Security isn’t a list of payloads to memorise. The useful skill is learning how a system is meant to work, noticing the assumptions it makes, and knowing where to push to break those assumptions.
That’s how I build Uphack. Every lab starts as a believable product with one realistic security flaw buried in an ordinary feature.
I still build every lab myself. Keeping early access small means I can stay close to the people, see where the teaching falls short, and make the next lab better.
Uphack is for people who want to understand why vulnerabilities exist, not just memorise how to exploit them. If you’d like to join:
I’ll send your invitation by email and occasionally let you know when a new lab is ready.