-automatic exploitability analysis. Lorenzo Pisu, Davide Balzarotti, Davide Maiorca, Giorgio Giacinto |
RAID | 1 |
| 2024 | HTTP/3 will not Save you from Request Smuggling: A Methodology to Detect HTTP/3 Header (mis)ValidationsabstractHTTP/3 will be the new de-facto standard for communication in web applications. Despite its increasing integration into modern browsers, its security properties have not yet been fully investigated. A significant problem is represented by request smuggling attacks, which may constitute a critical issue concerning web applications’ security and privacy, leading to critical consequences such as cache poisoning, session hijacking, and Denial Of Service (DOS). This category of attacks is particularly interesting as it involves abusing the characteristics of the HTTP protocol to manipulate and craft malicious requests that the server will misinterpret, creating desynchronizations between the frontend and the backend. In this paper, we present the first taxonomy of request smuggling attacks in HTTP/3. Specifically, we focus on conversion and validation issues observed in HTTP/2 that can persist in HTTP/3 environments. Since these attacks depend on how proxies parse incoming requests, we also present a methodology to discover possible header validation issues that can cause request smuggling in proxies and frameworks. Finally, we apply this methodology to four proxies and a Python framework, finding various incoherences in their ways to parse malformed requests. Our work aims to underscore the importance of vigilance in current and future applications utilizing HTTP/3 protocols to mitigate potential security risks. Despite the limited availability of libraries and frameworks supporting HTTP/3 at the present moment, its rapid adoption calls for consideration and analysis of its security. Lorenzo Pisu, Federico Loi, Davide Maiorca, Giorgio Giacinto |
NCA | 1 |
| 2024 | Bringing Binary Exploitation at Port 80: Understanding C Vulnerabilities in WebAssemblyabstractWebAssembly (Wasm) has emerged as a novel approach for integrating binaries into web applications starting from various programming languages such as C, Rust and Python. Despite the numerous claims about its memory safety, issues such as buffer overflow, format strings, use after free, and integer overflow have resurfaced within Wasm. These vulnerabilities can be used to impact web application security, potentially leading to critical issues like Cross-Site Scripting (XSS) and Remote Code Execution (RCE). Our work aims to demonstrate how memory-related vulnerabilities in C codes, when compiled into Wasm, can be exploited for XSS and RCE. Our methodology proposes proof of concepts related to exploiting important stack- and heap-based vulnerabilities. In particular, we demonstrate for the first time that specific vulnerabilities (such as format string) can be effectively employed to achieve arbitrary read and write in Wasm contexts. Our results pose serious concerns about the reliability of Wasm in terms of memory safety, which we believe should be addressed in the next releases. Emmanuele Massidda, Lorenzo Pisu, Davide Maiorca, Giorgio Giacinto |
SECRYPT | 2 |