# OSWA universal methodology

A target-by-target workflow for deliberate WEB-200 testing and evidence capture.

## 00 · Prepare and preserve

- [ ] Read the current exam guide, restrictions, proof rules, and target-specific control-panel objectives.
- [ ] Confirm Kali, OpenVPN, browser, proxy certificate, terminal, screenshot tool, clock, disk space, and report template.
- [ ] Create one notes folder and one evidence folder per target; start a command log before enumeration.
- [ ] Record the VPN interface address and prepare callback variables for web servers, listeners, and out-of-band tests.
- [ ] Bookmark the current official exam guide and this online reference; download the Markdown checklists you want in your own notes.
- [ ] Start the report immediately. Do not rely on memory after a long exploitation chain.

## 01 · Map the application

- [ ] Run focused host and service enumeration; note every HTTP and HTTPS port, title, redirect, certificate name, and technology clue.
- [ ] Add required virtual hosts to /etc/hosts and repeat discovery against each hostname and port.
- [ ] Browse every public feature through the proxy and record methods, paths, parameters, cookies, forms, APIs, uploads, and error behavior.
- [ ] Discover directories, files, extensions, virtual hosts, parameters, parameter values, and backup artifacts with controlled wordlists.
- [ ] Inspect HTML, JavaScript, source maps, comments, robots.txt, API documentation, and client-side requests for hidden routes.
- [ ] Draw the authentication boundary: registration, login, reset, logout, session renewal, roles, administrator routes, and emulated-user entry points.
- [ ] Create an input inventory covering path, query, form, JSON, XML, header, cookie, filename, file content, object ID, URL, and stored content.
- [ ] Save clean baseline requests and responses for important features before mutation.

## 02 · Classify and prioritize

- [ ] Classify each input as browser-rendered, database-consumed, filesystem-related, XML-parsed, template-rendered, command-adjacent, URL-fetched, or object-referencing.
- [ ] Prioritize stored inputs visited by administrators, administrative actions, file or URL features, search/filter fields, import/export, and object identifiers.
- [ ] For every promising input, record the source, transformations, sink, user context, and expected security boundary.
- [ ] Rank hypotheses by ability to reach an administrator session, local.txt, file access, command execution, a shell, or proof.txt.
- [ ] Define the smallest harmless probe that can confirm or reject each hypothesis.
- [ ] Track negative results with the exact context and encoding used so failed tests are not repeated blindly.

## 03 · Confirm the primitive manually

- [ ] Change one thing at a time and compare status, length, headers, body, timing, side effects, and subsequent requests.
- [ ] Use delimiters, arithmetic, timing, callbacks, object swaps, or harmless file reads appropriate to the suspected sink.
- [ ] Reproduce the signal at least twice and rule out caching, unstable content, proxy errors, and normal application behavior.
- [ ] Identify the exact execution context, operating system, database dialect, template engine, parser, role, or URL parser where possible.
- [ ] Save the minimum confirming request, response, command, and screenshot.
- [ ] Only after manual confirmation, hand off repetitive enumeration to approved tools such as SQLMap, Tplmap, Wfuzz, or a proxy fuzzer.

## 04 · Escalate and chain

- [ ] Ask whether the primitive runs in an administrator browser, application process, database, internal service, or another user's authorization context.
- [ ] For browser-side execution, target the administrator session or a same-origin administrative action and verify the resulting role.
- [ ] For database or server-side execution, enumerate the minimum information needed to reach file read, file write, command execution, or a shell.
- [ ] For authorization issues, test horizontal and vertical operations across read, create, update, delete, file access, and administrative endpoints.
- [ ] For SSRF and XXE, enumerate reachable local services and files methodically; do not confuse callback confirmation with objective completion.
- [ ] Prefer short, reproducible chains. Record every dependency and transformation between source and final sink.
- [ ] After a shell, locate proof.txt from its expected original location; privilege escalation is not required for OSWA.

## 05 · Capture evidence immediately

- [ ] Submit local.txt and proof.txt values to the Exam Control Panel before the active exam ends.
- [ ] For a web UI proof, capture the actual target browser view and the relevant request in Burp or another proxy.
- [ ] For a shell proof, capture cat or type reading the file from its original location with target context visible.
- [ ] Record commands, full requests, relevant responses, console output, payload hosting, listener setup, and every prerequisite step.
- [ ] Use meaningful screenshot filenames and add them to the report while the chain is fresh.
- [ ] Reproduce the chain from a clean session or clean target state before marking the target complete.
- [ ] Confirm that another technically competent tester could repeat the result using only the report.

## 06 · Validate and submit

- [ ] Calculate documented points, not merely discovered vulnerabilities; train for at least eight evidenced flags.
- [ ] Review every target against its control-panel objective and verify every required screenshot is embedded.
- [ ] Include scripts and PoCs as text in the PDF; do not rely on separate files inside the archive.
- [ ] Render and review the final PDF for clipped commands, broken images, missing pages, and unreadable screenshots.
- [ ] Name the PDF and .7z exactly as required, preserve case, do not password-protect the archive, and keep it under 200 MB.
- [ ] Upload within the documentation window and compare the returned MD5 with the local archive hash.
- [ ] Retain the final PDF, archive, checksum, and upload confirmation until results are received.

> Do you want to live curiously?
