Skip to main content
This page aggregates cross-platform resources to practice WebSockets Vulnerabilities: retired Hack The Box machines, PortSwigger Web Security Academy labs and TryHackMe rooms, plus curated resources (HackTricks, PortSwigger, etc.) and related skills. Coverage: 5 challenges across 3 platforms — 1 HackTheBox · 2 PortSwigger · 2 TryHackMe. 1 with a Spanish writeup, 1 with a video writeup.

Where to start

Ordered by actual difficulty. At the same level: isolated lab first, then the guided room, and the full machine last.
  1. PortSwiggerManipulating WebSocket messages to exploit vulnerabilities (Apprentice) · 🇬🇧
  2. PortSwiggerManipulating the WebSocket handshake to exploit vulnerabilities (Practitioner) · 🇬🇧
  3. TryHackMeAWS API Gateway (Medium · ~50 min) · 🇬🇧
  4. TryHackMeRequest Smuggling: WebSockets (Medium · ~30 min) · 🇬🇧
  5. HackTheBoxMultiMaster (Insano) · 🇪🇸 🇬🇧 📹

Curated resources

HTB machines practicing WebSockets Vulnerabilities (1)

PortSwigger labs practicing WebSockets Vulnerabilities (2)

TryHackMe rooms practicing WebSockets Vulnerabilities (2)


Back to the full glossary Last updated: 2026-08-17