← Back to list

My OSWE Journey — Madhavan Maniyarasu

Who am i?

Madhavan M · 2025-09-22 05:06 · 4 claps · 4.3 min read
#offsec #oswe #infosec
Open on Medium ↗
Wiki topics: 🔒 · Cybersecurity

My OSWE Journey — Madhavan Maniyarasu

Who am i?

Hey — I’m Madhavan. I’ve been working at Sumeru Infosec for the past six years in various roles; my primary hat is as an application security engineer doing VAPT, source-code review, and consulting. Along the way I’ve also contributed as a developer on several Sumeru products using Laravel, Node.js and Python — work that helped carve my developer mindset and made understanding application internals much easier.

For whole of my career I hadn’t done any professional certification. When I finally had the opportunity to pick one, my dev mindset naturally pulled me toward the OSWE. Why OSWE? Because it focuses on deep, hands-on web application exploitation and it uses a white-box approach — the kind of strong, technical challenge I wanted.

If you don’t know, OSWE (OffSec Web Expert) is a professional certification from OffSec known for its rigorous, proctored exams. The OSWE practical exam is a 48‑hour, proctored exercise that tests advanced web exploitation techniques in a realistic, time-pressured environment.

Why OSWE (and why it mattered to me)

I wanted a certification that proved deep, applied skills rather than multiple-choice knowledge. OSWE appealed to me because:

  • It’s hands-on and practical — you work on real targets and must demonstrate exploitation end-to-end.
  • The white-box style suits someone who enjoys digging into source code and application logic.
  • The exam’s duration and proctoring make it a true endurance and technical-verification challenge.

My background in both development and AppSec made many concepts familiar, but OSWE pushed me to turn that knowledge into real-world attacks — chaining vulnerabilities end-to-end.

Preparation: Modules and Labs

I bought the Learn One subscription in November 2024 and started going through modules in December. Then life happened and I didn’t touch the course again until the end of May 2025.

Realizing I had only a few months left, I ramped up the study effort in June. I didn’t start the challenge labs in June, which I later regretted.

So what I did was schedule the exam for mid‑August and began working through the challenge labs. That deadline pressure pushed me to finish labs by spending a lot of late nights and weekends. Honestly, the challenge labs are the most rewarding part of OSWE. At first they feel overwhelming, but if you persist, they become manageable and extremely valuable.

Prep Tips:

  1. Start with modules, but treat the Challenge labs as the core. Modules give theory and show techniques; the labs are where you actually learn to apply them.
  2. Do the challenges early and often. Even if you skim modules, the challenge boxes teach you the mindset and the workflow required in the exam.

The Exam

The OSWE is a proctored, 48‑hour practical exam. You are given access to multiple target applications and their source code, and the goal is to discover and exploit vulnerabilities, capture proof and local files (flags), develop a single click PoC script, and deliver a detailed report.

I scheduled my exam for August 22 at 1:30 PM IST and logged in 15 minutes early, as instructed. The proctoring setup ran longer than expected and I only began work around 2:00 PM. I started with Machine 1 and found the first flag around 7:00 PM — I immediately automated the steps up to that vulnerability so I could reproduce it reliably.

After that win I focused on achieving RCE on Machine 1 but ran into several dead ends and time sinks; by midnight I hadn’t made real progress, so I switched to Machine 2. That paid off: early on the morning of August 23 (around 6:00 AM) I found the first flag on Machine 2. Before the 24‑hour mark I had two flags — one on each machine — and only needed one more to pass. I slept for four hours to reset.

Came back and I discovered a potential RCE on Machine 2 around 4:00 PM on August 23. In hindsight, I was looking for an interactive shell there — a choice that cost me time. I struggled to get a reliable reverse shell through the night, gave up and went to sleep again to rest. After waking, I used an earlier, more reliable RCE approach to simply retrieve the flag, then quickly wrote a clean PoC script for the final machine.

I finished scripting and testing with about an hour left in the exam window. That hour went toward validating the exploits and taking all required screenshots; I wrapped up at 1:15 PM and the session ended. The report deadline was August 25 at 1:15 PM.

Me when submitting the report

Me when submitting the report

I left report writing too late and only started around 8:00 AM on the 25th — a risky mistake. somehow managed and submitted the report at 1:13 PM, just two minutes before the deadline.

Waiting for the result was nerve‑wracking — OffSec returned my result after eight working days.

Vetri Vetri

Vetri Vetri

Key Takeaways

  • Manage your stamina. The 48‑hour format is draining; schedule breaks and short naps to maintain focus.
  • Know when to switch. Avoid getting stuck in dead ends — move to other leads and return later with a fresh perspective.
  • Script early, script often. Build small, dependable exploit scripts as you go — they’ll save time and reduce mistakes.
  • Dont overlook reporting. Treat the report as part of the exam strategy, not an afterthought. Spend some good time on the reporting.

Conclusion

If you have a decent web‑app pentest background and a developer mindset, OSWE is absolutely within reach — it’s a grind, but it’s also one of the most satisfying certification.

Reference / Resources (personal notes)


메타데이터
post_id
b36091a291b5
slug
my-oswe-journey-madhavan-maniyarasu-b36091a291b5
url
https://medium.com/@i4mmaddy/my-oswe-journey-madhavan-maniyarasu-b36091a291b5
canonical_url
https://medium.com/@i4mmaddy/my-oswe-journey-madhavan-maniyarasu-b36091a291b5
author_url
https://medium.com/@i4mmaddy
status
ok
fetched_at
2026-06-26 03:39:16