# OSWA 12-week study plan

A practical study sequence with a readiness gate for each week.

## Week 1: Tools, proxy workflow, Nmap, wordlists, Gobuster, Wfuzz, crawling, shells, and XSS discovery

- [ ] Map a fresh application and explain every captured request.

## Week 2: XSS exploitation, JavaScript APIs, stored/emulated-user paths, evidence

- [ ] Turn context-specific XSS into a reliable callback and same-origin action.

## Week 3: Same-origin policy, SameSite, CSRF, CORS, browser enforcement

- [ ] Build browser-deliverable CSRF and distinguish weak from exploitable CORS.

## Week 4: SQL fundamentals across MySQL, PostgreSQL, MSSQL, and Oracle

- [ ] Write manual schema queries without copying a database dump recipe.

## Week 5: SQLi discovery, UNION, errors, stacked queries, file access, SQLMap handoff

- [ ] Manually confirm and enumerate before running SQLMap.

## Week 6: Directory traversal, normalization, encoding, Unix and Windows file targets

- [ ] Derive a working traversal from the application's path grammar.

## Week 7: XML and XXE: in-band, error-based, out-of-band

- [ ] Prove entity expansion and retrieve a controlled file or callback.

## Week 8: SSTI fingerprinting across Twig, FreeMarker, Pug, Jinja, Mustache, Handlebars

- [ ] Identify an engine from behavior and explain each escalation step.

## Week 9: Command injection, filters, blind confirmation, shells, transfer

- [ ] Obtain a callback using a runtime you first proved exists.

## Week 10: SSRF, URL parsing, internal services, microservice trust, metadata

- [ ] Differentiate server callback, blind reachability, and readable SSRF.

## Week 11: IDOR, two-account matrices, horizontal/vertical authorization, chaining

- [ ] Demonstrate an unauthorized operation with a single-variable replay.

## Week 12: Unknown challenge targets, five-target simulation, screenshots, reporting, logistics

- [ ] Score 80+ with complete evidence and produce the report without reopening targets.

> Do you want to live curiously?
