Skip to main content
This page aggregates cross-platform resources to practice Remote Code Execution (RCE): retired Hack The Box machines, PortSwigger Web Security Academy labs and TryHackMe rooms, plus curated resources (HackTricks, PortSwigger, etc.) and related skills. Coverage: 222 challenges across 3 platforms — 104 HackTheBox · 15 PortSwigger · 103 TryHackMe. 104 with a Spanish writeup, 106 with a video writeup.

Where to start

Ordered by actual difficulty. At the same level: isolated lab first, then the guided room, and the full machine last.
  1. PortSwigger2FA bypass using a brute-force attack (Apprentice) · 🇬🇧
  2. PortSwiggerBroken brute-force protection, multiple credentials per request (Apprentice) · 🇬🇧
  3. PortSwiggerDOM XSS in document.write sink using source location.search (Apprentice) · 🇬🇧
  4. PortSwiggerDOM XSS in innerHTML sink using source location.search (Apprentice) · 🇬🇧
  5. PortSwiggerDOM XSS in jQuery anchor href attribute sink using location.search source (Apprentice) · 🇬🇧 📹
  6. PortSwiggerFlawed enforcement of business rules (Apprentice) · 🇬🇧

Curated resources

HTB machines practicing Remote Code Execution (RCE) (104)

PortSwigger labs practicing Remote Code Execution (RCE) (15)

TryHackMe rooms practicing Remote Code Execution (RCE) (103)

Showing 50 of 103. The full catalog has the rest.
Back to the full glossary Last updated: 2026-08-17