Save clean baseline requests and responses for important features before mutation.
03
02 · Classify and prioritize
Classify each input as browser-rendered, database-consumed, filesystem-related, XML-parsed, template-rendered, command-adjacent, URL-fetched, or object-referencing.
Prioritize stored inputs visited by administrators, administrative actions, file or URL features, search/filter fields, import/export, and object identifiers.
For every promising input, record the source, transformations, sink, user context, and expected security boundary.
Rank hypotheses by ability to reach an administrator session, local.txt, file access, command execution, a shell, or proof.txt.
Define the smallest harmless probe that can confirm or reject each hypothesis.
Track negative results with the exact context and encoding used so failed tests are not repeated blindly.
04
03 · Confirm the primitive manually
Change one thing at a time and compare status, length, headers, body, timing, side effects, and subsequent requests.
Use delimiters, arithmetic, timing, callbacks, object swaps, or harmless file reads appropriate to the suspected sink.
Reproduce the signal at least twice and rule out caching, unstable content, proxy errors, and normal application behavior.
Identify the exact execution context, operating system, database dialect, template engine, parser, role, or URL parser where possible.
Save the minimum confirming request, response, command, and screenshot.
Only after manual confirmation, hand off repetitive enumeration to approved tools such as SQLMap, Tplmap, Wfuzz, or a proxy fuzzer.
05
04 · Escalate and chain
Ask whether the primitive runs in an administrator browser, application process, database, internal service, or another user's authorization context.
For browser-side execution, target the administrator session or a same-origin administrative action and verify the resulting role.
For database or server-side execution, enumerate the minimum information needed to reach file read, file write, command execution, or a shell.
For authorization issues, test horizontal and vertical operations across read, create, update, delete, file access, and administrative endpoints.
For SSRF and XXE, enumerate reachable local services and files methodically; do not confuse callback confirmation with objective completion.
Prefer short, reproducible chains. Record every dependency and transformation between source and final sink.
After a shell, locate proof.txt from its expected original location; privilege escalation is not required for OSWA.
06
05 · Capture evidence immediately
Submit local.txt and proof.txt values to the Exam Control Panel before the active exam ends.
For a web UI proof, capture the actual target browser view and the relevant request in Burp or another proxy.
For a shell proof, capture cat or type reading the file from its original location with target context visible.
Record commands, full requests, relevant responses, console output, payload hosting, listener setup, and every prerequisite step.
Use meaningful screenshot filenames and add them to the report while the chain is fresh.
Reproduce the chain from a clean session or clean target state before marking the target complete.
Confirm that another technically competent tester could repeat the result using only the report.
07
06 · Validate and submit
Calculate documented points, not merely discovered vulnerabilities; train for at least eight evidenced flags.
Review every target against its control-panel objective and verify every required screenshot is embedded.
Include scripts and PoCs as text in the PDF; do not rely on separate files inside the archive.
Render and review the final PDF for clipped commands, broken images, missing pages, and unreadable screenshots.
Name the PDF and .7z exactly as required, preserve case, do not password-protect the archive, and keep it under 200 MB.
Upload within the documentation window and compare the returned MD5 with the local archive hash.
Retain the final PDF, archive, checksum, and upload confirmation until results are received.