Where to start
Ordered by actual difficulty. At the same level: isolated lab first, then the guided room, and the full machine last.- PortSwigger — Manipulating WebSocket messages to exploit vulnerabilities (Apprentice) · 🇬🇧
- PortSwigger — Manipulating the WebSocket handshake to exploit vulnerabilities (Practitioner) · 🇬🇧
- TryHackMe — AWS API Gateway (Medium · ~50 min) · 🇬🇧
- TryHackMe — Request Smuggling: WebSockets (Medium · ~30 min) · 🇬🇧
- HackTheBox — MultiMaster (Insano) · 🇪🇸 🇬🇧 📹
Curated resources
HTB machines practicing WebSockets Vulnerabilities (1)
PortSwigger labs practicing WebSockets Vulnerabilities (2)
TryHackMe rooms practicing WebSockets Vulnerabilities (2)
← Back to the full glossary Last updated: 2026-08-17