WEB-300: Advanced Web Attacks and Exploitation - on the way to OSWE.
WEB-300 is the whitebox advanced course (OSWE): source review with an attacker mindset, authentication bypasses, and building your own exploit chains up to remote code execution in real applications.

- Certification
- OSWE - OffSec Web Expert
- Level
- Advanced
- Discipline
- Attack
- Audience
- Teams and individuals
Who this course is for
Experienced web testers and application security engineers with source access.
Not the right course yet if
- -You cannot read someone else's code
- -Black-box web is still new - start with WEB-200
- →Review large codebases specifically for exploitable flaws
- →Write and automate your own exploits
- →Evidence attack chains from a line of code to RCE
- ·Confident web testing experience, ideally OSWA level
- ·Reading and writing code in at least one language
- ·Patience for debugging
Not sure whether you meet them? We run a short placement conversation before you buy.
What WEB-300 covers.
- Source review with an attacker mindset
- Authentication bypasses
- Deserialisation and type juggling
Course content, labs and the OSWE exam are provided by OffSec. Precedence always sits with the official course description. This page reviewed: 2026-08-12.
Labs and format
Labs with complete applications including source code, plus a challenge lab for exam preparation.
Exam and credential
48-hour practical exam with a report. Passing awards the OSWE certification.
The packages that include WEB-300.
Prices in EUR, net, plus statutory VAT. Invoiced through a German entity. Your course is pre-selected at checkout.
You have a focused block of time and want to sit the exam soon.
- ▸ 90 days of course access including labs
- ▸ 1 exam attempt
- ▸ Exactly this course
Study alongside a job, without lab time pressure.
- ▸ 365 days of course access including labs
- ▸ 2 exam attempts
- ▸ Proving Grounds Practice, KLCP and OSWP included
Several people in a team, with evidenced progression.
- ▸ The full OffSec catalogue
- ▸ Learning paths and reporting
- ▸ Reassignable from 5 seats
- +A review of your own application as the practical case
- +Handover into an application pentest engagement where internal capacity is missing
For security teams
Multiple people, role paths, reporting and procurement run through OffSec Learn Enterprise.
See Learn EnterpriseTeam capability development
Badges, learning paths and evidence across attack, defend, build and govern.
See the capability mapOther hackers also bought ... ;)
JavaScript/Node, Java, .NET and PHP among others. You do not need to master all of them, but you must read code.
Notably harder than OSCP. Without completing the labs and building debugging routine it is very tough.
Not sure whether WEB-300 is the right course?
We run a short placement conversation: background, study time, goal. Then we recommend a course and package - even when it is the cheaper one.
From training to the engagement: our testing services
- Red TeamingThreat intelligence-led red teaming: attack paths, detection testing and proven business impact.Read more
- Pentest as a ServiceContinuous testing at release cadence instead of one audit per year.Read more
- Hybrid PentestAutomated coverage plus manual depth - evidence for ISMS, DORA and NIS2.Read more
- DORA TLPTThreat-led penetration testing under DORA: scoping, run-through and regulator documentation.Read more