Where to start
Ordered by actual difficulty. At the same level: isolated lab first, then the guided room, and the full machine last.- PortSwigger — Exfiltrating sensitive data via server-side prototype pollution (Apprentice) · 🇬🇧
- TryHackMe — Custom Tooling Using Python (Easy · ~60 min) · 🇬🇧
- PortSwigger — Bypassing flawed input filters for server-side prototype pollution (Practitioner) · 🇬🇧
- PortSwigger — Client-side prototype pollution in third-party libraries (Practitioner) · 🇬🇧
- PortSwigger — Client-side prototype pollution via flawed sanitization (Practitioner) · 🇬🇧
- PortSwigger — Detecting server-side prototype pollution without polluted property reflection (Practitioner) · 🇬🇧
Curated resources
HTB machines practicing Prototype Pollution (1)
PortSwigger labs practicing Prototype Pollution (9)
TryHackMe rooms practicing Prototype Pollution (1)
← Back to the full glossary Last updated: 2026-08-13