Project · boundaries
Legal & ethical use
This is a reference for people with permission to test. What that means in practice.
required readingThe rule
Testing a system you do not own, or do not have explicit written permission to test, is unlawful in most jurisdictions — including scans that “only” read a banner. Authorization is not a formality you clear before the interesting part starts; for network and wireless work it is the entire boundary.
Scope in concrete terms
- Written permission naming the assets, the window and the techniques allowed.
- A rate agreed with whoever operates the target; a default wordlist run can degrade a small service.
- Data minimisation: never collect or retain personal data you did not need to prove a point.
- A stop condition: anything touching real user data, availability or a third party halts and gets reported immediately.
Where to practise instead
Use deliberately vulnerable applications you host yourself, CTF ranges, or vendor-provided labs. The Learning Hub lists practice environments; none of them require inventing targets.
What this site will not do
- Execute commands for you, in a browser or on a server.
- Provide material aimed at access to systems without authorisation.
- Present disruption as entertainment, or frame tools as weapons.