Learn OffSec Web Assessor (WEB-200) through our classroom and online OSWA training at WebAsha Technologies. The course builds the hands-on, 'Try Harder' skills that the OSWA exam tests.
Training overview:
OSWA is OffSec's foundational web-application security certification, earned through the WEB-200 course. You learn to find and exploit real web vulnerabilities: cross-site scripting, SQL injection, directory traversal, XXE, server-side template injection, command injection, SSRF and IDOR. The certification is earned in a 24-hour hands-on exam against five live web targets.
Intended audience:
The course suits aspiring web-application penetration testers, application security analysts, developers moving into security, and bug-bounty hunters targeting the OSWA certification.
Topics covered:
-
Cross-site scripting: Discovery and exploitation.
-
SQL injection: Extracting data and access.
-
Directory traversal: Reaching files outside the web root.
-
XXE: Abusing XML parsers.
-
Template injection: Server-side template attacks.
-
Command injection: Executing OS commands.
-
SSRF: Forcing the server to make requests.
-
IDOR: Accessing other users' data.
Requirements:
Comfort with Linux and the command line is recommended. Online participants need a stable internet connection and a laptop/desktop for the live labs.
Prerequisites:
OffSec recommends familiarity with core web technologies (HTML, CSS, JavaScript), networking fundamentals and Linux basics. No formal prerequisite is required.
Career benefits:
Employers hire for web assessment skills. In India, OSWA-certified professionals typically earn ₹5 LPA to ₹32+ LPA in application-security roles.