My Experience with OffSec’s WEB-200 and the OSWA Exam

I recently passed the OffSec Web Assessor certification exam after completing WEB-200, OffSec’s foundational web application hacking course. The course introduces common web vulnerabilities and teaches students how to discover and exploit them using Kali Linux and tools such as Burp Suite, Nmap, Gobuster, Wfuzz, and sqlmap.

WEB-200 consists of 16 modules covering topics such as cross-site scripting, SQL injection, CSRF, CORS, web reconnaissance, directory and parameter discovery, SSRF, XXE, SSTI, and IDOR. It also includes around a dozen hands-on labs, including nine challenge labs designed to test whether you can combine the techniques taught throughout the course.

At the time of writing, the course costs $1,499 and includes three months of access to the study material and labs.

A lot of the attacks were already familiar to me, but I still found value in the course. In particular, it helped strengthen my understanding of XXE, SSTI, IDOR, and SSRF. These were areas where I was not as confident before starting WEB-200.

The OSWA exam has a format similar to the OSCP. It is a proctored, open-book exam that lasts 24 hours. AI tools and asking for help online are prohibited. Students can search existing content in the OffSec student Discord, but they cannot message other students for assistance during the exam.

Unlike the OSCP, Burp Suite Professional is permitted. Thankfully, sqlmap is also allowed. I would have found the exam considerably more difficult if sqlmap had been prohibited.

Overall, I was somewhat pleased with WEB-200, but I do not think it is the best web application security course available. For most people, I would recommend completing PortSwigger’s Web Security Academy instead. It covers a much wider range of attacks and teaches more advanced ways to use Burp Suite Professional, which I believe provides greater practical value.

WEB-200 is still a reasonable introduction for someone who wants a structured path, hands-on practice, and an OffSec certification. It provides a solid foundation, but it should be treated as the beginning of a much longer journey into penetration testing and application security.

Privacy Preference Center