OffSec Web Expert (OSWE)
Offensive Security
The OffSec Web Expert certification demonstrates your ability to identify, exploit, and report on complex vulnerabilities within a real-world environment, culminating in the development of a custom exploit.
Cost
Course + Cert Bundle: $1,749Show moreShow less
Format
Online
Skills developed through this program
- Understand and exploit stored cross-site scripting (XSS) vulnerabilities
- Gain insights into SQL injection attacks and develop methods to exploit them
- Analyze and exploit code injection vulnerabilities in server-side JavaScript
- Understand deserialization vulnerabilities and learn to exploit them for remote code execution
- Perform manual source code analysis to identify potential security flaws
- Develop custom fuzzing tools for vulnerability discovery
Occupations this program prepares you for
Credentials this program stacks toward
No program pathways.
Detailed information about this program
Becoming OSWE certified - 48-hour proctored: All exams are proctored by an OffSec employee in a private VPN - Hands-on labs: Identify, exploit, and report real-world vulnerabilities in live lab systems - Compromise multiple machines: You’re required to write a professional report describing your exploitation process for each target - Retrieve proof files: Failure to provide the appropriate documentation or proof files for a specific exam objective may result in partial or zero points being awarded for that objective Train to become OSWE certified WEB-300: Advanced Web Attacks and Exploitation WEB-300 (Advanced Web Attacks and Exploitation) provides experienced offensive cybersecurity team members with a comprehensive analysis of various vulnerabilities and their exploitation techniques in web applications. Building on the PEN-200 and WEB-200 programs, this program will dig deep into the methodologies and skill used to analyze the target web applications and exploit development. This will give learners a complete understanding of the underlying flaws that we are going to exploit. The goal of this course is to expose you to a general and repeatable approach to web application security and vulnerability discovery and exploitation, while continuing to strengthen the foundational knowledge that is necessary when faced with modern-day web applications. WEB-300 covers a wide range of advanced web exploitation skills and techniques, including: - Analyzing and exploiting a deserialization remote code execution (RCE) vulnerability in the DotNetNuke (DNN) platform - Mastering advanced web security methodologies such as fuzzing, static and dynamic analysis, and manual code review - Practicing session hijacking techniques to gain unauthorized access to sensitive data and functionality, including exploiting an RCE vulnerability in the Dolibarr application using a dedicated virtual machine WEB-300 is organized into 17 in-depth modules, each focusing on different topics. Many modules include companion videos and hands-on activities to reinforce the learning experience. Additionally, 20 Challenge Labs are provided to test learners' understanding and prepare them for the OffSec Web Expert (OWSE) certification exam. As an advanced offensive course, WEB-300 is developed to test experienced penetration testers and security professionals seeking to master advanced web application attacks and exploitation techniques. It is expected that learners are not only familiar with basic web technologies and scripting languages, such as JavaScript, PHP, Java, and C#, but also have a high level of experience in offensive techniques taught in PEN-200.
What you need to earn this credential
No requirements listed.
Eligible funding programs
No funding information available.
Scholarships
No scholarships listed.