Code IconOggetto's Portfolio

Blog

My silly little corner of the internet where I write about random things

How We Owned Every FantaSanremo Account in 2 HTTP Requests
Security
NoSQL Injection

How We Owned Every FantaSanremo Account in 2 HTTP Requests

March 2, 2026

A NoSQL injection in AppFactory's shared auth code hit the entire Fanta suite: FantaSanremo, FantaMasterChef, FantaOlimpiadi, FantaGiro. Any account, any platform, 0-click.

Read article
How We Broke McDonald's Italy From the Inside Out
Security
Reverse Engineering

How We Broke McDonald's Italy From the Inside Out

February 27, 2026

An in-depth write-up on automating the anniversary Snake game, reversing client-side validation, and uncovering major auth and WebView bridge flaws.

Fix 'Failed to Open \efi\ubuntu\' GRUB Error on Linux Mint
Guide
Linux Mint
GRUB

Fix 'Failed to Open \efi\ubuntu\' GRUB Error on Linux Mint

January 18, 2026

Step-by-step guide to resolve GRUB bootloader failures on older Linux Mint systems by reinstalling without UEFI Secure Boot.

Read article
The Magic Behind ShowHiddenChannels: How Discord Accidentally Reveals Everything
Discord
Security
Technical

The Magic Behind ShowHiddenChannels: How Discord Accidentally Reveals Everything

January 13, 2026

ShowHiddenChannels works because Discord sends all channels to your client by default. A simple permission override reveals them all.

Read article
How to get your Genshin Impact UID without opening the game
Guide
Genshin Impact

How to get your Genshin Impact UID without opening the game

January 11, 2026

Retrieve your UID directly from the browser using developer tools without needing to launch the full game client.

Read article
Free Nuggets
Reverse Engineering
Exploit
Security
Free Food

Free Nuggets

November 23, 2025

How a team reverse-engineered a fast-food game, exploited client-side logic for immortal runs, and still won a year of free nuggets.