CWES ยท Web Exploitation

Web Exploitation Specialist

Intermediate

A 3-day hands-on certification. A private two-service corporate network is provisioned on booking: enumerate, exploit and pivot through 16 tasks covering SQL injection, IDOR, command injection, LFI, XXE, SSRF, JWT forgery and secret leakage. Passing the practical (70%) then requires a written penetration-test report that an examiner reviews before certification is granted.

Flags / tasks 16
Environment Live targets
Access Super VIP
Price TBA
Objectives

Flag every task to complete the lab

16 aims
1 Enumerate the second service on this host. What Server header does the RegBridge gateway report?
2 The portal's robots.txt disallows a /dev/ path. Open the developer notes there and submit the flag.
3 A leaked SQL backup is downloadable from the portal. What is the backup file's name?
4 Download the SQL backup and extract the flag hidden inside it.
5 Bypass the legacy admin login to reach the admin console. Submit the flag.
6 Which API endpoint enumerates all available API endpoints? (Submit the path.)
7 The users API is vulnerable to IDOR. Enumerate the administrator's profile and submit the flag in its note.
8 The network tools page runs ping without sanitizing input. Inject a command to read /flag5.txt.
9 The download tool is vulnerable to local file inclusion. Read /flag6.txt.
10 The XML import endpoint resolves external entities. Exfiltrate /flag7.txt via XXE.
11 The gateway exposes an internal flag route that only answers requests from the gateway host itself. What is that route?
12 Use the portal's SSRF (the fetch tool) to reach the gateway's internal route and submit the flag.
13 A JavaScript asset leaks the JWT signing secret. What is it?
14 Forge an admin JWT with the leaked secret and query the admin API. Submit the flag.
15 The API documentation leaks an admin API key. What is it?
16 What internal hostname is the gateway registered as?
Learning outcomes

Mapped skills

  • OWASP Web Security Testing Guide v4.2
  • MITRE ATT&CK (web-facing techniques)
  • OWASP Top 10 (2021)

On start, a dedicated live environment is provisioned for you. While your Super VIP membership is active you can spawn it, work through the objectives, and destroy it whenever you like. Progress is saved as you go. Complete all objectives to earn a unique, publicly verifiable credential (verify link, score snapshot and integrity hash) bound to this Pro Lab.

Pro Labs require an active Super VIP membership.
Sign in and upgrade to Super VIP to unlock this lab.