OSWE Study Plan
White-box web exploitation for people who read source code for fun. A free, day-by-day OSWE schedule built from the official WEB-300: Advanced Web Attacks and Exploitation syllabus, scaled to your exam date and weekly hours.
- Approx. cost
- $1,749–$2,749
- Difficulty
- ♥♥♥♥♥
- Study time
- about 264h
- Start level
- Advanced
> How long does OSWE take?
The plan assumes about 264 study hours. Here is how that stretches across different weekly schedules.
| Hours per week | Time to finish |
|---|---|
| 5 hours | about 53 weeks (12.2 months) |
| 10 hours | about 27 weeks (6.2 months) |
| 15 hours | about 18 weeks (4.2 months) |
| 20 hours | about 14 weeks (3.2 months) |
| 30 hours | about 9 weeks (2.1 months) |
> OSWE exam format
OffSec · WEB-300: Advanced Web Attacks and Exploitation
- 47h 45m hands-on exam + 24h to submit report
- White-box, source-code-driven vulnerability chains against live targets
- Professional report with reproducible proof required for every objective
- OSCP-level experience strongly recommended before starting
- OSWE certification does not expire
> OSWE syllabus and study hours
Every topic in the plan, in order, with its baseline hours. The planner shrinks or stretches these to fit your dates.
Methodology & Source Review
Learn to read code like an attacker before you exploit it.
- Web Security Tools & Methodologies8h · learn
- Source Code Analysis10h · learn
- Blind SQL Injection8h · learn
- Data Exfiltration (SQLi, XXE & File Uploads)6h · learn
- XML External Entity Injection6h · learn
- RCE via Database Functions6h · learn
Deserialization & RCE
Chain source-level flaws into remote code execution.
- .NET Deserialization10h · learn
- Remote Code Execution8h · learn
- Server-Side Template Injection8h · learn
- PostgreSQL Extensions & User-Defined Functions8h · learn
- UDF Reverse Shells6h · learn
- PostgreSQL Large Objects6h · learn
Client & Application Logic
Browser-side and application-logic vulnerability classes.
- JavaScript Prototype Pollution8h · learn
- Advanced Server-Side Request Forgery (SSRF)8h · learn
- Persistent Cross-Site Scripting6h · learn
- DOM-Based Cross-Site Scripting (Black Box)6h · learn
- Session Hijacking6h · learn
- Weak Random Token Generation4h · learn
Filter & Auth Bypasses
Get past the guardrails developers put up.
- Bypassing File Upload Restrictions & Extension Filters8h · learn
- PHP Type Juggling with Loose Comparisons6h · learn
- Bypassing REGEX Restrictions4h · learn
- Magic Hashes4h · learn
- Bypassing Character Restrictions6h · learn
- OS Command Injection via WebSockets (Black Box)6h · learn
Challenge Labs
Exam-style white-box targets, end to end.
- 20 Challenge Labs60h · lab
- Reproduce public N-day web exploits16h · lab
Final Boss Prep
Source-review checklists and a timed dry run.
- Build a source-review checklist per framework8h · review
- Write a full report from one challenge lab6h · review
- Timed 48-hour mock exam12h · review
> Where to practise for OSWE
Each task in your plan lists practice labs for its own topic. These are the best places to put in extra hands-on hours:
- All Web Security Academy labs (PortSwigger)
- Mystery lab challenge (PortSwigger)
- Juice Shop (practice app) (OWASP)
> OSWE exam-day checklist
General logistics for exam week. The official exam guide always takes priority if it differs.
One to two weeks before
- Schedule your exam and add the start time, time zone and deadline to your calendar
- Read the official exam guide end to end: rules, allowed and banned tools, and what counts as proof
- Set up your source-review environment and debugger for each language you might meet
- Keep a proof-of-concept script template ready: every result must be reproducible
- Complete a full-length timed practice run (48 hours if you can) on your exam setup
- Finalize your note-taking setup and templates (see the notes starter below)
- Build and review your cheat sheets and command references
- Arrange time off, tell people you will be unavailable, and plan your meals ahead
- Check your ID is valid and matches the name on your exam account
Machine and network
- Charge and test a backup device or phone hotspot, and know how to contact support if your connection drops
- Plug in your laptop and turn off sleep, updates and notifications for the exam
- Test the VPN or lab connection early and know how to reconnect after a drop
- Update your attack VM, take a clean snapshot and keep a spare
- Install and test every tool you plan to use, and check none of them are banned
- Test your screenshot hotkeys and make sure you have plenty of free disk space
Proctoring and room
- Test your webcam, microphone and screen sharing on the proctoring platform
- Clear your desk and room as the rules require, and tell housemates not to interrupt
- Confirm what is allowed at your desk (second monitor, phone, notes, paper) and follow it exactly
- Learn the rules for breaks and for leaving the camera view
- Have your ID ready and know the check-in steps
During the exam
- Sleep well the night before, and skip last-minute cramming
- Prepare food and water, and set timers for break reminders
- Read the brief and scope carefully before you touch anything
- Write notes and capture proof as you go, not at the end
- Time-box each target and move on when stuck. You can come back later
- Stop new attacks with enough time left to verify your evidence
Report and submission
- Copy your report template and fill in the easy parts (scope, methodology) while you work
- Check every finding has reproducible steps and screenshots
- Proofread: could someone else follow each step?
- Export in the exact format and naming the exam guide requires
- Submit with a buffer before the deadline and confirm it was received
Suggested exam-day rhythm
- Hour 0 to 1. Connect, confirm the VPN, read the brief, set up your notes and plan the first day.
- Day 1. Enumerate everything, then go after the most promising targets in 90-minute blocks with short breaks.
- 1 sleep window. Plan 6 or more hours each night. Write down where you stopped and your next three ideas before you sleep.
- Meals and movement. Eat proper meals away from the desk and walk outside at least once a day.
- Last 5 hours. Stop new attacks, verify evidence and outline the report while everything is fresh.
- After the hands-on part. Write the report in focused blocks, proofread, and submit with a buffer before the deadline.
▶ Open the interactive OSWE exam kit
The kit lets you tick items off, download a notes starter and report template, and see a readiness score from your plan progress.
> Passed OSWE with PWN PATH
No OSWE debriefs yet
Passed a cert? A short debrief helps the next learner plan their own run, and it only takes a couple of minutes.
▶ Share my debriefDebriefs are self-reported. See all pass stories.
> Frequently asked questions
How long does it take to prepare for OSWE?
PWN PATH builds the OSWE plan on about 264 study hours. At 10 hours a week that is roughly 27 weeks, and at 20 hours a week roughly 14 weeks. Your own timeline depends on how much of the material you already know.
What is the OSWE exam like?
47h 45m hands-on exam + 24h to submit report. White-box, source-code-driven vulnerability chains against live targets. Professional report with reproducible proof required for every objective. OSCP-level experience strongly recommended before starting. OSWE certification does not expire.
How hard is OSWE?
We rate OSWE 5 out of 5. It suits strong programmers who enjoy white-box source review. OSCP-level experience and comfort reading PHP, Java, .NET and JavaScript.
How much does OSWE cost?
OffSec bundles start around $1,749 (course, 90 days of labs, one exam attempt); Learn One is about $2,749 per year with two attempts. Prices are approximate, in US dollars unless a currency is shown, and change often. Confirm with the vendor before you buy.
What should I study first for OSWE?
Start with the "Methodology & Source Review" phase: Web Security Tools & Methodologies, Source Code Analysis, Blind SQL Injection. The planner puts topics in a sensible order and scales the hours to the time you have.
What are the prerequisites for OSWE?
OSCP-level experience and comfort reading PHP, Java, .NET and JavaScript.
What should I do the week before the OSWE exam?
Re-read the official exam guide for rules and banned tools, test your machine, network and VPN or lab connection, finish a full timed practice run, finalize your notes and cheat sheets, and plan your meals, breaks and sleep. The exam-day checklist on this page covers it step by step.
How should I handle breaks and sleep during the OSWE exam?
Hour 0 to 1: Connect, confirm the VPN, read the brief, set up your notes and plan the first day. Day 1: Enumerate everything, then go after the most promising targets in 90-minute blocks with short breaks. 1 sleep window: Plan 6 or more hours each night. Write down where you stopped and your next three ideas before you sleep. Meals and movement: Eat proper meals away from the desk and walk outside at least once a day.
What should I take after OSWE?
OSWE is one of the furthest steps in its track. The roadmap shows related certs in other tracks.
Is the PWN PATH study planner free?
Yes. There are no accounts and no sign-up. Your plan and progress are saved in your browser, and you can export a backup file, add the schedule to your calendar or print it.
> Plan your path
Good stepping stones before OSWE:
More in web application security:
Not sure OSWE is right for you? Take the one-minute cert quiz.