Educating the next generation of ethical hackers.

United Kingdom
Intercepting the HTTP request your browser sends when you chat with an AI assistant. Turns out there's actually a lot you can tamper with. 🤓
1
3
27
1,505
These are the actual prompts you can send when hacking an AI Assistant: 👇
1
1
31
1,076
Having a hard time catching SSRF? Maybe you’re hunting in the wrong places. 🤔 Here's where you should look: 👀
1
2
35
1,225
This is the first and most important thing you should look at when you’re hunting SSRF: 👀
1
7
64
2,551
Stop misidentifying SSRF. Let’s clear things up: 🤓
3
6
64
2,120
🔥
I'm so excited to announce NahamCon's new format this year: #Prompt2Pwn, an in-person conference and live hacking event! 🔥 Keynotes and location details drop later this week. #NahamCon2026
5
729
Web cache deception tricks 🪄 GET /api/me → returns PII Run these to trick the CDN into caching a sensitive endpoint: 🟥 GET /api/me;.css 🟥 GET /api/me/foo.css 🟥 GET /static/..%2fapi/me 🟥 GET /api/me%00.css 🟥 GET /profile%2f%2e%2e%2fstatic Your ideal scenario: the origin ignores the trailing junk (; param, extra path segment, encoded traversal) and returns private data anyway, but the CDN only sees the .css suffix and caches it as static. NOTE: Also try other delimiters, file extensions, and static directories.
1
44
257
9,479
Want to access the /admin panel? Try these variants: 🟥 //admin 🟥 /./admin 🟥 /%2f/admin Didn't work? Add these headers: GET / HTTP/1.1 X-Original-URL: /admin/panel X-Rewrite-URL: /admin Edge/WAF blocks /admin by path rules, the origin may re-route on these headers before your request hits its own auth.
2
12
107
3,139
You can still find success in hunting for stored/blind XSS today. 🥸 Here’s why: 👇
3
4
46
1,711
These 3 bug classes became harder to find. If you’re starting bug bounty today, here’s why you might want to skip learning them and focus on other bug classes instead: 👇
1
3
74
3,100
3 tips to get to a 75% bug bounty report hit rate: 👇
1
4
44
1,841