Skip to main content
This page aggregates cross-platform resources to practice SSTI (Server-Side Template Injection): retired Hack The Box machines, PortSwigger Web Security Academy labs and TryHackMe rooms, plus curated resources (HackTricks, PortSwigger, etc.) and related skills. Coverage: 24 challenges across 3 platforms — 12 HackTheBox · 7 PortSwigger · 5 TryHackMe. 12 with a Spanish writeup, 12 with a video writeup.

Where to start

Ordered by actual difficulty. At the same level: isolated lab first, then the guided room, and the full machine last.
  1. PortSwiggerServer-side template injection in a sandboxed environment (Apprentice) · 🇬🇧
  2. PortSwiggerServer-side template injection with a custom exploit (Apprentice) · 🇬🇧
  3. TryHackMeOWASP Top 10 2025: Insecure Data Handling (Easy · ~30 min) · 🇬🇧
  4. HackTheBoxDoctor (Fácil) · 🇪🇸 🇬🇧 📹
  5. HackTheBoxGoodGames (Fácil) · 🇪🇸 🇬🇧 📹
  6. HackTheBoxLate (Fácil) · 🇪🇸 🇬🇧 📹

Curated resources

HTB machines practicing SSTI (Server-Side Template Injection) (12)

PortSwigger labs practicing SSTI (Server-Side Template Injection) (7)

TryHackMe rooms practicing SSTI (Server-Side Template Injection) (5)


Back to the full glossary Last updated: 2026-08-17