How to attack Offensive Security Web Expert (OSWE)

Cristian Cornea
4 min readJan 12, 2022

In this article, we will discuss about one of the toughest exams from Offensive Security, the web expert one (OSWE).

Mindset

If the mindset for OSCP is “Try harder!”, then the mindset for OSWE would be something like “Try harder, but harder than ever!”.

If you thought that OSCP contains a lot of rabbit holes than you are totally wrong! From my experience with OSWE, I’ve run into a LOT of dead ends and noticed at some point that those were created intentionally, just to exercise your vision, mindset, and perspicacity. So expect that you will run into multiple rabbit holes during the exam, but I will provide some methodology guidelines in order to get over quickly and put yourself on the right way.

It is very important that you won’t give up, fight until the end! For example, when I was sitting the exam, I’ve met the minimum passing points during the last hours before the end.

I suggest getting some fresh air and taking regular breaks, which will help you refresh your perspective.

Also, when you realize that you got caught in a rabbit hole, just accept that, and move on. Do not feel discouraged when this happens, because you didn’t fail, you just found a way of how to NOT exploit the application, and you can remove it from your…

--

--

Cristian Cornea
Cristian Cornea

Written by Cristian Cornea

🥷🏻Zerotak - Cyber Security & Pentesting 🧑‍🎓CSTCE - Cyber Security Training Centre of Excellence 🦉SectionX.io - Threat Intel🧛🏼BSides Transylvania

No responses yet