Skip to main content
This page aggregates cross-platform resources to practice HTTP Request Smuggling: retired Hack The Box machines, PortSwigger Web Security Academy labs and TryHackMe rooms, plus curated resources (HackTricks, PortSwigger, etc.) and related skills. Coverage: 20 challenges across 3 platforms — 1 HackTheBox · 16 PortSwigger · 3 TryHackMe. 1 with a Spanish writeup, 1 with a video writeup.

Where to start

Ordered by actual difficulty. At the same level: isolated lab first, then the guided room, and the full machine last.
  1. PortSwigger0.CL request smuggling (Apprentice) · 🇬🇧
  2. PortSwiggerExploiting HTTP request smuggling to perform web cache deception (Apprentice) · 🇬🇧
  3. PortSwiggerExploiting HTTP request smuggling to perform web cache poisoning (Apprentice) · 🇬🇧
  4. TryHackMeHTTP Request Smuggling (Easy · ~60 min) · 🇬🇧
  5. PortSwiggerExploiting HTTP request smuggling to bypass front-end security controls, CL.TE vulnerability (Practitioner) · 🇬🇧
  6. PortSwiggerExploiting HTTP request smuggling to bypass front-end security controls, TE.CL vulnerability (Practitioner) · 🇬🇧

Curated resources

HTB machines practicing HTTP Request Smuggling (1)

PortSwigger labs practicing HTTP Request Smuggling (16)

TryHackMe rooms practicing HTTP Request Smuggling (3)


Back to the full glossary Last updated: 2026-08-17