Where to start
Ordered by actual difficulty. At the same level: isolated lab first, then the guided room, and the full machine last.- PortSwigger — 2FA bypass using a brute-force attack (Apprentice) · 🇬🇧
- PortSwigger — Broken brute-force protection, multiple credentials per request (Apprentice) · 🇬🇧
- PortSwigger — DOM XSS in document.write sink using source location.search (Apprentice) · 🇬🇧
- PortSwigger — DOM XSS in innerHTML sink using source location.search (Apprentice) · 🇬🇧
- PortSwigger — DOM XSS in jQuery anchor href attribute sink using location.search source (Apprentice) · 🇬🇧 📹
- PortSwigger — Flawed enforcement of business rules (Apprentice) · 🇬🇧
Curated resources
HTB machines practicing Remote Code Execution (RCE) (104)
PortSwigger labs practicing Remote Code Execution (RCE) (15)
TryHackMe rooms practicing Remote Code Execution (RCE) (103)
Showing 50 of 103. The full catalog has the rest.
Related skills
← Back to the full glossary Last updated: 2026-08-17