Skip to content

OSWE

The OSWE (Offensive Security Web Expert) is OffSec’s advanced web security certification, focused on EXPLOITATION through SOURCE CODE analysis (white-box). It’s not blind bug hunting: it’s reading an app’s code, finding the flaw, and chaining an exploit (often to RCE).

- a WHITE-BOX focus: you have the SOURCE CODE and must find and exploit the vulns in it
- goal: chain vulnerabilities to RCE or auth bypass + execution
- requires UNDERSTANDING and READING code (PHP, Java, C#, Node, Python...) not just using tools
- writing automated EXPLOITS (scripts that exploit the chain end to end)
- source code auditing to find vulns (injection, deserialization, logic, auth)
- advanced SQLi (incl. blind), deserialization, SSTI, type juggling, race conditions
- chained authentication/authorization bypasses (see web-logic, web-session)
- building exploits that automate the full chain
- 48 practical hours + a report: compromise applications by analyzing their code
- typical goal: chained auth bypass + RCE, with a working exploit script
- very demanding: requires fluency reading code and debugging
- the WEB-300 course + intense source-code-analysis practice
- master web vulns thoroughly (Web area: web-logic, web-session, deserialization, SSTI)
- PortSwigger Web Security Academy (advanced topics); practice writing exploits in Python
- read real app code and find/understand their CVEs
- a reference for AppSec / senior web pentester and for code auditing
- demonstrates real WHITE-BOX capability (in high demand in AppSec/DevSecOps)
- a natural complement to the OSCP for web specialization
  • The OSWE validates code auditing + white-box exploitation: read the code and chain to RCE.
  • It fits AppSec/DevSecOps roles (dso-*) and senior web pentesting.
  • Preparing it requires mastering the Web area thoroughly and knowing how to write exploits (Python).
  • A natural complement to the OSCP to specialize in web.
  • It’s white-box: train reading code (PHP/Java/JS/.NET) to find the chain, not blind fuzzing.
  • Prepare your own exploit scripts; the exam rewards automating the auth-bypass → RCE chain.
  • Common mistake: getting lost in the code without method; trace user input down to the sink.
  • Master the Web area (Business Logic Flaws, Session Management, deserialization, SSTI)
  • Fluency reading code (PHP/Java/C#/Node/Python)
  • WEB-300 course + code-auditing practice
  • Write automated exploits in Python
  • PortSwigger (advanced topics) and real app CVEs
  • Practice auth bypass → RCE chains
  • Simulated 48h exam + report