A complete study guide covering advanced web application security, exploitation techniques, source code review, vulnerability research, and OSWE exam methodology.
Mostafa Ibrahim — DarcHacker
- 🔗 LinkedIn: Mostafa Ibrahim
- 📅 Created: 2026
- 📚 Status: Complete Web Security Exploitation Guide
This repository contains my complete OSWE study guide, organized as a structured reference for advanced web application security and exploitation.
The goal is not only to understand how to exploit vulnerabilities, but to understand why applications become vulnerable, how application logic can fail, and how vulnerabilities can be identified through analysis and source code review.
| Module | Topic | Key Skills |
|---|---|---|
| 00 | Web App Fundamentals | HTTP, Cookies, Sessions, HTTPS |
| 01 | Burp Suite Mastery | Proxy, Scanner, Intruder, Repeater |
| 02 | SQL Injection Exploitation | Extraction, Blind SQLi, Time-based |
| 03 | Authentication Mechanisms | Bypass, Brute Force, Session Fixation |
| 04 | Authorization & Access Control | IDOR, Privilege Escalation, ACL |
| 05 | Business Logic Flaws | Rate Limiting, State Manipulation |
| 06 | Server-Side Request Forgery | SSRF, Cloud Metadata, Bypasses |
| 07 | XML External Entity Injection | XXE, Billion Laughs, DTD Abuse |
| 08 | Cross-Site Scripting | Reflected, Stored, DOM-based XSS |
| 09 | Cross-Site Request Forgery | CSRF, Token Bypass, SameSite |
| 10 | Deserialization Attacks | Java, PHP, Python Gadgets |
| 11 | Server-Side Template Injection | SSTI, Code Execution, Payloads |
| 12 | NoSQL & Injection Variants | MongoDB, Injection, Bypasses |
| 13 | API Security | REST/GraphQL, Authentication, IDOR |
| 14 | OAuth & OpenID Connect | Flow Attacks, Token Theft, Bypasses |
| 15 | WebSocket Security | Protocol, CSWSH, Exploitation |
| 16 | Advanced Exploitation | Chaining, Multi-stage, Complex Scenarios |
| 17 | Source Code Review | Vulnerability Identification, Analysis |
Throughout the guide, the focus is on:
- Advanced Web Application Security
- Web Vulnerability Research
- Exploitation Methodology
- Burp Suite
- SQL Injection
- Authentication & Authorization
- Business Logic Vulnerabilities
- SSRF & XXE
- XSS & CSRF
- Deserialization
- SSTI
- NoSQL Injection
- REST & GraphQL API Security
- OAuth & OpenID Connect
- WebSocket Security
- Advanced Exploitation & Vulnerability Chaining
- Source Code Review
Don't focus only on how to exploit a vulnerability.
Instead:
- Understand the application's logic
- Identify developer assumptions
- Predict potential failure points
- Understand the root cause of the vulnerability
For every vulnerability, consider:
- What are developers trying to protect?
- What assumptions are being made?
- Where could those assumptions fail?
- How could the attack be detected?
A professional security assessment should be reproducible.
The guide emphasizes:
- Reproducible exploitation steps
- Evidence and screenshots
- Clear technical explanations
- A timeline of events
Security testing should always be performed responsibly.
- Only test systems you are authorized to test
- Don't access unnecessary data
- Remove testing artifacts when appropriate
- Provide value to the organization
- Communicate findings professionally
Web security continuously evolves.
Recommended practices include:
- Reading security advisories
- Following security researchers
- Practicing on CTF platforms
- Studying real-world vulnerability disclosures
- Sharing security knowledge with the community
The guide references resources including:
- OWASP API Security Top 10
- PortSwigger Web Security Academy
- HackerOne disclosed reports
- CVSS Calculator
- CWE — Common Weakness Enumeration
This repository is intended for educational and authorized security testing purposes only.
Only test applications, systems, and infrastructure where you have explicit permission to conduct security testing.
The author is not responsible for misuse of the information contained in this repository.
The goal is not to hack the application. The goal is to understand WHY the application is hackable.
The complete study material is available in:
OSWE_Complete_Study_Guide.md
OSWE | Offensive Security
By DarcHacker — Mostafa Ibrahim
Complete Web Security Exploitation Guide · 2026