eWPTX Certification Review and Exam

Ömür Uğur
2 min readDec 19, 2022

Hello to everyone,

Recently, I successfully completed the eWPTXv2 certification, which is the exam of eLearn Security, and I decided to write a blog while the information was fresh. First of all, I got this certificate because it was downloading during the black friday discount period, otherwise it was not a certificate I wanted 🙂

You can take the training published by INE to learn about the exam and training, or you can get this certificate by purchasing the exam directly (current price $400).

It offers free admission to the certification exam if you purchase annual training from the INE.
The tutorials focus on topics that general penetration tester friends know (it didn’t add much to me, frankly, I just skimmed through the tutorials ☹). If you are a penetration tester, you can take the exam directly without training.

If you do not take an active role in penetration tests, you can draw a roadmap in the form of WPTX after JPT-WPT.
This is because WPTX certification is elearn’s most difficult certification exam in web penetration testing.

I particularly liked that the exam had sections on:

XML attacks (including advanced)
Server-side attacks such as SSRF, XSLT, and template injections.
Authentication attacks against JWT, OAuth and 2FA, API penetration tests: REST, SOAP etc.
Push-up;
• The exam lasts for seven days and you can take the exam at any time.
• It describes in detail which applications you will test in the exam, which path you should follow and what kind of report you should write. It is not enough to get a flag, a very comprehensive report with detailed solution suggestions is required, remember that 🙂

If we look at the shortcomings of training and certification
Cons of course, as with every certificate, there are eLearn certificates and exams.
I think the absence of an auditor in the exam lowers the value of the certificate.
I hope the information was useful.

See you in my next certification adventure.. GICSSP coming soon 😊

--

--

Ömür Uğur

Pentest Manager at Turk Telekom | Sr.Penetration Tester | Bug Bounty Hunter | OSCP | OSWP |AWS |CRTO | eMAPT | eWPTX | CEH Master | ISO 27001 LA | ICS | @Synack