← All Certifications
OffSec

OffSec OSWE Certification

WEB-300 · Practical

Last updated: March 31, 2026

Exam Syllabus & Domains

The OffSec OSWE certification exam covers the following domains. Focus your training time proportionally to each domain's weight.

Domain 1 20%

Advanced Web Application Source Code Review

  • 1.1 Perform systematic source code review of web applications
  • 1.2 Identify vulnerabilities in multiple programming languages
  • 1.3 Trace data flow from user input to dangerous sinks
  • 1.4 Analyze application logic for business logic flaws
Source Code ReviewData Flow AnalysisTaint TrackingCode Auditing ToolsLanguage-Specific PatternsMVC ArchitectureORM VulnerabilitiesInput Sources/SinksBusiness Logic FlawsSecure Coding Patterns
Domain 2 20%

Authentication Bypass

  • 2.1 Identify and exploit authentication bypass vulnerabilities in source code
  • 2.2 Exploit type juggling and loose comparison vulnerabilities
  • 2.3 Attack custom authentication implementations
  • 2.4 Chain multiple flaws to achieve authentication bypass
Type JugglingLoose ComparisonJWT ManipulationSession Token PredictionPassword Reset FlawsOAuth Implementation BugsSSO BypassRole ManipulationPrivilege EscalationAccess Control Bypass
Domain 3 25%

Advanced SQL/NoSQL Injection

  • 3.1 Identify SQL injection through source code analysis
  • 3.2 Exploit complex SQL injection scenarios with filters
  • 3.3 Perform NoSQL injection against document databases
  • 3.4 Write custom exploitation scripts for data extraction
Parameterized Query BypassORM InjectionStored Procedure ExploitationNoSQL Injection (MongoDB)Second-Order SQLiOut-of-Band ExtractionWAF Bypass TechniquesCustom Exploit ScriptsDatabase-Specific FunctionsStacked Queries
Domain 4 20%

Deserialization Attacks

  • 4.1 Identify insecure deserialization in Java, PHP, and .NET applications
  • 4.2 Construct exploitation gadget chains
  • 4.3 Exploit deserialization for remote code execution
  • 4.4 Analyze serialization formats and custom protocols
Java DeserializationPHP Object Injection.NET DeserializationGadget ChainsysoserialPHPGGCMagic MethodsSerialization FormatsProperty-Oriented ProgrammingCustom Deserialization
Domain 5 15%

Server-Side Template Injection & RCE

  • 5.1 Identify server-side template injection vulnerabilities
  • 5.2 Exploit SSTI across different template engines
  • 5.3 Achieve remote code execution through application flaws
  • 5.4 Write custom exploit scripts for chained vulnerabilities
Jinja2 SSTITwig SSTIFreemarker SSTIThymeleaf SSTITemplate Engine SandboxesSandbox EscapesRCE via File WriteRCE via Code InjectionExploit ChainingCustom Exploit Development

Where to Focus Your Study Time

Domains with higher weight have more exam questions — allocate your study hours accordingly.

D1 Advanced Web Application Source Code Review
20%
D2 Authentication Bypass
20%
D3 Advanced SQL/NoSQL Injection
25%
D4 Deserialization Attacks
20%
D5 Server-Side Template Injection & RCE
15%

Study Tips

Free Study Resources

๐Ÿ“‹

Study Roadmap

Week-by-week study plan with free resources

โœ…

Study Tracker

Track objective completion with progress dashboard

๐Ÿ’ฐ

Cost Calculator

Total cost breakdown and ROI analysis

๐Ÿงช

Practice Quiz

Test your knowledge with free practice questions

Practice Quiz

Test your knowledge before the exam with our free practice quiz.

Take the OffSec OSWE Practice Quiz

Get the OffSec OSWE Study Planner

Fillable PDF with 16-week schedule, domain trackers, flashcard templates, progress tracking, and quick reference sheets. Available in Standard, ADHD-Friendly, Dark Mode, and 4-Format Bundle.

Get the Study Planner — $5.99

Also available as a 4-Format Bundle for $15.99

CyberFolio

Earned your certs? Show employers.

Build a shareable cybersecurity portfolio that highlights your certifications, projects, and skills — free.

Build Your Portfolio →

Free Training Resources

Use these free tools to support your OffSec OSWE certification training:

Frequently Asked Questions

What is the OffSec OSWE certification?

The OffSec OSWE (WEB-300) is a professional IT certification that validates your knowledge and skills in the exam domains covered. It is recognized globally by employers and is a valuable credential for career advancement in cybersecurity and IT.

What does the OffSec OSWE certification syllabus cover?

The OffSec OSWE exam syllabus covers Practical. Each domain is weighted differently, so focus your training on higher-weighted domains first. Review the complete domain breakdown above for objectives and key concepts.

How should I study for OffSec OSWE?

Create a structured study plan covering all exam domains, use practice tests to identify weak areas, and review key concepts regularly. A fillable study planner can help you organize your training with weekly schedules and progress tracking.

How long does it take to prepare for OffSec OSWE?

Preparation time varies by experience level. Most candidates spend 8-12 weeks of dedicated training. Using a structured study planner with domain-by-domain breakdown helps ensure you cover all certification objectives efficiently.