Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
exploit-writing-for-oswe — Tips on how to write exploit scripts (faster!) | Kitploit
Tools/GitHubGitHub/rizemon/exploit-writing-for-oswe
Scripting & AutomationWeb Application ExploitationWeb SecurityPenetration TestingLearning & EducationCurated ResourcesPayload Development
GitHubrizemon/exploit-writing-for-oswe

exploit-writing-for-oswe

Tips on how to write exploit scripts (faster!)

View Repository
591112162 years agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Exploit Writing for OSWE

Background

What

This repository contains a list of useful snippets and tips that pertain to the writing of exploit scripts in the OSWE labs and certification exam.

Some examples here may go against certain coding practices, but our end goal is to write the exploit script fast and correct.

The Code Snippets section is a great place to start if you are not experienced in using the requests library or are new to Python. Otherwise, feel free to skip to the Reusable Code section or the Tips section.

Why

  • While there are many write-ups, reviews, and notes on the certification, few resources specifically focus on the process of writing exploits.
  • Writing the exploit script can be daunting, especially for those who are new to Python or have little experience interacting with web applications through code.
  • Time spent on identifying vulnerabilities and documenting an exam report can fluctuate considerably, but the time spent on developing the exploit script can be minimized and kept constant if mastered well.

Table of Contents

  • Exploit Writing for OSWE
    • Background
      • What
      • Why
    • Table of Contents
    • Code Snippets
      • Starting Template
      • Useful imports
      • Using the requests library
        • Sending the simplest HTTP request
        • Specifying different HTTP methods
        • Reading the HTTP response
        • Sending data as a query string in the URL (Using params argument)
        • Sending data as a query string in the body (Using data argument)
        • Sending data as a JSON in the body (Using json argument)
        • Sending a file in the body (Using files argument)
        • Setting HTTP headers (Using headers argument)
        • Setting HTTP cookies (Using cookies argument)
        • Disabling following of 3XX redirects (Using allow_redirects argument)
        • Interacting with an unverified HTTPS server (Using verify argument)
        • Sending request through a HTTP proxy (Using proxies argument)
        • Creating a Session
        • Setting persistent cookies
        • Setting persistent headers
      • Troubleshooting
        • Use Wireshark and filter for HTTP requests
        • Print contents of the HTTP request
        • Proxy HTTP request through Burp Suite and inspect
      • Reusable code
        • Serving files via HTTP
        • Stealing HTTP cookies
        • Speeding up SQL injections
    • Tips
      • Perform a sanity check after every HTTP request using assert
      • Print meaning messages after each step
      • Separate each exploitation step into its own function
      • Create a global Session object so it does not need to be explictly passed to each function call
      • Create a global BASE_URL string and construct the required URLs from it
      • To force all HTTP requests to go through Burp Suite without the use of the proxies argument , set the HTTP_PROXY / HTTPS_PROXY environment variable when running
      • Apply encoding/decoding scheme(s) to enable safe transmission of payloads
      • Use """ to create the payload string if it contains both single (') and double quotes (")
      • Speed up SQL injections using multithreading
      • Hardcode an authenticated user's cookie when developing exploits for authenticated features
      • Avoid using f-strings (f"") or str.format if the payload contains too many curly braces ({})

Code Snippets

Starting Template

import requests

def main():
    print("Hello World!")

if __name__ == __main__:
    main()

Useful imports

# For sending HTTP requests
import requests

# For Base64 encoding/decoding
from base64 import b64encode, b64decode, urlsafe_b64encode, urlsafe_b64decode

# For getting current time or for calculating time delays
from time import time

# For regular expressions
import re

# For running shell commands
import subprocess

# For multithreading
from concurrent.futures import ThreadPoolExecutor

# For running a HTTP server in the background
import threading
from http.server import HTTPServer, BaseHTTPRequestHandler

# For parsing HTTP cookies
from http import cookies

# For getting command-line arguments
import sys

Using the requests library

Sending the simplest HTTP request

resp_obj = requests.get("https://github.com")

Specifying different HTTP methods

# GET method
requests.get("https://github.com")

# POST method
requests.post("https://github.com")

# PUT method
requests.put("https://github.com")

# PATCH method
requests.patch("https://github.com")

# DELETE method
requests.delete("https://github.com")

Reading the HTTP response

resp_obj = requests.get("https://github.com")

# HTTP status code (e.g 404, 500, 301)
resp_obj.status_code

# HTTP response headers (e.g Location, Content-Disposition)
resp_obj.headers["Location"]

# Body as bytes
resp_obj.content

# Body as a string
resp_obj.text

# Body as a dictionary (if body is a JSON)
resp_obj.json()

Sending data as a query string in the URL (Using params argument)

params = {
    "foo": "bar"
}

requests.get("https://github.com", params=params)
Download Tool