Articles

Ubuntu Server : Récupérer un accès Root perdu en 5 minutes

Image
  Récupération de mot de passe sur Ubuntu Server Perdre l'accès à un compte serveur n'est pas une catastrophe à condition de savoir comment le système démarre et comment fonctionnent les mécanismes de récupération privilégiés. Sur Ubuntu Server, il arrive qu'un mot de passe local soit oublié ou perdu. Dans un environnement autorisé, le bootloader GRUB et le mode recovery d'Ubuntu permettent de reprendre l'accès administrateur. Cette procédure est utile sur serveurs physiques, machines virtuelles, homelabs et infrastructures isolées, dès lors qu'un accès console est disponible. 1. Redémarrer la machine Redémarrez le serveur (physique ou VM sous VMware, VirtualBox, Hyper-V, Proxmox...). En environnement distant, un accès console ou à la console virtuelle de l'hyperviseur est nécessaire. 2. Accéder au menu GRUB Pendant le démarrage, appuyez sur Échap (ou Shift sur certains systèmes). Le timing dépend du matériel et du firmware. Vous devriez voir : Ubu...

🐝 Inside Hive: Construire un Honeypot Événementiel Haute Performance pour le Threat Intelligence en Temps Réel

Image
  🛡️ Hive: Engineering a Real-Time Honeypot Network for Modern Threat Intelligence 🐝 What if your security infrastructure could turn attackers into a source of intelligence ? That was the idea behind Hive , an enterprise-grade, event-driven honeypot platform I built from the ground up to attract, isolate, observe, and analyze malicious activity in real time . Rather than building a simple honeypot that waits for attackers, I designed Hive as a high-concurrency security platform capable of processing thousands of attack events while continuously transforming raw attacker activity into actionable threat intelligence. Here are some of the engineering decisions behind it: ⚡ High-Performance Backend  Go 🔹 Asynchronous Event-Driven Architecture I designed a non-blocking event pipeline using Go goroutines, channels, and an event bus , allowing network listeners to remain responsive while attack events are processed asynchronously. 🔹 Low-Level Protocol Emulation Instead of relyi...

IRONSTACK : Automatisation, validation applicative profonde et CI/CD Local pour infrastructures sécurisées.

Image
  ⚙️ Bâtir un Framework d'Automatisation Hardened Sans Cloud : Les Coulisses d'IRONSTACK  À l'ère du tout-cloud, une idée fausse persiste : une infrastructure moderne, agile et hautement automatisée devrait nécessairement dépendre d'un fournisseur managé tiers (AWS, Azure ou GCP). Pourtant, dans les secteurs à fortes contraintes de sécurité où la souveraineté des données, l'isolation réseau et la conformité GRC sont absolues le cloud n'est tout simplement pas une option. Pour répondre à ce cas d'usage critique, j'ai relevé un défi de 3 jours : concevoir et déployer IRONSTACK, une mini-production On-Premise durcie dotée d'un orchestrateur intelligent et d'une validation de santé automatisée, le tout tournant entièrement sur du hardware local (Homelab). Pour ce projet j'ai construit l'infrastructure et la couche de contrôle logiciel qui permettent de la valider et de la déployer de manière ultra-fiable. 🧭 Contexte et Principes d'Archit...

Most Companies Trust Their Supply Chain… Until AXIOS Got Compromised

Image
Hook — Trust Has Become an Attack Surface In modern development, speed is everything. We assemble, import, and deploy. A single line of code can pull in thousands of dependencies… without ever being truly audited. The reality is: we no longer trust code, we trust the ecosystem that delivers it . And that’s exactly where attackers have found their playground. A compromised supply chain doesn’t break an application. It breaks a trust model. The AXIOS incident on March 31, 2026 is a near-perfect example of this new generation of attacks: fast, silent, and dangerously effective. The Incident — 3 Hours Were Enough On March 31, 2026, a discreet but critical event unfolded in the NPM ecosystem. What we know Maintainer account compromised: jasonsaayman Affected packages: axios@1.14.1 axios@0.30.4 Malicious dependency injected: plain-crypto-js@4.2.1 Payload: Cross-platform RAT executed via a postinstall script Exposure window: ≈ 3 hours before removal Like...

Anonymous and the DRC: The Untold History of a Cyberwar for Congo’s Minerals

Image
The digital age, defined by sleek smartphones and high-capacity electric vehicle batteries, rests upon a foundation of rare earth elements extracted from some of the most volatile regions on Earth. At the heart of this global supply chain lies the Democratic Republic of the Congo (DRC). While the physical struggle for control over these resources—coltan, cobalt, and cassiterite—is well-documented through decades of armed conflict, a parallel, invisible war has been unfolding in the digital shadows. This is the story of Operation Coltan , a decentralized campaign led by the hacktivist collective Anonymous . It represents a modern convergence of cybersecurity and geopolitical activism, where lines of code are used as weapons to protest the perceived complicity of multinational corporations in the exploitation of Congolese mineral wealth. 1. The Pulse of the Digital World: Congo’s Strategic Minerals The Democratic Republic of the Congo holds more than 70% of the world’s coltan reserves an...

After Reading Ethical Hacking, Here’s What Every Security Engineer Should Realize

Image
  After reading Ethical Hacking: A Hands-on Introduction to Breaking In by Daniel G. Graham , one idea became very clear to me: Security is not about installing tools. It is about understanding attack logic. In a time where organizations invest heavily in firewalls, EDRs, SIEMs, and AI-driven detection platforms, we sometimes forget something fundamental: if we do not understand how an attacker thinks, we are only reacting — not anticipating. This book reinforced that reality for me. Ethical Hacking Is About Method, Not Ego The book follows a structured path: Reconnaissance Scanning and enumeration Exploitation Post-exploitation At first glance, this looks simple. Almost basic. But here is what every security engineer should realize: Most real-world breaches still follow this exact logic. The tools may change. The automation may evolve. AI may accelerate reconnaissance. But the structure of intrusion remains consistent. What I appreciated in this book is t...