Where to practice web hacking legally: 30+ platforms and labs ordered by level — BBLABS, PortSwigger, Hack The Box, TryHackMe, OWASP Juice Shop, Root Me and many more. Honest and useful.
Gorka El Bochi
Founder of BBLABS
Quick answer: The best way to learn web hacking is to practice in legal, deliberately vulnerable environments. To start with real flaws, BBLABS; for free web theory, the PortSwigger Web Security Academy; for boot2root-style machines, Hack The Box and TryHackMe. Below you have 30+ options ordered by level and type, with what each one is good for.
There are dozens of platforms, but not all serve the same purpose. Before the list, three rules:
Let's get to the platforms.
I'll start with my own house because it solves the concrete problem of practicing web bug bounty with real cases: each BBLABS lab reproduces a vulnerability taken from a real public report, you launch it directly in the browser (no machines or Docker to set up) and you go through them in order with the hunter roadmap, from easy to hard without skipping fundamentals. If you're coming from scratch, combine it with the Learn bug bounty path. It's the most direct starting point if your goal is to report real bugs, not just solve academic challenges.
Free and possibly the best web theory resource out there. Made by the people behind Burp Suite. Labs by topic (SQLi, XSS, SSRF, JWT, race conditions...) with increasing difficulty. Essential.
The best-known platform of vulnerable machines. It has guided modules (Academy) and CTF-style machines. More oriented toward systems pentesting, but with a good web portion.
The friendliest option to get started. Step-by-step guided rooms, many free, with explanations included. Ideal if you've never touched a terminal.
Exercises very focused on web and code, with "badges" by topic. Excellent for understanding the why of each flaw, not just the how.
French platform (also in English) with hundreds of short challenges by category: web, cryptography, steganography, forensics. Very good for quick sessions.
Videos + a free CTF from HackerOne. Solving its challenges can earn you invitations to private programs. Built specifically for bug bounty.
Free training material from Bugcrowd: methodology, flaw types and reporting tips. Good for understanding how a platform thinks.
Challenges from the European platform YesWeHack focused on specific web vulnerabilities. Useful and geared toward real bug bounty.
You set these up yourself (Docker or local) and break them without limits. Perfect for tinkering fearlessly:
The quintessential modern vulnerable app (JavaScript). Dozens of challenges with a scoreboard. Maintained by OWASP.
The PHP/MySQL classic. Security levels (low/medium/high) to see how exploitation changes. Ideal for understanding SQLi and XSS from scratch.
Interactive OWASP lessons in Java. More didactic than Juice Shop, with built-in explanations.
"Buggy Web Application": more than 100 catalogued vulnerabilities. A veteran but very complete reference.
A PHP app with flaws mapped directly to the OWASP Top 10. Good for practicing category by category.
A vulnerable site designed to test scanners and practice recon on a realistic store.
A huge repository of downloadable vulnerable machines (VMs) created by the community. Free. You set them up in VirtualBox and go for root.
Carnegie Mellon's educational CTF. Free, with beginner challenges. Very good for fundamentals.
Wargames over SSH and web. Natas is the web series: you learn exploitation logic level by level. Bandit teaches you Linux.
One of the oldest challenge sites. Missions of increasing difficulty, a veteran community.
Not a practice platform in itself, but the calendar of every CTF in the world. For when you want to compete in real team events.
Permanent CTF challenges by category, with beginner difficulty. A good complement to picoCTF.
Official Google challenges for understanding XSS step by step. Short and very didactic.
Modern, entertaining XSS challenges to sharpen your eye for payloads.
Every month, Intigriti publishes a public XSS challenge. Excellent for practicing creative bypasses and comparing yourself with the community.
PortSwigger's expert-level labs (already mentioned) deserve a separate mention: race conditions, HTTP request smuggling, prototype pollution. State of the art.
"Completely Ridiculous API": a vulnerable app focused on the OWASP API Security Top 10. Essential if you want to specialize in APIs.
A deliberately vulnerable API (Flask) to practice IDOR, broken authentication and more, at the endpoint level.
For learning to attack GraphQL: introspection, injection, IDOR in resolvers. A niche with little competition in bug bounty.
Free courses on API security with labs included. Well-structured theory + practice.
A Linux VM full of vulnerable services. More about network/systems than web, but a mandatory reference for recon and service exploitation.
Binary exploitation (pwn) challenges. If you want to go beyond web toward binaries, start here.
Vulnerable mobile apps for anyone who wants to get into Android/iOS bug bounty.
Another source of boot2root-style machines, with a ranking and an active community. A fresh alternative to VulnHub.
If the list overwhelms you, this is the order I recommend for web bug bounty:
The key isn't how many platforms you touch, but practicing in order and consistently until the flaw jumps out at you on its own.
Is it legal to practice on these sites?
Yes. Everything on this list is designed to be hacked or is our own lab. What's illegal is attacking third-party systems without a program or explicit permission.
Which is the best one to start from scratch?
For web theory, PortSwigger (free). For real flaws with nothing to set up, BBLABS. To get comfortable with the terminal, TryHackMe.
Free or paid?
There's a lot of free content (PortSwigger, picoCTF, Juice Shop, OverTheWire). The paid ones usually add guided paths, support and ordered content, which saves a lot of time when you're starting.
Does practicing labs help you make money in bug bounty?
It helps you recognize patterns, which is 80% of the job. The more the labs resemble real flaws (like report-based ones), the less distance there is between practicing and reporting for real.
You don't need to try all 30+: you need to pick three or four and be consistent. Start with the PortSwigger theory, train the pattern with labs based on real cases at BBLABS following the roadmap, and once the flaws feel familiar, make the jump to a real program with the base from Learn bug bounty. The difference between someone who practices and someone who gets paid isn't the platform: it's consistency.
hunters training
labs from real reports
completions
in bounties practiced
Create your free account and practice on labs based on real reports that paid out thousands of euros. The Academy is free forever.
No card · free Academy · cancel anytime
Learn to identify and exploit IDOR (Insecure Direct Object Reference) vulnerabilities in web applications. From the basics to writing effective reports.
What bug bounty is, how a program works step by step, which platforms it runs on (HackerOne, Bugcrowd, Intigriti, YesWeHack), how much you earn, whether it's legal and where to start from scratch.
What bug bounty really pays: average rewards by vulnerability type and severity, what top hunters earn, the reality for beginners and why most people don't make a living from it.