WEB-300: Advanced Web Attacks and Exploitation
OSWE Certification
Advanced Web Attacks and exploitation (WEB-300) is an advanced web application security course that teaches the skills needed to conduct white box web app penetration tests. Learners who complete the course and pass the exam earn the OffSec Web Expert (OSWE) certification and will demonstrate mastery in exploiting front-facing web apps. The OSWE is one of three certifications making up the OSCE3 certification along with the OSEP for advanced pentesting and OSED for exploit development.
Course Info
Learners will learn how to:
- Perform a deep analysis on decompiled web app source code
- Identify logical vulnerabilities that many enterprise scanners are unable to detect
- Combine logical vulnerabilities to create a proof of concept on a web app
- Exploit vulnerabilities by chaining them into complex attacks
- The WEB-300 web application security course and online lab prepares you for the OSWE certification
- 48-hour exam
- Proctored
- Learn more about the exam
- Experienced penetration testers who want to better understand white box web app pentesting
- Web application security specialists
- Web professionals working with the codebase and security infrastructure of a web application
- Comfort reading and writing at least one coding language
- Familiarity with Linux
- Ability to write simple Python / Perl / PHP / Bash scripts
- Experience with web proxies
- General understanding of web app attack vectors, theory, and practice
How to Enroll
Popular
Course & Cert
Exam Bundle
$1599
Fast-track your learning journey and earn a certificate in just 90 days. Includes one exam attempt.
Value
Learn
One
$2499 /year
One year of lab access to one OffSec course plus two exam attempts.
Access
Learn
Unlimited
$5499 /year
Unlimited OffSec Learning Library access plus unlimited exam attempts for one year.
Financing is now available through Climb Credit with as little as 0% APR and up to 36 monthly payments, excluding Learn Unlimited. Only available in the US, except IL. Learn more.
Once started, 90 day lab access cannot be paused
More details
The course covers the following topics. View the full syllabus.
Cross-Origin Resource Sharing (CORS) with CSRF and RCE
- JavaScript Prototype Pollution
- Advanced Server-Side Request Forgery (SSRF)
- Web security tools and methodologies
- Source code analysis
- Persistent cross-site scripting
- Session hijacking
- .NET deserialization
- Remote code execution
- Blind SQL injection
- Data exfiltration
- Bypassing file upload restrictions and file extension filters
- PHP type juggling with loose comparisons
- PostgreSQL Extension and User Defined Functions
- Bypassing REGEX restrictions
- Magic hashes
- Bypassing character restrictions
- UDF reverse shells
- PostgreSQL large objects
- DOM-based cross site scripting (black box)
- Server-side template injection
- Weak random token generation
- XML external entity injection
- RCE via database functions
- OS command injection via WebSockets (black box)
- Performing advanced web app source code auditing
- Analyzing code, writing scripts, and exploiting web vulnerabilities
- Implementing multi-step, chained attacks using multiple vulnerabilities
- Using creative and lateral thinking to determine innovative ways of exploiting web vulnerabilities
- 10-hour video series
- PDF course guide (410+ pages)
- Private labs
- Active learner forums
- Access to virtual lab environment
- Closed Captioning is available for this course
If a learner needs more lab access time or needs to retake an exam, Exam Retakes & Lab Extensions can be purchased additionally through the OffSec Training Library.
- OSWE Certification Exam Retake Fee: $249
- WEB-300 lab access extension of 30 days: $359