Skip to main content
This page aggregates cross-platform resources to practice SQL Injection: retired Hack The Box machines, PortSwigger Web Security Academy labs and TryHackMe rooms, plus curated resources (HackTricks, PortSwigger, etc.) and related skills. Coverage: 78 challenges across 3 platforms โ€” 36 HackTheBox ยท 22 PortSwigger ยท 20 TryHackMe. 36 with a Spanish writeup, 36 with a video writeup.

Where to start

Ordered by actual difficulty. At the same level: isolated lab first, then the guided room, and the full machine last.
  1. PortSwigger โ€” Detecting NoSQL injection (Apprentice) ยท ๐Ÿ‡ฌ๐Ÿ‡ง
  2. PortSwigger โ€” Exploiting NoSQL operator injection to bypass authentication (Apprentice) ยท ๐Ÿ‡ฌ๐Ÿ‡ง
  3. PortSwigger โ€” SQL injection vulnerability allowing login bypass (Apprentice) ยท ๐Ÿ‡ฌ๐Ÿ‡ง
  4. PortSwigger โ€” SQL injection vulnerability in WHERE clause allowing retrieval of hidden data (Apprentice) ยท ๐Ÿ‡ฌ๐Ÿ‡ง
  5. TryHackMe โ€” 25 Days of Cyber Security (Easy ยท ~45 min) ยท ๐Ÿ‡ฌ๐Ÿ‡ง
  6. TryHackMe โ€” Advent of Cyber 2 [2020] (Easy ยท ~45 min) ยท ๐Ÿ‡ฌ๐Ÿ‡ง

Curated resources

HTB machines practicing SQL Injection (36)

PortSwigger labs practicing SQL Injection (22)

TryHackMe rooms practicing SQL Injection (20)


โ† Back to the full glossary Last updated: 2026-08-17