# OSWA evidence and submission

A final evidence, packaging, and submission review derived from the field manual.

## Evidence by vulnerability

- [ ] Cross-site scripting: Vulnerable request and rendered response
- [ ] Cross-site scripting: Exact context and payload
- [ ] Cross-site scripting: Callback or administrator visit
- [ ] Cross-site scripting: Authenticated administrator view
- [ ] Cross-site scripting: local.txt browser and proxy screenshots
- [ ] CSRF, SOP, SameSite, and CORS: Original privileged request
- [ ] CSRF, SOP, SameSite, and CORS: Removed/bypassed control
- [ ] CSRF, SOP, SameSite, and CORS: Browser-deliverable PoC
- [ ] CSRF, SOP, SameSite, and CORS: Privileged side effect or readable response
- [ ] CSRF, SOP, SameSite, and CORS: Administrator objective
- [ ] SQL injection: True/false or error confirmation
- [ ] SQL injection: Dialect identification
- [ ] SQL injection: Working enumeration query
- [ ] SQL injection: Administrative or RCE transition
- [ ] SQL injection: Original-location proof screenshot
- [ ] Directory traversal and file access: Baseline file request
- [ ] Directory traversal and file access: Working traversal grammar
- [ ] Directory traversal and file access: Known file contents
- [ ] Directory traversal and file access: Sensitive file that advances the chain
- [ ] Directory traversal and file access: Resulting administrator or server proof
- [ ] XML external entity injection: Valid baseline XML
- [ ] XML external entity injection: Internal expansion proof
- [ ] XML external entity injection: External file or callback proof
- [ ] XML external entity injection: Parser-specific payload
- [ ] XML external entity injection: Chain to objective
- [ ] Server-side template injection: Literal-versus-evaluated proof
- [ ] Server-side template injection: Engine fingerprint
- [ ] Server-side template injection: Accessible object/function
- [ ] Server-side template injection: Command output or callback
- [ ] Server-side template injection: proof.txt from original location
- [ ] Operating-system command injection: Harmless direct/timing confirmation
- [ ] Operating-system command injection: Execution context enumeration
- [ ] Operating-system command injection: Listener and target command
- [ ] Operating-system command injection: Stable shell or direct file read
- [ ] Operating-system command injection: Original-location proof
- [ ] Server-side request forgery: Unique callback request
- [ ] Server-side request forgery: Server-fetch characteristics
- [ ] Server-side request forgery: Internal destination evidence
- [ ] Server-side request forgery: Privileged internal response/action
- [ ] Server-side request forgery: Resulting objective
- [ ] IDOR and broken object authorization: Ownership setup for both accounts
- [ ] IDOR and broken object authorization: Original authorized request
- [ ] IDOR and broken object authorization: Single-variable unauthorized replay
- [ ] IDOR and broken object authorization: Victim-side verification
- [ ] IDOR and broken object authorization: Administrator objective

## Submission

- [ ] All local.txt and proof.txt values were entered into the Exam Control Panel before the active exam ended.
- [ ] Every awarded objective has the required browser/proxy or shell/original-location screenshot.
- [ ] Every attack is reproducible from the report, including commands, requests, output, callbacks, and PoCs.
- [ ] Scripts and PoCs are included as text inside the PDF.
- [ ] The final PDF was rendered and visually reviewed.
- [ ] PDF name: OSWA-OS-XXXXX-Exam-Report.pdf.
- [ ] Archive name: OSWA-OS-XXXXX-Exam-Report.7z.
- [ ] The .7z is not password protected and is no larger than 200 MB.
- [ ] The archive was uploaded within 24 hours after the active exam.
- [ ] The upload MD5 matches the local md5sum output.

> Do you want to live curiously?
