Write-ups & Articles
Feedback on CTFs, Hack The Box machines, API penetration testing and security best practices.
Medium — @lebonson237
● Featured articleFind my long-form analyses on Medium — AI offensive security, LLM Red Team, RAG & compliance. The featured article is also available here in the blog, with embedded YouTube demo.
Why Your Annual Pentest Missed Your AI Completely
Your report is green. All boxes are ticked. Yet it tested none of your AI vulnerabilities. Why traditional pentests are blind to AI — LIVE demos, Cobalt 2026 stats, EU AI Act and a 7-point checklist.
TraceBash CTF 2026 — Story of a Solo Top 18%
24 hours of competition, 12 challenges solved, 1200 points and a top 18% worldwide. Feedback on my solo participation in TraceBash CTF 2026 under the pseudonym TH3 PH03N1X.
HTB Connected — SQLi on FreePBX to Root Access (CVE-2025-57819)
Write-up of the Connected machine from Hack The Box. Exploiting a SQL injection (CVE-2025-57819) on FreePBX, command execution via Cron, abusing the incrond daemon and DAHDI poisoning for definitive root access.
HTB Reactor — From Web to Root via Node.js Inspector RCE
Complete write-up of the Reactor machine from Hack The Box. Initial access via web application, SQLite enumeration, credential reuse and privilege escalation by abusing the Node.js Inspector service leading to RCE.
Securing Your REST/GraphQL APIs — Essential Best Practices
BOLA, injections, IDOR, weak authentication… An overview of the most common API vulnerabilities (tested on CRAPI, VAPI, DVGA) and the fixes to implement on the development side.