Skip to content

Project · boundaries

Legal & ethical use

This is a reference for people with permission to test. What that means in practice.

required reading

The rule

Testing a system you do not own, or do not have explicit written permission to test, is unlawful in most jurisdictions — including scans that “only” read a banner. Authorization is not a formality you clear before the interesting part starts; for network and wireless work it is the entire boundary.

Scope in concrete terms

  • Written permission naming the assets, the window and the techniques allowed.
  • A rate agreed with whoever operates the target; a default wordlist run can degrade a small service.
  • Data minimisation: never collect or retain personal data you did not need to prove a point.
  • A stop condition: anything touching real user data, availability or a third party halts and gets reported immediately.

Where to practise instead

Use deliberately vulnerable applications you host yourself, CTF ranges, or vendor-provided labs. The Learning Hub lists practice environments; none of them require inventing targets.

What this site will not do

  • Execute commands for you, in a browser or on a server.
  • Provide material aimed at access to systems without authorisation.
  • Present disruption as entertainment, or frame tools as weapons.