OffSec Advanced Web Attacks and Exploitation WEB-300 (OSWE) Training
We are a Premier Provider of WEB-300 OffSec OSWE Training. In Advanced Web Attacks and Exploitation, you will learn white box web app pentesting methods. The bulk of your time will be spent analyzing source code, decompiling Java, debugging DLLs, manipulating requests and more, using tools like Burp Suite, dnSpy, JD-GUI, Visual Studio, and the trusty text editor.
Advanced Web Attacks and Exploitation (WEB-300)
Course Overview
Advanced Web Attacks and Exploitation (WEB-300) is an advanced web application security review course. We teach the skills needed to conduct white box web app penetration tests.
WEB-300 features three new modules, updated existing content, new machines, plus refreshed videos .
Students who complete the course and pass the exam earn the OffSec Web Expert (OSWE) certification, demonstrating mastery in exploiting front-facing web apps. The OSWE is one of three certifications making up the new OSCE 3 certification, along with the OSEP for advanced pentesting and the OSED for exploit development.
Course Outline
- The course covers the following topics.
- Cross-Origin Resource Sharing (CORS) with CSRF and RCE
- JavaScript Prototype Pollution
- Advanced Server-Side Request Forgery (SSRF)
- Web security tools and methodologies
- Source code analysis
- Persistent cross-site scripting
- Session hijacking
- .NET deserialization
- Remote code execution
- Blind SQL injection
- Data exfiltration
- Bypassing file upload restrictions and file extension filters
- PHP type juggling with loose comparisons
- PostgreSQL Extension and User Defined Functions
- Bypassing REGEX restrictions
- Magic hashes
- Bypassing character restrictions
- UDF reverse shells
- PostgreSQL large objects
- DOM-based cross site scripting (black box)
- Server-side template injection
- Weak random token generation
- XML external entity injection
- RCE via database functions
- OS command injection via WebSockets (black box)
Intended Audience
All students are required to have:
- Comfort reading and writing at least one coding language (Java, .NET, JavaScript, Python, etc)
- Familiarity with Linux: file permissions, navigation, and editing and running scripts
- Ability to write simple Python / Perl / PHP / Bash scripts
- Experience with web proxies such as Burp Suite and similar tools
- General understanding of web app attack vectors, theory, and practice
- Experienced penetration testers who want to better understand white box web app pentesting
- Web application security specialists
- Web professionals working with the codebase and security infrastructure of a web application
Prerequisites
- Comfort reading and writing at least one coding language
- Familiarity with Linux
- Ability to write simple Python / Perl / PHP / Bash scripts
- Experience with web proxies
- General understanding of web app attack vectors, theory, and practice
Features
- Course Materials
- Active Student Forums
- Access to Home Lab Setup
- Instructors with decades of cumulative real world experience</>
This course is also available in On Demand formats:
- Learn One Package – $2,749
- One course
- 365 days of lab access
- Two exam attempts
- Plus exclusive content
- Learn Unlimited Package – $6,099
- All courses
- 365 days of lab access
- Unlimited exam attempts
- Plus exclusive content
Follow-On Courses
PROUD OFFSEC PARTNERSHIP
We are proud to be an OffSec Learning, Government, and Channel Partner. We pride
ourselves on providing award winning boot camps and direct mentoring in our classrooms,
Online Live or at your location. The only immersive Authorized Instructor-Led OffSec
training available - join us today.
Related training topics
Justify your training
Use this sample request letter — copy it into an email to your manager and personalize the bracketed details to make the case for the time and budget.
Sample training request letter
Subject: Request for Penetration Testing & Red Teaming training from Applied Technology Academy
[Decision Maker Name],
I'm writing to request time and budget approval to complete Applied Technology Academy's course, OffSec Advanced Web Attacks and Exploitation WEB-300 (OSWE) Training. The information below outlines how this training benefits our organization, the tasks I'll be able to perform after completing it, and relevant cost and funding details.
Course Description
We are a Premier Provider of WEB-300 OffSec OSWE Training. In Advanced Web Attacks and Exploitation, you will learn white box web app pentesting methods. The bulk of your time will be spent analyzing source code, decompiling Java, debugging DLLs, manipulating requests and more, using tools like Burp Suite, dnSpy, JD-GUI, Visual Studio, and the trusty text editor. Applied Technology Academy is an award-winning, SBA-certified woman-owned training provider (est. 2008) whose instructors are active practitioners; the course is hands-on with virtual labs and a learn-by-doing methodology.
Course Objectives
Once I've completed the course, I'll have hands-on, job-ready skills in penetration testing & red teaming that I can apply immediately to our work.
Expected Organizational Benefits
After completing this course, I will be better equipped to apply these skills directly to our projects, reduce our reliance on outside expertise, strengthen our team's capabilities, and share what I learn with colleagues.
Expected Cost & Funding
Course fee: [request an itemized quote at the link below]. Applied Technology Academy supports multiple funding paths that may reduce or cover this cost: GSA MAS purchasing and government purchase orders, military credentialing funding (Army CA, AF COOL, CG COOL), VA GI Bill and VR&E, ATA Flexible Spending, and student financing. Private team cohorts are available if colleagues should attend with me.
Conclusion
This training provides practical, hands-on experience I can apply immediately to strengthen our work in penetration testing & red teaming. Additional course information is available at https://appliedtechnologyacademy.com/offsec-training/offsec-web-300-oswe-training/.
Thank you for your consideration,
[Your Name]
Related Penetration Testing & Red Teaming courses
Design training around your team, not the other way around.
Talk to a training advisor about private cohorts, funding paths and program management.