Where to start
Ordered by actual difficulty. At the same level: isolated lab first, then the guided room, and the full machine last.- PortSwigger — Host header authentication bypass (Apprentice) · 🇬🇧
- PortSwigger — Host validation bypass via connection state attack (Practitioner) · 🇬🇧
- PortSwigger — Routing-based SSRF (Practitioner) · 🇬🇧
- PortSwigger — SSRF via flawed request parsing (Practitioner) · 🇬🇧
- PortSwigger — Web cache poisoning via ambiguous requests (Practitioner) · 🇬🇧
Curated resources
PortSwigger labs practicing HTTP Host Header Attacks (5)
← Back to the full glossary Last updated: 2026-08-13