Where to start
Ordered by actual difficulty. At the same level: isolated lab first, then the guided room, and the full machine last.- PortSwigger — Remote code execution via web shell upload (Apprentice) · 🇬🇧
- PortSwigger — Web shell upload via Content-Type restriction bypass (Apprentice) · 🇬🇧
- PortSwigger — Web shell upload via race condition (Apprentice) · 🇬🇧
- TryHackMe — 25 Days of Cyber Security (Easy · ~45 min) · 🇬🇧
- TryHackMe — Advent of Cyber 2 [2020] (Easy · ~45 min) · 🇬🇧
- TryHackMe — Advent of Cyber 2022 (Easy · ~1440 min) · 🇬🇧
Curated resources
HTB machines practicing File Upload Vulnerabilities (16)
PortSwigger labs practicing File Upload Vulnerabilities (8)
TryHackMe rooms practicing File Upload Vulnerabilities (4)
Related skills
← Back to the full glossary Last updated: 2026-08-17