// the find
nahamsec/nahamsec.training
The labs for my Udemy course (https://www.udemy.com/course/intro-to-bug-bounty-by-nahamsec)
A deliberately vulnerable PHP app that bundles the labs from Ben Sadeghipour's Intro To Bug Bounty course into one Docker image. Each lab sits on its own subdomain under naham.sec, so you attack it the way you would a real target. It is for people working through the course, or anyone who wants a small, self-contained set of web vulnerabilities to practice on.
- Covers the usual web bug classes in one image: XSS, SQLi, SSRF, XXE, LFI, RCE, file upload, IDOR, CSRF and open redirect, with one controller file per class under app/training/controllers.
- Each lab gets its own hostname (xss1.naham.sec, ssrf7.naham.sec and so on), so you have to deal with host-based routing and scope instead of a single localhost path.
- The codebase is small enough to read end to end. Once you solve a lab you can open the matching controller and see exactly what the bug was.
- Last push was May 2023 and there is no sign of maintenance since. The README doesn't say which PHP or base image version it targets, so the build will drift as upstream images change.
- The README covers setup only. It explains how to build and which hostnames to add, but nothing about the labs themselves, so without the course this is a set of endpoints with no guidance.
- The hosts file is hand-maintained, roughly 30 lines to paste, and a missing line just fails to resolve with no troubleshooting notes. The tree shows no tests or CI, so nothing checks that the labs still work after a change.