Course package
digicode: OSWE
Advanced Web Attacks and Exploitation (Web-300) – OSWE Certification
Course facts
Download as PDF- Applying systematic methods to analyze complex web applications and their source code
- Identifying vulnerabilities through static and dynamic analysis as well as fuzzing
- Analyzing complex web vulnerabilities and deriving appropriate attack techniques
- Exploiting advanced vulnerabilities in web applications
- Developing and customizing your own exploits for identified vulnerabilities
- Bypassing authentication, validation, and other protection mechanisms
- Combining multiple vulnerabilities into complex attack paths
- Documenting vulnerabilities, exploitation steps, and the results of a web application penetration test
- Web security methodology and white-box penetration testing
- Source code analysis and manual code review
- Static and dynamic analysis
- Fuzzing and vulnerability discovery
- Authentication bypass and session hijacking
- Advanced server-side request forgery (SSRF)
- Persistent cross-site scripting (XSS)
- Blind SQL injection and data exfiltration
- .NET deserialization and remote code execution
- JavaScript prototype pollution
- Bypassing file upload and extension filters
- Developing custom exploits
- Chaining complex web vulnerabilities and attack paths
- Realistic attack scenarios and challenge labs
- Documentation and exploit reporting
- Preparation for the OSWE certification exam
The course combines five days of intensive, instructor-led training with a subsequent individual learning and practice phase. During the training days, the instructors cover the OSWE material in a structured manner and consistently integrate theory with demonstrations, hands-on exercises, and realistic attack scenarios.
After the training, you’ll reinforce the material on your own using your Learn-One subscription. For 365 days, you’ll have access to OffSec learning materials and extensive labs to further develop your practical skills and prepare specifically for the exam.
The course concludes with a brush-up session with the instructor, which is already included in the course. The date is chosen or, if necessary, rescheduled so that the brush-up takes place as close as possible to your scheduled exam. During this session, you’ll clarify any remaining questions, reinforce key topics, and get final tips to help you prepare for the exam.
The Learn-One subscription includes:
- 365 days of access to the digital OffSec course and the accompanying labs
- Digital OffSec course materials, which can also be downloaded
- Two exam attempts for the OffSec certification associated with the course
- Access to over 200 Proving Grounds Practice Labs for additional hands-on training
- Bonus access to the KLCP course (Kali Linux Certified Professional), including the exam
- Bonus access to the OSWP course (OffSec Wireless Professional), including the exam
The WEB-300 is ideal for you if you already have experience in penetration testing and web application security. You want to further develop your skills in analyzing and exploiting complex web applications at an expert level and validate them with the internationally recognized OSWE certification.
The course is specifically aimed at:
Penetration Testers & Ethical Hackers: You want to deepen your web security expertise and learn how to identify and exploit complex vulnerabilities through source code analysis, and link them into attack chains.
Application Security Engineers: You want to analyze web applications from an attacker’s perspective, identify vulnerabilities in the code, and specifically improve application security.
Security Researchers & Exploit Developers: You want to use advanced vulnerability discovery methods and develop your own exploits for complex web vulnerabilities.
Red Team Operators & Experienced Security Professionals: You want to expand your offensive skillset with advanced web attack techniques and demonstrate your practical expertise with the OSWE certification.
For this advanced course, you should already have solid experience in penetration testing and web application security. Ideally, you should have the following knowledge:
- Good knowledge of web technologies and common web attack vectors
- Experience with web proxies and web security tools
- Good knowledge of Linux
- Experience reading and analyzing source code
- Basic programming and scripting skills
Practical offensive security skills at the OSCP certification level and/or in-depth knowledge of web application security, similar to the course below, are a plus:
However, an OSCP or OSWA certification is not a formal prerequisite for participating in WEB-300.
To successfully earn certification, it is important that you engage intensively with technical challenges and practice independently in the labs.
With the WEB-300, you’ll prepare for the OffSec Web Expert (OSWE) certification. The exam is entirely hands-on: You’ll analyze and compromise vulnerable web applications in a private testing environment and develop your own exploits.
- Exam duration: 47 hours and 45 minutes
- Documentation: an additional 24 hours afterward to submit the exam report
- Format: practical, proctored hands-on exam in a private VPN environment
- Maximum score: 100 points
- Passing score: 85 out of 100 points
- Exam environment: multiple vulnerable target systems with individual exam objectives
- Exam tasks:
- Identification and analysis of complex vulnerabilities
- Exploitation of identified vulnerabilities
- Chaining multiple vulnerabilities
- Development of your own functional exploits or PoC scripts
- Demonstration of successful compromise
- Exam report: All attack steps, commands used, results, and self-developed exploits must be documented in such a way that a technically skilled person can reproduce the procedure step by step.
A unique feature of the OSWE exam: You demonstrate your expertise by linking complex vulnerabilities into an attack chain and developing your own, automatically executable exploit from it.
Certification
Upon successful completion of the exam, you will receive the OffSec Web Expert (OSWE) certification, as well as a digital certificate and badge from OffSec. The OSWE certification is valid indefinitely and does not need to be renewed.