Now accepting early access signups

Spot vulnerabilities faster by practicing on real-world apps

Uphack gives you hands-on labs in realistic apps so you can recognize vulnerability patterns, exploit them as an attacker, and fix them as a developer.

After confirming your email, I’ll follow up personally before sending an invitation.
A Uphack lab open in the browser, showing a realistic application alongside the guided investigation panel
Darius Giurgiu
Frontend Developer

I've taken many courses before, but none with this level of attention to detail. The labs build up your intuition step by step, and the explanations are incredibly thorough. It's clear a lot of thought went into making complex security principles not just understandable, but intuitive.

Deepika Vasudevan
Senior Security Engineer

I got the chance to preview the content and was immediately impressed by the depth of explanation. It's rare to find material that not only shows you how security vulnerabilities work, but dives deep into why they exist and how to think about them.

Let’s face it - getting real practice in application security is hard. Not the challenging kind of hard, but the frustrating kind of hard...

The problem

Security vulnerabilities follow patterns. The same broken access controls, the same output encoding issues, the same injection flaws — they show up in every codebase, every pentest, every bug bounty program.

But most security training platforms don't teach you to see patterns. You either get theory-heavy courses that explain vulnerabilities in isolation, or CTF challenges on toy apps that look nothing like production software. One teaches you about security. The other tests you on puzzles. Neither builds real security intuition.

The security education model is broken. It focuses too much on competition and puzzle-solving rather than helping you develop the pattern recognition that actually helps you identify critical vulnerabilities. That's why I built Uphack.

The solution

Uphack is a hands-on lab platform built around the vulnerability patterns that cause real-world breaches.

Every lab drops you into a realistic, production-quality application — an app that looks and behaves like something you'd actually encounter in the field. Not a CTF challenge. Not a deliberately broken demo.

You'll see the same vulnerability pattern across different features and applications. A broken access control in a real estate platform. The same pattern in a multi-tenant SaaS app. And again in a payment flow. Different context, same underlying flaw, until spotting it becomes second nature.

I don't walk you through a procedure to memorize. I teach you how to think about the vulnerability: what to look for, why the flaw exists, and what made the developer introduce it in the first place. You're building mental models you can carry into other applications.

Marius Horatau
Marius Horatau

What's inside

Deep dives across every web attack surface

I've organized the labs around the attack surfaces you'll encounter in real applications: auth/z, server-side, client-side, and browser security. Each topic goes deep, with multiple labs across different app contexts, so you're not just learning a vulnerability once — you're training yourself to recognize it wherever it shows up.

I don't skip over the hard parts. I break them down, explain the "why" behind each vulnerability, and help you build security intuition you can use outside Uphack.

// Module 01

Welcome (start here)

Introduction to Uphack
Think like a hacker! But how?!
A mental model for learning application security

// Module 02

Authentication & authorization

Authentication in Web Applications
Server Side Authentication
Client Side Authentication
Authentication In Practice
Authorization in Web Applications
Authorization in Practice

// Module 03

Server-side security

Server-side as an attack surface
Injection vulnerabilities
Open Redirect
SQL Injection
XXE Injection
Directory Traversal
Command Injection
...plus 1 other lesson

// Module 04

Browser security

Introduction to browser security
Browser sandbox
Site isolation
Same origin policy
Cross Origin Resource Sharing (CORS)
The great Same-Origin Policy confusion
Let's talk cookie security
The iframe security model

// Module 05

Client-side security

Client-side as an attack surface
Cross-Site Scripting (XSS)
Cross-Site Request Forgery (CSRF)
The pitfalls of the cookie security model

...and much more content to come!

I'm continuously adding new labs and attack surfaces. Early-access members can explore them as they ship.

Here's what I'm working on next:

Module 6
Coming soon
HTTP Middleware Security
Module 7
Coming soon
API Security
Module 8
Coming soon
Secure Coding
Module 9
Coming soon
Testing methodology
Module 10
Coming soon
Communicating Security
Module 11
Coming soon
Interviewing Preparation
Early access is open
Start learning now

What to expect

Structured learning that combines theory, practice, and interactive exercises. Carefully designed to help you build in-depth expertise.

An Uphack lesson open in the reader

45+

Lessons

A hands-on lab environment running in the browser

25+

Hands-on Labs

An interactive exercise with inline answer checking

45+

Interactive Exercises

Interactive learning

Uphack lessons feature bite-sized, interactive exercises designed to reinforce key concepts. These visual exercises make complex ideas feel intuitive, sparking those “Aha” moments before hitting the labs.

Watch an exercise walkthrough video
An Uphack exercise, with the question and answer checks laid out step by step

Uphack Labs

Every lab spins up an isolated, realistic web app, just for you. Find the vulnerability, exploit it, and understand the pattern.

A Uphack lab open in the browser, showing the vulnerable application next to the lab instructions

Everything you need, in your browser

Uphack Labs redefine convenience in AppSec learning. With an integrated in-page browser, you have instant access to all essential tools—without ever leaving the platform. No complex setups, no VPN, no bullshit.

Built-in proxy interceptor
SSH Access
Integrated code editor
Real-world vulnerable apps
Corina
Corina Anton
Software Engineer

The platform UI is brilliantly designed. It's clean, easy to navigate, and has everything you need in one place, which honestly makes learning so smooth and enjoyable. It’s a game-changer in security education.

Step-by-step instructions

Each lab comes with step by step instructions to guide you through the hands-on exercise and help you make the most of it.

Step-by-step lab instructions guiding the learner through a hands-on exercise

Built-In Proxy

Analysing requests is essential when learning security. Uphack makes it easy to view and modify requests with its embedded proxy interceptor.

Uphack's built-in proxy interceptor showing a captured HTTP request ready to modify

Questions?

I'm glad you asked.

Can’t find the answer you’re looking for? Email me at [email protected] and I'll get back to you.