Skip to main content
This page aggregates cross-platform resources to practice Server-Side Request Forgery: retired Hack The Box machines, PortSwigger Web Security Academy labs and TryHackMe rooms, plus curated resources (HackTricks, PortSwigger, etc.) and related skills. Coverage: 25 challenges across 3 platforms — 10 HackTheBox · 11 PortSwigger · 4 TryHackMe. 10 with a Spanish writeup, 10 with a video writeup.

Where to start

Ordered by actual difficulty. At the same level: isolated lab first, then the guided room, and the full machine last.
  1. PortSwiggerBasic SSRF against another back-end system (Apprentice) · 🇬🇧
  2. PortSwiggerBasic SSRF against the local server (Apprentice) · 🇬🇧
  3. PortSwiggerBlind SSRF with Shellshock exploitation (Apprentice) · 🇬🇧
  4. PortSwiggerExploiting XXE to perform SSRF attacks (Apprentice) · 🇬🇧
  5. PortSwiggerSSRF with whitelist-based input filter (Apprentice) · 🇬🇧
  6. TryHackMeAdvent of Cyber 2023 (Easy · ~1440 min) · 🇬🇧

Curated resources

HTB machines practicing Server-Side Request Forgery (10)

PortSwigger labs practicing Server-Side Request Forgery (11)

TryHackMe rooms practicing Server-Side Request Forgery (4)


Back to the full glossary Last updated: 2026-08-17