Ethical Hacking Basics · Lesson 1 of 5
Permission is the whole subject
Understand the line before you learn any technique.
Everything in this course is legal with authorisation and a crime without it. That is not a disclaimer at the top of the page; it is the first skill.
In Pakistan, the Prevention of Electronic Crimes Act covers unauthorised access to an information system, unauthorised copying of data, and interference with a system. The offences do not require that you caused damage or that you intended harm. Accessing a system you were not permitted to access is the offence, and "I was only testing" is not a defence.
What authorisation actually looks like. Written permission, from somebody with the authority to give it, naming the specific systems, the specific dates, and the specific techniques that are allowed and excluded. A verbal yes from a friend who works there is not authorisation. A bug bounty programme's published scope is authorisation, and only for exactly what that scope names.
Scope discipline. If the agreement names one domain, a related domain is out of scope even if it obviously belongs to the same company. Shared hosting means the machine may hold other people's sites, and touching those is unauthorised access to them regardless of your agreement with your client.
Where to practise legally. Deliberately vulnerable applications you install yourself, such as DVWA or Juice Shop. Platforms built for it, such as TryHackMe or HackTheBox. Your own systems.
Report responsibly. If you find something by accident, tell the owner privately, give them time, and do not publish or exploit it.
Write the authorisation checklist you would require before any test: who signed, what systems, which dates, what is excluded. Keep it as a template.
کوئی بھی ٹیسٹ شروع کرنے سے پہلے درکار اجازت کی فہرست لکھیں: کس نے دستخط کیے، کون سے نظام، کون سی تاریخیں، کیا خارج ہے۔ اسے سانچے کے طور پر رکھیں۔
Check what you learned
Create your free BvLogic ID to take the quiz and record your score.
Create your BvLogic ID