Offensive Security: Advanced Web Attacks and Exploitation New content for 2020 - get 50% more

Looks like the AWAE course has been updated this year with %50 more content. Same pricing.
WHAT’S NEW IN AWAE FOR 2020?
New
- Material
- XML external entity injection
- Weak random token generation
- DOM XSS
- Server side template injection
- Command injection via websockets (black box material)
- Labs: Three new private exercise machines with custom web apps
- Updated control panel
In AWAE, students will learn how to:
- Perform a deep analysis on decompiled web app source code
- Identify logical vulnerabilities that many enterprise scanners are unable to detect
- Combine logical vulnerabilities to create a proof of concept on a web app
- Exploit vulnerabilities by chaining them into complex attacks
Certs: CISSP, EnCE, OSCP, CRTP, eCTHPv2, eCPPT, eCIR, LFCS, CEH, SPLK-1002, SC-200, SC-300, AZ-900, AZ-500, VHL:Advanced+
2023 Cert Goals: SC-100, eCPTX
2023 Cert Goals: SC-100, eCPTX
Comments
Did it used to be 48 hours?
Security+, eJPT, CySA+, PenTest+,
Cisco CyberOps, GCIH, VHL,
In progress: OSCP
Security Engineer/Analyst/Geek, Red & Blue Teams
OSCP, GCFA, GWAPT, CISSP, OSWP, AWS SA-A, AWS Security, Sec+, Linux+, CCNA Cyber Ops, CCSK
2021 goals: maybe AWAE or SLAE, bunch o' courses and red team labs?
With the little experience I have with this path, I spent a month studying wetw0rk study guide to prep for the AWAE course. I was only able to touch 25% of the prep work "experience" one should have before attempting AWAE. I had a hard time understanding that little 25% within the month. I felt I needed a good 3-4 months of this prep work before attempting the AWAE course which I heard is dry and a lot of code review. Without prior experience I would find it hard for anyone to pass this cert within 30 days.
Not an authoritative statement, just my little experience and what I have read from other people experience.
2023 Cert Goals: SC-100, eCPTX
If it were me, I would need
- 3-4 months doing the AWAE prep from wetw0rks.
- Possibly another added 2 months doing Burp Suite free online courses and triple-reading "The Web Application Hacker's Handbook: Finding and Exploiting Security Flaws 2nd Edition."
- I would also consider another month of webapp pentesting vms or online pentesting challenges (pentesterlabs, pentester academy active defense labs, other materials I am sure are out there) for hands-on.
- Then I would get the 60 day lab minimum or 90 day if I could afford it.
It is an expert level course, walking into it without any web app experience would be a very rough challenge. Especially 30 days only. With minimum web app pentesting experience I would recommend you expect to spend 6 months minimum on this journey.In any case, do what you feel is right based on your experience.
2023 Cert Goals: SC-100, eCPTX