Practice Labs
Reading about a vulnerability only gets you so far — these are established, well-regarded platforms where you can practice finding and exploiting the vulnerabilities covered in our lessons, safely and legally.
Only test against these platforms' own designated targets, in line with each platform's own terms of use — see our Disclaimer for why authorization always matters, even in a "practice" context.
PortSwigger Web Security Academy ↗
Free, extensive hands-on labs covering nearly every vulnerability class on this site, built by the makers of Burp Suite. The best starting point for structured, guided practice.
OWASP Juice Shop ↗
A deliberately vulnerable modern web application you can run locally or self-host. Covers the OWASP Top 10 and beyond, with challenge tracking built in.
TryHackMe ↗
Guided, beginner-friendly rooms covering web security and broader offensive security topics, with browser-based lab environments — no local setup required.
Hack The Box ↗
More advanced, less hand-held practice targets — a good next step once you're comfortable with fundamentals and want realistic, CTF-style challenges.
DVWA (Damn Vulnerable Web Application) ↗
A classic, self-hosted PHP/MySQL vulnerable app with adjustable difficulty levels — good for practicing the same vulnerability at different levels of defense.
PentesterLab ↗
Focused, exercise-based lessons that pair a short explanation with a real vulnerable target — strong for building testing methodology, not just theory.
Root Me ↗
A large catalog of challenges spanning web security and many other security disciplines, with a strong community and write-up culture.