WEB-300: Advanced Web Attacks and Exploitation
Learn the skills needed to conduct white box web app penetration tests with the WEB-300 certification
-
Module 1: Introduction
-
Module 2: Tools & Methodologies
-
Module 3: ATutor Authentication Bypass and RCE
-
Module 4: ATutor LMS Type Juggling Vulnerability
-
Module 5: ManageEngine Applications Manager AMUserResourcesSyncServlet SQL Injection RCE
-
Module 6: Bassmaster NodeJS Arbitrary JavaScript Injection Vulnerability
-
Module 7 : DotNetNuke Cookie Deserialization RCE
-
Module 8: ERPNext Authentication Bypass and Server Side Template Injection
-
Module 9: openCRX Authentication Bypass and Remote Code Execution
-
Module 10: openITCOCKPIT XSS and OS Command Injection – Blackbox
-
Module 11: Concord Authentication Bypass to RCE
-
Module 12: Server Side Request Forgery
-
Module 13: Guacamole Lite Prototype Pollution
-
Module 14: Conclusion
About The Course
Advanced Web Attacks and exploitation (WEB-300) is an advanced web application security course that teaches the skills needed to conduct white box web app penetration tests. Students who complete the course and pass the exam earn the Offensive Security Web Expert (OSWE) certification and will demonstrate mastery in exploiting front-facing web apps. The OSWE is one of three certifications making up the OSCE3 certification along with the OSEP for advanced pentesting and OSED for exploit development.
Course Objectives
- Performing advanced web app source code auditing
- Analyzing code, writing scripts, and exploiting web vulnerabilities
- Implementing multi-step, chained attacks using multiple vulnerabilities
- Using creative and lateral thinking to determine innovative ways of exploiting web vulnerabilities
Pre-Requisites
- Comfort reading and writing at least one coding language
- Familiarity with Linux
- Ability to write simple Python / Perl / PHP / Bash scripts
- Experience with web proxies
- General understanding of web app attack vectors, theory, and practice
What's included
- 40 Hours Training Course
- Certificate
- 14 Modules
- 24/7 Support