Web SecurityWeb Security · Lesson 01
Ethical Hacking & The Law
Authorisation, scope, responsible disclosure and legal practice labs.
Video tutorialTrack course · freeCodeCamp
Speed
Transcript & captions
8/8
Testing a system you do not own or have written permission to test is a crime in most countries. Everything in this track is for securing your own applications and for authorised, in-scope testing only.
- Get written authorisation with a defined scope before any test.
- Stay inside scope: named domains, IPs and accounts only.
- Never exfiltrate real user data - prove impact with minimum evidence.
- Disclose responsibly: report privately, give time to patch.
- Practise on legal labs: OWASP Juice Shop, DVWA, PortSwigger Web Security Academy, TryHackMe, HackTheBox.
| Role | Focus |
|---|---|
| Red team | Simulated attacker, finds ways in |
| Blue team | Defence, detection and response |
| Purple team | Feeds offensive findings into defence |
| Bug bounty hunter | Scoped public programs, paid per valid report |
Knowledge check
0/2 answeredWhat must you have before testing a live site?
Which is a legal place to practise attacks?