Useful tips and resources for preparing for exam.
Note: Only topics from the course will come up on the exam in most cases with slight variations.
Real world examples
| Order | Name | Link |
|---|---|---|
| 1 | Reflected XSS to Account Takeover | https://medium.com/a-bugz-life/from-reflected-xss-to-account-takeover-showing-xss-impact-9bc6dd35d4e6 |
| 2 | dotCMS 5.1.5: Exploiting H2 SQL injection to RCE | https://blog.sonarsource.com/dotcms515-sqli-to-rce?redirect=rips |
| 3 | ATutor Authentication Bypass | https://rebraws.github.io/ATutorAuthBypass/ |
Python examples of pocs that can be used for write single click pocs
Exam related resources that might be useful
Hackthebox writeups with vulnerabilities and exploitation paths similiar to lab and course content. Video walkthroughs of these writeups can also be found here
Good resources to learn before starting AWAE or after finishing your OSWE exam