<blog/>

Write-ups & Articles

Feedback on CTFs, Hack The Box machines, API penetration testing and security best practices.

M

Medium — @lebonson237

● Featured article

Find my long-form analyses on Medium — AI offensive security, LLM Red Team, RAG & compliance. The featured article is also available here in the blog, with embedded YouTube demo.

#IA#Pentest#LLM Security#OWASP
📄 Read portfolio version → · Pourquoi votre pentest annuel n'a rien vu sur votre IA
All#thoughts#ctf#writeup#tutorial
📡
LOG // 202612 min
📅 September 6, 2026• ⏱️ 12 min

Why Your Annual Pentest Missed Your AI Completely

Your report is green. All boxes are ticked. Yet it tested none of your AI vulnerabilities. Why traditional pentests are blind to AI — LIVE demos, Cobalt 2026 stats, EU AI Act and a 7-point checklist.

⬢ Medium#AI#Pentest#LLM Security
Read article
📡
LOG // 20267 min
📅 June 28, 2026• ⏱️ 7 min

TraceBash CTF 2026 — Story of a Solo Top 18%

24 hours of competition, 12 challenges solved, 1200 points and a top 18% worldwide. Feedback on my solo participation in TraceBash CTF 2026 under the pseudonym TH3 PH03N1X.

#CTF#OSINT#Crypto#Forensics
Read article
📡
LOG // 202614 min
📅 June 22, 2026• ⏱️ 14 min

HTB Connected — SQLi on FreePBX to Root Access (CVE-2025-57819)

Write-up of the Connected machine from Hack The Box. Exploiting a SQL injection (CVE-2025-57819) on FreePBX, command execution via Cron, abusing the incrond daemon and DAHDI poisoning for definitive root access.

#HTB#SQLi#FreePBX#CVE-2025-57819
Read article
📡
LOG // 202612 min
📅 June 20, 2026• ⏱️ 12 min

HTB Reactor — From Web to Root via Node.js Inspector RCE

Complete write-up of the Reactor machine from Hack The Box. Initial access via web application, SQLite enumeration, credential reuse and privilege escalation by abusing the Node.js Inspector service leading to RCE.

#HTB#Web#Node.js#RCE
Read article
📡
LOG // 202611 min
📅 April 15, 2026• ⏱️ 11 min

Securing Your REST/GraphQL APIs — Essential Best Practices

BOLA, injections, IDOR, weak authentication… An overview of the most common API vulnerabilities (tested on CRAPI, VAPI, DVGA) and the fixes to implement on the development side.

#API#Security#OWASP#BOLA
Read article