Skip to main content
This page aggregates cross-platform resources to practice Buffer Overflow (BoF / ROP): retired Hack The Box machines, PortSwigger Web Security Academy labs and TryHackMe rooms, plus curated resources (HackTricks, PortSwigger, etc.) and related skills. Coverage: 20 challenges across 2 platforms β€” 12 HackTheBox Β· 8 TryHackMe. 12 with a Spanish writeup, 13 with a video writeup.

Where to start

Ordered by actual difficulty. At the same level: isolated lab first, then the guided room, and the full machine last.
  1. TryHackMe β€” Advent of Cyber 2023 (Easy Β· ~1440 min) Β· πŸ‡¬πŸ‡§
  2. TryHackMe β€” Buffer Overflows (Easy Β· ~45 min) Β· πŸ‡¬πŸ‡§ πŸ“Ή
  3. TryHackMe β€” Flag Vault (Easy Β· ~45 min) Β· πŸ‡¬πŸ‡§
  4. TryHackMe β€” Intro To Pwntools (Easy Β· ~45 min) Β· πŸ‡¬πŸ‡§
  5. TryHackMe β€” Sudo Buffer Overflow (Info Β· ~30 min) Β· πŸ‡¬πŸ‡§
  6. HackTheBox β€” Buff (FΓ‘cil) Β· πŸ‡ͺπŸ‡Έ πŸ‡¬πŸ‡§ πŸ“Ή

Curated resources

HTB machines practicing Buffer Overflow (BoF / ROP) (12)

TryHackMe rooms practicing Buffer Overflow (BoF / ROP) (8)


← Back to the full glossary Last updated: 2026-08-13