> ## Documentation Index
> Fetch the complete documentation index at: https://rootea.es/llms.txt
> Use this file to discover all available pages before exploring further.

# NahamStore

> In this room you will learn the basics of bug bounty hunting and web application hacking

# NahamStore

<p className="machine-summary"><span className="prompt"><code>\$ tldr</code></span> TryHackMe · Challenge · Medium</p>

<div className="machine-meta">
  | ·            | ·                                                  |
  | ------------ | -------------------------------------------------- |
  | Plataforma   | TryHackMe                                          |
  | Tipo         | Challenge                                          |
  | Dificultad   | <span className="dbadge dbadge-easy">MEDIUM</span> |
  | Acceso       | 🟢 Free                                            |
  | Tiempo medio | 75 min                                             |
  | Usuarios     | 21.192                                             |
  | Sala oficial | [Abrir](https://tryhackme.com/room/nahamstore)     |
</div>

## Descripción

In this room you will learn the basics of bug bounty hunting and web application hacking

## Resolver la room

| Idioma  | Autor         | Formato     | Enlace                                         |
| ------- | ------------- | ----------- | ---------------------------------------------- |
| 🇬🇧 EN | **TryHackMe** | Lab oficial | [Abrir](https://tryhackme.com/room/nahamstore) |

## Recursos por skill

| Skill                             | Fuente               | Enlace                                                                                      |
| --------------------------------- | -------------------- | ------------------------------------------------------------------------------------------- |
| CSRF (Cross-Site Request Forgery) | PortSwigger          | [Abrir](https://portswigger.net/web-security/csrf)                                          |
| Local File Inclusion (LFI)        | HackTricks           | [Abrir](https://book.hacktricks.wiki/en/pentesting-web/file-inclusion/index.html)           |
| Local File Inclusion (LFI)        | PayloadsAllTheThings | [Abrir](https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/File%20Inclusion)   |
| Remote Code Execution (RCE)       | HackTricks           | [Abrir](https://book.hacktricks.wiki/en/pentesting-web/command-injection.html)              |
| Cross-Site Scripting (XSS)        | HackTricks           | [Abrir](https://book.hacktricks.wiki/en/pentesting-web/xss-cross-site-scripting/index.html) |
| Cross-Site Scripting (XSS)        | PortSwigger          | [Abrir](https://portswigger.net/web-security/cross-site-scripting)                          |
| XML External Entity               | HackTricks           | [Abrir](https://book.hacktricks.wiki/en/pentesting-web/xxe-xee-xml-external-entity.html)    |

## Skills relacionadas

[CSRF (Cross-Site Request Forgery)](/skills/csrf) · [Local File Inclusion (LFI)](/skills/lfi) · [Remote Code Execution (RCE)](/skills/rce) · [Cross-Site Scripting (XSS)](/skills/xss) · [XML External Entity](/skills/xxe)

***

## Comentarios y truquillos

¿Has resuelto la room por una vía distinta? Compártela aquí — los comentarios viven en [GitHub Discussions](https://github.com/FFuson/HTB_Writeups/discussions).

<div className="rootea-giscus-wrap" data-giscus-term="thm:tryhackme-nahamstore" data-giscus-lang="es" />

*Última actualización: 2026-05-09*

<script type="application/ld+json">
  {`{"@context":"https://schema.org","@type":"TechArticle","name":"NahamStore","headline":"NahamStore — TryHackMe room index","url":"https://rootea.es/tryhackme/rooms/nahamstore","inLanguage":"es","about":[{"@type":"Thing","name":"TryHackMe"},{"@type":"Thing","name":"Challenge"}],"isPartOf":{"@type":"WebSite","name":"rootea.es","url":"https://rootea.es"},"author":{"@type":"Organization","name":"rootea.es"}}`}
</script>
