Skip to main content
This page aggregates cross-platform resources to practice File Upload Vulnerabilities: retired Hack The Box machines, PortSwigger Web Security Academy labs and TryHackMe rooms, plus curated resources (HackTricks, PortSwigger, etc.) and related skills. Coverage: 28 challenges across 3 platforms — 16 HackTheBox · 8 PortSwigger · 4 TryHackMe. 16 with a Spanish writeup, 16 with a video writeup.

Where to start

Ordered by actual difficulty. At the same level: isolated lab first, then the guided room, and the full machine last.
  1. PortSwiggerRemote code execution via web shell upload (Apprentice) · 🇬🇧
  2. PortSwiggerWeb shell upload via Content-Type restriction bypass (Apprentice) · 🇬🇧
  3. PortSwiggerWeb shell upload via race condition (Apprentice) · 🇬🇧
  4. TryHackMe25 Days of Cyber Security (Easy · ~45 min) · 🇬🇧
  5. TryHackMeAdvent of Cyber 2 [2020] (Easy · ~45 min) · 🇬🇧
  6. TryHackMeAdvent of Cyber 2022 (Easy · ~1440 min) · 🇬🇧

Curated resources

HTB machines practicing File Upload Vulnerabilities (16)

PortSwigger labs practicing File Upload Vulnerabilities (8)

TryHackMe rooms practicing File Upload Vulnerabilities (4)


Back to the full glossary Last updated: 2026-08-17