دوره WEB-300: Advanced Web Attacks and Exploitation

  • OffSec
  • 12,287 بازدید
  • 0 نظر

Advanced Web Attacks and exploitation (WEB-300) is an advanced web application security course that teaches the skills needed to conduct white box web app penetration tests. Learners who complete the course and pass the exam earn the OffSec Web Expert (OSWE) certification and will demonstrate mastery in exploiting front-facing web apps. The OSWE is one of three certifications making up the OSCE³ certification along with the OSEP for advanced pentesting and OSED for exploit development.

Syllabus

  1. JavaScript Prototype Pollution
  2. Advanced Server-Side Request Forgery (SSRF)
  3. Web security tools and methodologies
  4. Source code analysis
  5. Persistent cross-site scripting
  6. Session hijacking
  7. .NET deserialization
  8. Remote code execution
  9. Blind SQL injection
  10. Data exfiltration
  11. Bypassing file upload restrictions and file extension filters
  12. PHP type juggling with loose comparisons
  13. PostgreSQL Extension and User Defined Functions
  14. Bypassing REGEX restrictions
  15. Magic hashes
  16. Bypassing character restrictions
  17. UDF reverse shells
  18. PostgreSQL large objects
  19. DOM-based cross site scripting (black box)
  20. Server-side template injection
  21. Weak random token generation
  22. XML external entity injection
  23. RCE via database functions
  24. OS command injection via WebSockets (black box)

WEB-300: Advanced Web Attacks and Exploitation