Train to become OSWA certified
WEB-200 (OSWA)
Web Attacks with Kali Linux
OffSec WEB-200 teaches you the practical basics for analyzing and carrying out web attacks. You will learn to identify and exploit typical vulnerabilities in web applications and understand their effects. Through realistic labs and the use of Kali Linux, you will develop a deep understanding of attack techniques in the web environment.
Included services
Your added value with the Red & Blue Alliance
- Training with a strong practical orientation
- Individually selected OffSec license (Course & Cert, Learn One, Learn Enterprise)
- Professional team of trainers with many years of practical experience in IT security companies
- Course language English – trainers are at least bilingual (DE/EN)
- Catering included during the training days (for public face-to-face training courses)
Trainer support included – even after the course: Our Discord channel provides you with direct exchange with trainers, professional support and targeted guidance on your way to certification.
Aims of the training
WEB-200 (OSWA)
The course enables you to systematically check web applications for vulnerabilities and assess security gaps.
- You identify typical web vulnerabilities
- You analyze and exploit web applications
- You understand common attack techniques (e.g. OWASP Top 10)
- You use tools from Kali Linux specifically
- You assess risks and security gaps
This will enable you to realistically test web applications and make a well-founded assessment of security risks.
Target group & requirements
Target group
The course is aimed at participants who want to build up or deepen their knowledge of web security and pentesting.
- Beginners in Web Application Security
- Prospective penetration testers
- Security analysts with a focus on the web
- Developers with an interest in secure software
Ideal for you if you want to learn how web applications work from an attacker’s perspective.
Prerequisites
For successful participation, you should have basic technical knowledge.
- Basic knowledge of IT & networks
- Basic knowledge of web technologies (HTTP, HTML, cookies)
- First experience with Linux / Kali Linux (an advantage)
- Basic understanding of IT security
- Analytical thinking and interest in web applications
Initial practical experience is helpful, but not essential.
Seminar content
Contents of the WEB-200 (OSWA)
The focus is on practical techniques for analyzing and exploiting web vulnerabilities.
- Web Application Fundamentals
Basics of HTTP, sessions and web architectures - Information Gathering
Methods for gathering information about target systems - Authentication Attacks
Attacks on login mechanisms and sessions - Injection Attacks
SQL Injection, Command Injection and similar techniques - Cross-site scripting (XSS)
Analysis and exploitation of client-side vulnerabilities - File Inclusion & File Upload Attacks
Abuse of insecure file handling mechanisms - Access Control & Authorization Issues
Circumvention of access controls - Tooling with Kali Linux
Use of tools such as Burp Suite, Nikto or dirb
The aim is to identify and exploit web vulnerabilities and to realistically assess their impact.
The right license for your requirements
With Course & Cert, Learn One and Learn Enterprise, we offer three different learning models – from targeted certification to comprehensive, scalable training. The following overview shows the most important differences at a glance.
Course & Cert
The classic entry option for a single course.
- 1 course + certification
- 90 days Lab access
- 1 examination attempt
- Download the course materials
Ideal for you if you want to prepare specifically for certification
👉 In short: focused, affordable, but not very flexible
Learn One
Your annual subscription with significantly more options.
- 1 200 or 300 level course + certification
- 365 days Lab access
- 2 exam attempts
- Access to exercise environments, challenge labs and learning paths
- Download the course materials
Ideal for you if you want to build up several skills or broaden your base
👉 In short: flexible, comprehensive, highly practice-oriented
Learn Enterprise
The corporate solution for structured team training.
- Unlimited choice of courses
- 6 examination attempts/certification per year
- 365 days Lab access
- Central management of users, progress and licenses
- Reporting & analytics for training progress
- Individual learning paths for different roles (e.g. SOC, Pentest, Blue Team)
- Scalable for larger teams or entire departments
👉 In short: scalable, controllable, ideal for strategic training
