Skip to main content
This page aggregates cross-platform resources to practice Authentication Vulnerabilities: retired Hack The Box machines, PortSwigger Web Security Academy labs and TryHackMe rooms, plus curated resources (HackTricks, PortSwigger, etc.) and related skills. Coverage: 33 challenges across 3 platforms β€” 4 HackTheBox Β· 27 PortSwigger Β· 2 TryHackMe. 4 with a Spanish writeup, 4 with a video writeup.

Where to start

Ordered by actual difficulty. At the same level: isolated lab first, then the guided room, and the full machine last.
  1. PortSwigger β€” 2FA bypass using a brute-force attack (Apprentice) Β· πŸ‡¬πŸ‡§
  2. PortSwigger β€” 2FA simple bypass (Apprentice) Β· πŸ‡¬πŸ‡§
  3. PortSwigger β€” Authentication bypass via information disclosure (Apprentice) Β· πŸ‡¬πŸ‡§
  4. PortSwigger β€” Authentication bypass via OAuth implicit flow (Apprentice) Β· πŸ‡¬πŸ‡§
  5. PortSwigger β€” Broken brute-force protection, multiple credentials per request (Apprentice) Β· πŸ‡¬πŸ‡§
  6. PortSwigger β€” Host header authentication bypass (Apprentice) Β· πŸ‡¬πŸ‡§

Curated resources

HTB machines practicing Authentication Vulnerabilities (4)

PortSwigger labs practicing Authentication Vulnerabilities (27)

TryHackMe rooms practicing Authentication Vulnerabilities (2)


← Back to the full glossary Last updated: 2026-08-17