Web SecurityWeb Security · Lesson 01

Ethical Hacking & The Law

Authorisation, scope, responsible disclosure and legal practice labs.

Video tutorialTrack course · freeCodeCamp
Speed
Next lesson
Watch 00:00 · 2 checkpoints Watch on YouTube More on this topic
Transcript & captions
8/8

Testing a system you do not own or have written permission to test is a crime in most countries. Everything in this track is for securing your own applications and for authorised, in-scope testing only.

  • Get written authorisation with a defined scope before any test.
  • Stay inside scope: named domains, IPs and accounts only.
  • Never exfiltrate real user data - prove impact with minimum evidence.
  • Disclose responsibly: report privately, give time to patch.
  • Practise on legal labs: OWASP Juice Shop, DVWA, PortSwigger Web Security Academy, TryHackMe, HackTheBox.
RoleFocus
Red teamSimulated attacker, finds ways in
Blue teamDefence, detection and response
Purple teamFeeds offensive findings into defence
Bug bounty hunterScoped public programs, paid per valid report

Knowledge check

0/2 answered

What must you have before testing a live site?

Which is a legal place to practise attacks?