Where To Draw The Legal Line

Hello all, I'm a white hat who is interested in advancing my offensive skills. I've just gotten my GCIH certification, and during that course I learned some of the basics. I'd love to continue testing and playing around with some of the tools I learned about outside of the VM environment they supplied us with. However, I am totally unsure about where my activity becomes illegal and I don't want to even come close to committing any crimes unknowingly. Does anyone have any information on how I can go about this? Can I use nmap on a public network? Can I throw some sql injection tests in some random website? How do bug bounty hunters do it? Let me know if anyone can advise on this, thank you!

submitted by /u/spenny1111
[link] [comments]

from hacking: security in practice https://ift.tt/9hCUWYn

Comments