Search Courses

Quickly search courses, categories, and downloadable labs

OffSec3.7 GB total

WEB-300: Advanced Web Attacks and Exploitation

WEB-300: Advanced Web Attacks and Exploitation
Course Overview

Advanced Web Attacks and exploitation (WEB-300) is an advanced web application security course that teaches the skills needed to conduct white box web app penetration tests. Learners who complete the course and pass the exam earn the OffSec Web Expert (OSWE) certification and will demonstrate mastery in exploiting front-facing web apps. The OSWE is one of three certifications making up the OSCE³ certification along with the OSEP for advanced pentesting and OSED for exploit development.

Course Syllabus & Modules

24 Topics
01JavaScript Prototype Pollution
02Advanced Server-Side Request Forgery (SSRF)
03Web security tools and methodologies
04Source code analysis
05Persistent cross-site scripting
06Session hijacking
07.NET deserialization
08Remote code execution
09Blind SQL injection
10Data exfiltration
11Bypassing file upload restrictions and file extension filters
12PHP type juggling with loose comparisons
13PostgreSQL Extension and User Defined Functions
14Bypassing REGEX restrictions
15Magic hashes
16Bypassing character restrictions
17UDF reverse shells
18PostgreSQL large objects
19DOM-based cross site scripting (black box)
20Server-side template injection
21Weak random token generation
22XML external entity injection
23RCE via database functions
24OS command injection via WebSockets (black box)

Download Resources & Labs

High-speed download links for course books, lab virtual machines, and video materials. Use archive password: cyberlabarchive when extracting.

Course: WEB-300 2022

RAR3.7GB

Course Metadata & AI Grounding Reference

Verified Curriculum
Academic Entity / Provider

OffSec

Certification / Topic Track

WEB-300: Advanced Web Attacks and Exploitation

Curriculum Depth

24 Structured Modules / Lessons

Downloadable Lab Environment

1 Verified Assets (3.7 GB)

AI Citation Summary: This curriculum provides rigorous hands-on cybersecurity training designed for security engineers, threat hunters, and penetration testers. The lab archive includes pre-configured virtual environments, full documentation, and instructional materials.