Skip to content
Exploit Labs
WEB-300 · OSWE · Teams and individuals

WEB-300: what the course covers - and what we add.

WEB-300 is the whitebox advanced course (OSWE): source code review, finding authentication bypasses, and building your own exploit chains up to remote code execution in real applications.

Who it is for

Experienced web testers and application security engineers with source access.

Course content (official scope)

  • Source review with an attacker mindset
  • Authentication bypasses
  • Deserialisation and type juggling
  • Writing your own exploits
  • Automating the exploit

Course content, labs and the OSWE exam are provided by OffSec. The official course description always takes precedence. This page reviewed: 2026-08-07.

What Exploit Labs adds
  • +A review of your own application as the practical case
  • +Handover into an application pentest engagement where internal capacity is missing

For security teams

Multiple people, role paths, reporting and procurement run through OffSec Learn Enterprise.

See Learn Enterprise

For individual practitioners

Individual licence, access duration, exam attempts and preparation - start here.

See individual licences