Where to start
Ordered by actual difficulty. At the same level: isolated lab first, then the guided room, and the full machine last.- PortSwigger — Basic SSRF against another back-end system (Apprentice) · 🇬🇧
- PortSwigger — Basic SSRF against the local server (Apprentice) · 🇬🇧
- PortSwigger — Blind SSRF with Shellshock exploitation (Apprentice) · 🇬🇧
- PortSwigger — Exploiting XXE to perform SSRF attacks (Apprentice) · 🇬🇧
- PortSwigger — SSRF with whitelist-based input filter (Apprentice) · 🇬🇧
- TryHackMe — Advent of Cyber 2023 (Easy · ~1440 min) · 🇬🇧
Curated resources
HTB machines practicing Server-Side Request Forgery (10)
PortSwigger labs practicing Server-Side Request Forgery (11)
TryHackMe rooms practicing Server-Side Request Forgery (4)
Related skills
← Back to the full glossary Last updated: 2026-08-17