Skip to main content
This page aggregates cross-platform resources to practice Web Cache Attacks (Poisoning / Deception): retired Hack The Box machines, PortSwigger Web Security Academy labs and TryHackMe rooms, plus curated resources (HackTricks, PortSwigger, etc.) and related skills. Coverage: 22 challenges across 2 platforms — 21 PortSwigger · 1 TryHackMe. 0 with a Spanish writeup, 0 with a video writeup.

Where to start

Ordered by actual difficulty. At the same level: isolated lab first, then the guided room, and the full machine last.
  1. PortSwiggerCache key injection (Apprentice) · 🇬🇧
  2. PortSwiggerCombining web cache poisoning vulnerabilities (Apprentice) · 🇬🇧
  3. PortSwiggerExploiting exact-match cache rules for web cache deception (Apprentice) · 🇬🇧
  4. PortSwiggerExploiting HTTP request smuggling to perform web cache deception (Apprentice) · 🇬🇧
  5. PortSwiggerExploiting HTTP request smuggling to perform web cache poisoning (Apprentice) · 🇬🇧
  6. PortSwiggerExploiting path mapping for web cache deception (Apprentice) · 🇬🇧

Curated resources

PortSwigger labs practicing Web Cache Attacks (Poisoning / Deception) (21)

TryHackMe rooms practicing Web Cache Attacks (Poisoning / Deception) (1)


Back to the full glossary Last updated: 2026-08-13