OSWE
The OSWE (Offensive Security Web Expert) is OffSec’s advanced web security certification, focused on EXPLOITATION through SOURCE CODE analysis (white-box). It’s not blind bug hunting: it’s reading an app’s code, finding the flaw, and chaining an exploit (often to RCE).
What sets it apart
Section titled “What sets it apart”- a WHITE-BOX focus: you have the SOURCE CODE and must find and exploit the vulns in it- goal: chain vulnerabilities to RCE or auth bypass + execution- requires UNDERSTANDING and READING code (PHP, Java, C#, Node, Python...) not just using tools- writing automated EXPLOITS (scripts that exploit the chain end to end)What it covers (WEB-300 course)
Section titled “What it covers (WEB-300 course)”- source code auditing to find vulns (injection, deserialization, logic, auth)- advanced SQLi (incl. blind), deserialization, SSTI, type juggling, race conditions- chained authentication/authorization bypasses (see web-logic, web-session)- building exploits that automate the full chainThe exam
Section titled “The exam”- 48 practical hours + a report: compromise applications by analyzing their code- typical goal: chained auth bypass + RCE, with a working exploit script- very demanding: requires fluency reading code and debuggingHow to prepare
Section titled “How to prepare”- the WEB-300 course + intense source-code-analysis practice- master web vulns thoroughly (Web area: web-logic, web-session, deserialization, SSTI)- PortSwigger Web Security Academy (advanced topics); practice writing exploits in Python- read real app code and find/understand their CVEsProfessional value
Section titled “Professional value”- a reference for AppSec / senior web pentester and for code auditing- demonstrates real WHITE-BOX capability (in high demand in AppSec/DevSecOps)- a natural complement to the OSCP for web specializationBlue Team / career
Section titled “Blue Team / career”- The OSWE validates code auditing + white-box exploitation: read the code and chain to RCE.
- It fits AppSec/DevSecOps roles (dso-*) and senior web pentesting.
- Preparing it requires mastering the Web area thoroughly and knowing how to write exploits (Python).
- A natural complement to the OSCP to specialize in web.
Tips and common mistakes
Section titled “Tips and common mistakes”- It’s white-box: train reading code (PHP/Java/JS/.NET) to find the chain, not blind fuzzing.
- Prepare your own exploit scripts; the exam rewards automating the auth-bypass → RCE chain.
- Common mistake: getting lost in the code without method; trace user input down to the sink.
Testing checklist
Section titled “Testing checklist”- Master the Web area (Business Logic Flaws, Session Management, deserialization, SSTI)
- Fluency reading code (PHP/Java/C#/Node/Python)
- WEB-300 course + code-auditing practice
- Write automated exploits in Python
- PortSwigger (advanced topics) and real app CVEs
- Practice auth bypass → RCE chains
- Simulated 48h exam + report