Skip to main content
This page aggregates cross-platform resources to practice Prototype Pollution: retired Hack The Box machines, PortSwigger Web Security Academy labs and TryHackMe rooms, plus curated resources (HackTricks, PortSwigger, etc.) and related skills. Coverage: 11 challenges across 3 platforms — 1 HackTheBox · 9 PortSwigger · 1 TryHackMe. 1 with a Spanish writeup, 1 with a video writeup.

Where to start

Ordered by actual difficulty. At the same level: isolated lab first, then the guided room, and the full machine last.
  1. PortSwiggerExfiltrating sensitive data via server-side prototype pollution (Apprentice) · 🇬🇧
  2. TryHackMeCustom Tooling Using Python (Easy · ~60 min) · 🇬🇧
  3. PortSwiggerBypassing flawed input filters for server-side prototype pollution (Practitioner) · 🇬🇧
  4. PortSwiggerClient-side prototype pollution in third-party libraries (Practitioner) · 🇬🇧
  5. PortSwiggerClient-side prototype pollution via flawed sanitization (Practitioner) · 🇬🇧
  6. PortSwiggerDetecting server-side prototype pollution without polluted property reflection (Practitioner) · 🇬🇧

Curated resources

HTB machines practicing Prototype Pollution (1)

PortSwigger labs practicing Prototype Pollution (9)

TryHackMe rooms practicing Prototype Pollution (1)


Back to the full glossary Last updated: 2026-08-13