← All Roadmaps
OffSec

OffSec OSWA Study Roadmap

WEB-200 / OSWA · 12-week plan · Free

Last updated: March 30, 2026

Progress:
0/12

Domain Weight Distribution

D1: Web Application Assessment Methodology
20%
D2: Cross-Site Scripting (XSS)
20%
D3: SQL Injection
25%
D4: Authentication & Session Attacks
20%
D5: Server-Side Attacks & File Inclusion
15%

Week-by-Week Study Plan

Week 1

Domain 1: Web app architecture — HTTP protocol, Burp Suite setup, proxy configuration

Week 2

Domain 1: Application mapping — Technology fingerprinting, endpoint enumeration, API testing

Week 3

Domain 2: XSS fundamentals — Reflected, stored, DOM-based XSS identification

Week 4

Domain 2: Advanced XSS — Filter bypass, CSP evasion, payload crafting, cookie theft

Week 5

Domain 3: SQL injection basics — Detection, UNION-based, error-based extraction

Week 6

Domain 3: Advanced SQLi — Blind techniques (boolean/time-based), sqlmap, WAF bypass

Week 7

Domain 4: Authentication attacks — Bypass techniques, brute force, credential stuffing

Week 8

Domain 4: Session attacks — Fixation, hijacking, JWT attacks, CSRF exploitation

Week 9

Domain 5: File inclusion — LFI/RFI exploitation, PHP wrappers, log poisoning

Week 10

Domain 5: Server-side attacks — SSRF, file upload exploits, command injection, XXE

Week 11

Lab Practice: Full web application assessments, timed exercises, report writing

Week 12

Final Review: Weak areas, mock exam practice, exam preparation

Free Resources

Proving Grounds

Related Tools

FixTheVuln Store

Get the OffSec OSWA Study Planner

Fillable PDF with 12-week schedule, domain trackers, flashcard templates, and progress tracking.

Get the Study Planner — $5.99