Where to start
Ordered by actual difficulty. At the same level: isolated lab first, then the guided room, and the full machine last.- PortSwigger — Cache key injection (Apprentice) · 🇬🇧
- PortSwigger — Combining web cache poisoning vulnerabilities (Apprentice) · 🇬🇧
- PortSwigger — Exploiting exact-match cache rules for web cache deception (Apprentice) · 🇬🇧
- PortSwigger — Exploiting HTTP request smuggling to perform web cache deception (Apprentice) · 🇬🇧
- PortSwigger — Exploiting HTTP request smuggling to perform web cache poisoning (Apprentice) · 🇬🇧
- PortSwigger — Exploiting path mapping for web cache deception (Apprentice) · 🇬🇧
Curated resources
PortSwigger labs practicing Web Cache Attacks (Poisoning / Deception) (21)
TryHackMe rooms practicing Web Cache Attacks (Poisoning / Deception) (1)
← Back to the full glossary Last updated: 2026-08-13