Where to start
Ordered by actual difficulty. At the same level: isolated lab first, then the guided room, and the full machine last.- PortSwigger — 0.CL request smuggling (Apprentice) · 🇬🇧
- PortSwigger — Exploiting HTTP request smuggling to perform web cache deception (Apprentice) · 🇬🇧
- PortSwigger — Exploiting HTTP request smuggling to perform web cache poisoning (Apprentice) · 🇬🇧
- TryHackMe — HTTP Request Smuggling (Easy · ~60 min) · 🇬🇧
- PortSwigger — Exploiting HTTP request smuggling to bypass front-end security controls, CL.TE vulnerability (Practitioner) · 🇬🇧
- PortSwigger — Exploiting HTTP request smuggling to bypass front-end security controls, TE.CL vulnerability (Practitioner) · 🇬🇧
Curated resources
HTB machines practicing HTTP Request Smuggling (1)
PortSwigger labs practicing HTTP Request Smuggling (16)
TryHackMe rooms practicing HTTP Request Smuggling (3)
← Back to the full glossary Last updated: 2026-08-17