What ethical hacking is
Ethical hacking means exactly the skills an attacker has, but with the prior written permission of whoever owns the system and an obligation to report whatever is found. The difference between the two is neither in the tools nor in the knowledge; it is a document signed before the work starts, and the law stands on exactly that word.
- Lesson 2 of 12
- Beginner
- Free, no signup
Two pans with identical contents, and the thing on neither of them
What the penetration test team does
- Reconnaissance: seeing what is visible from outside
- Scanning and comparing against known weakness lists
- Trying to prove a weakness genuinely exists
- The same tools, the same knowledge, the same patience
What the attacker does
- Reconnaissance: seeing what is visible from outside
- Scanning and comparing against known weakness lists
- Trying to prove a weakness genuinely exists
- The same tools, the same knowledge, the same patience
The scale is deliberately level: the four rows on both sides are identical. The only thing separating them is a document written before the work starts, and that document sits on neither pan.
Last checked: Facts and tool names in this lesson are re-checked against their sources on this date.
Where exactly is the difference between an ethical hacker and an attacker?
In none of the places people usually guess. Not the tools, which are the same. Not the knowledge, which is the same. Not even in the work performed, because the steps of a penetration test deliberately resemble the steps of a real attack, and their value lies in exactly that resemblance.
Ethical hacking means the same work, with permission obtained before it starts and put in writing, and with an obligation to report whatever was found to the owner of the system. That is all. The technical guide of the American standards institute calls this document the rules of engagement, and its glossary gives a definition that settles the whole argument in one sentence: the rules of engagement are established before the start of a security test and give the test team "authority to conduct defined activities without the need for additional permissions". What the ethical hacker has and the attacker does not is an authority somebody granted.
That is what keeps the scale at the top of this page level. Whatever you put on one side is on the other too: the same scanning, the same analysis, the same effort to prove a weakness. The thing that separates the two is not on either pan at all.
An uncomfortable conclusion follows from this definition, and many people would rather not hear it. Skill does not make you ethical and neither does good intent. Somebody who visits a company site without permission in order to "help them" has, by the definition and in law, done what the attacker does, even if they email afterwards and ask for nothing. Permission is something only the owner of the system can give, and it only means anything before the work; afterwards it is an explanation, not a permission.

What does a penetration test actually look like?
The popular image is one person in front of a black screen. The real one is mostly paperwork. The SP 800-115 guide from the American standards institute defines penetration testing as "security testing in which assessors mimic real-world attacks to identify methods for circumventing the security features of an application, system, or network", and breaks it into four stages: planning, discovery, attack, reporting.
The first stage is the one everybody skips over. That same document says explicitly that in the planning phase "no actual testing occurs": rules are identified, management approval is finalised and documented, and testing goals are set. Which means that before a single command runs, it must be settled what is in scope, what is not, which hours are permitted, and who gets woken up if something breaks.
The last stage is equally invisible and is in fact the product. What the client buys is not an intrusion, it is a report: what was found, how serious it is, how it is reproduced and what has to change. A team that got in and produced no usable report has not done the job.
There is also a distinction that is often sold and should not be. That same document states it plainly: a vulnerability scanner checks only for the possible existence of a weakness, whereas the attack phase of a penetration test exploits that weakness to confirm it exists. So the output of an automated scanner, however colourful and long, is not a penetration test; it is a list of possibilities and a good part of it is a false alarm. Anybody selling you a tool output as a penetration test is removing the stage that is actually hard.
We carry both on this very site and deliberately keep them apart: a free scan that reads only the public page and the site headers, and a penetration test which our own services page describes with the words that it is not performed without the written permission of the owner.
The four stages of a penetration test, and which of them nobody sees
The division comes from the SP 800-115 guide of the American National Institute of Standards and Technology.
-
1
Planning
Rules, scope and documented management approval. The document says explicitly that no actual testing occurs in this phase.
-
2
Discovery
Gathering information, then comparing what was found against databases of known weaknesses.
-
3
Attack
The stage the popular imagination takes for the whole job and which is in fact only part of it. Its work is confirming a weakness exists.
-
4
Reporting
The product the client actually buys. Without it a successful entry is worth nothing to the owner of the system.
That same document notes this is one example of a division and other acceptable groupings exist. There is also a feedback loop between discovery and attack: anything learned during the attack reopens discovery.
White, black and grey hat, without the romance
Three terms everybody has heard and whose exact meaning is stated less often. A white hat works with permission and hands what they find to the owner of the system. A black hat gets in without permission and uses what they find for their own gain. A grey hat is the person who gets in without permission but does not intend to exploit it, and usually tells you afterwards.
And the third is where one has to be blunt. Grey hat is not a middle ethical position, it is a clear legal one: what they did was without permission and in most legal systems carries the same definition as what the black hat did. Emailing afterwards and asking for nothing may affect what is decided about you, but it does not change the definition. The people who believe good intent is a shield are usually the ones who never got that far.
The right way to do the very same thing exists and is not complicated: many companies run a bug bounty, meaning they have announced in advance and in public what is in scope, what is permitted, and where to send the report. That public announcement is the prior permission. Google reward programme is one example that publishes its rules on its own page.
And for anybody who owns a site this has another side. If you have not written down where a finder should report to, that person either goes to the general contact form which nobody may read, or does not report at all. RFC 9116 exists for exactly this: a plain text file on the site saying where to send a security report. We do not have such a file ourselves yet, and we say so plainly at the end of this lesson.
What does the law say, and why is good intent not a defence?
Access without permission to a system that is not yours is in practice a crime in every legal system, and Iran is no exception. The computer crimes law ratified in May 2009 says exactly this in its first article, which became article 729 after being merged into Book Five of the Islamic Penal Code: whoever gains unauthorised access to data or to computer or telecommunications systems that are protected by security measures is sentenced to imprisonment from ninety one days to one year, or a fine, or both.
Two phrases in that sentence do all the work and are worth reading slowly. One is "unauthorised", which is the very concept this whole lesson stands on. The other is "protected by security measures", meaning that the existence of a lock, however simple, is part of the definition of the offence. The fine amounts were adjusted once by a cabinet decision in March 2021, so any figure you read somewhere may no longer be current and has to be taken from the text in force.
Iran is not alone in this and seeing a second example helps. The United Kingdom Computer Misuse Act of 1990 also names its first offence "unauthorised access to computer material". The pattern is the same everywhere: the pivotal word is permission, not harm, not skill, and not what you did afterwards with what you found.
So real permission has three conditions and all three are needed. It comes before the work, not after. It is written down, because a spoken conversation is worth nothing on the day things go wrong. And it comes from somebody who genuinely has the authority to give it; a salesperson at a company cannot authorise you to test its servers, and a site owner cannot authorise you to test the infrastructure of their hosting company, because that infrastructure is not theirs.
And let us be plain about who we are: we are a web team, not lawyers. What is above describes the text of a law and is not legal advice. If your work comes near this line, talk to somebody whose profession is law before you act, not afterwards.
Where does the real way of learning start?
With systems somebody built on purpose for you to practise on. That sounds simple and is in fact the whole answer: in a practice lab the permission has been given in advance and written into the service itself, so the very thing that is a crime outside is an exercise here.
Three places carry the known names for this. OverTheWire is a set of games played by logging into their own servers remotely, and its first set is for somebody who has just started; there is no signup and no payment. TryHackMe and Hack The Box both offer learning paths and interactive labs, part of the content free and part on subscription. One honest note is needed here: we have not checked how signing up and paying for those two works from Iran, and we do not write what we have not checked; look at the terms of each on its own page.
Capture the flag competitions run on the same logic and are its competitive form: problems somebody built and published in order to be solved. For most people that is more enjoyable than reading and it also sticks better, because getting stuck and then understanding actually happens.
And the certificates. Three recur in job listings in this field: OSCP, taken through a practical exam lasting hours, CEH, which has a more theoretical exam, and PenTest+ from CompTIA. Our position on them is clear: a certificate is a hiring filter, not a proof of skill. Somebody who has worked in labs for months without a certificate is ahead in practice of somebody who only studied for the exam, but their CV may never be read. If your goal is employment you need both, and the order is this: skill first, paper second.
And the last thing we will say about it, because it is where this lesson began: nowhere along this whole route do you ever need to touch a system that is not yours. If somebody tells you that to learn you should "practise on a real target", the conversation ends right there.
The learning route, without touching anybody system once
Every station sits on a system whose owner built it for this and gave permission in advance.
-
1
The technical basics
Networking, the command line, and a little programming. Without them the rest is memorising commands rather than understanding.
-
2
Free teaching games
OverTheWire works by logging into its own servers remotely and its first set is built for beginners.
-
3
Interactive labs
TryHackMe and Hack The Box offer learning paths and practice machines, part free and part on subscription.
-
4
Competition, then the certificate
Capture the flag competitions build the skill and the certificate opens doors in hiring. That is the order, and the reverse does not work.
This order is a suggestion and not a standard; plenty of people start in the middle. We have not checked the signup and payment terms of these services from Iran and we make no claim about it.
The fast path, with AI
The usual way into this field is buying a long course and abandoning it in week three. The faster way is to pick your own target and then turn the published objectives of that target into a weekly plan where every objective is attached to an exercise in a legal lab. A language model is good at that conversion, because the work is sorting a published list, not knowing something unpublished.
- Pick one specific target: a certificate, or a job role whose advert you have seen. Without a target any plan is a wish list.
- Take the official objectives of that target from its own page and copy the text. That is the only real input here and it must not come from the model memory.
- Write down the hours you actually have in a week, not the hours you would like to have. A plan written around eight imaginary hours breaks in week two.
- Ask the model to split the objectives across weeks and note beside each week which lab or teaching game that objective can be practised on. A stronger model does better here, because mapping an objective to an exercise takes judgement.
- Before starting, check on the service itself that every exercise it named actually exists. That is the one step you must not skip.
Copy-ready recipe
Your role is to build a study plan. Work only from the objectives I paste below and add no objective from your own memory.
My target:
{certificate or job role}
The official published objectives, copied verbatim from their own page:
{objectives}
My real hours per week:
{number}
Output:
A week by week table with the columns: week, objective, suggested exercise, hours needed.
In the exercise column name only these three services: OverTheWire, TryHackMe, Hack The Box.
If you do not know a suitable exercise among those three for an objective, write "exercise unknown" and move on.
Hard rules:
- Name no real system, no real domain and no organisation as a practice target. Only the labs above.
- Write no command, tool or executable attack step. This plan is a list of topics, not a how to.
- Add no objective that is not in the text above, even if you are sure it is on the exam.
- Beside every exercise name, write that it must be confirmed on the service itself, because names change.
- If the weeks do not fit my hours, increase the number of weeks and leave the hours alone.
Before you trust the output: Two things you have to check yourself and the model cannot. First, the names of practice rooms and machines: models invent names that do not exist and you meet a dead link in week one; before starting, see every name on the service itself. Second and more important: this plan is a list of topics, not a permission. No objective, even one on an official exam, entitles you to practise it on a system that is not yours. If the conversation ever drifts toward a real target, close it there; the usage policies of the model vendors forbid exactly that, and more importantly so does the law.
AI in this kind of work
On this subject a language model is a good teacher and a bad colleague, and its boundary is exactly the boundary of the lesson itself. Good: explaining a concept, building a study plan from published objectives, translating an English report or document. Bad: anything that moves toward a real target. There it is not only the vendor usage policy that stops it, the request itself is meaningless: a model cannot grant you a permission it does not have.
Tools that actually help
- Claude For reading the long documents of this field, nearly all of them English and formal, such as the SP 800-115 guide or the rules text of a bug bounty. Anthropic usage policy forbids using the model for unauthorised access, and Iran is not on its supported countries list.
- Gemini For that conversion of objectives into a weekly plan and for a plain explanation of a concept. Google prohibited use policy for generative AI explicitly forbids assisting unauthorised access to systems, and Iran is not in the list of regions where Gemini is available.
- NotebookLM If you are working through a long document such as a standard technical guide or the full objectives of a certificate, uploading it and asking from inside that document beats reading a summary, because the answer cites its own paragraph. It runs on a Google account and Iran is not in the list of available regions.
Where it backfires
The big risk here is not the one you would guess. The problem is not that a model teaches somebody how to attack; it is that people generate fabricated, worthless security reports and burn the time of real teams. Daniel Stenberg, the maintainer of curl, wrote in July 2025 that about 20 percent of all that year submissions were AI generated slop, while only about 5 percent of submissions turned out to be genuine vulnerabilities; their bug bounty had found 81 real problems since 2019 and paid out over 90,000 dollars, and every report engages three or four people out of a seven person team. So the real effect of this on security is negative: volunteer run projects get exhausted and correct reports are read later. The second risk is simpler: the usage policy of all three vendors above forbids assisting unauthorised access, so steering the conversation that way wastes your time at best and closes your account at worst. What paying for these tools from Iran looks like is written in the buying guide.
Sources: Daniel Stenberg: death by a thousand slops Anthropic usage policy Google: generative AI prohibited use policy Anthropic: supported countries Google: where Gemini Apps are available
Where this advice stops
This lesson is a map, not a method: there is no technique in it, no tool walkthrough and no executable step, and that is a choice. Anybody who wants those should go to the labs named here, where the permission has been given in advance. The second limit is legal: what we wrote about the law describes a text and is not legal advice, we are not lawyers, the details differ from country to country, and the fine amounts have already been adjusted once. The third is about the services: we have not checked how signing up and paying for TryHackMe and Hack The Box works from Iran and we make no claim about it. And the last, which has nothing to do with teaching: this lesson is about a profession, not about how to make your own site safe; that work belongs to the other lessons in this path.
From our own work
The line this lesson is about is written and enforced on this very site. Our website security page sells two separate things, and printed under its free scan tool is the sentence that the scan is entirely non invasive, that only the public page and the site headers are examined, and that no penetration test is performed without the written permission of the owner; that tool really does exactly that, and beyond reading the page and its headers it sends nothing that tests the site on the other end. The other side of the same coin is in our own log: nothing there can separate that 57 address scan at 2:20 in the morning, the one counted in the previous lesson, from the scan of a researcher, because both have the same shape and that one described itself as Chrome on a Mac; the only thing that would have made them distinguishable is a document signed before the work started, and its absence is what constitutes the whole argument of this lesson. And a gap of our own, because saying it is more honest than not: we still have no security.txt file, so somebody who genuinely finds a flaw on our site has no announced route to reach us and has to use the general contact form. RFC 9116 exists for exactly that and we have not implemented it yet.
Real follow-up questions
If I find a flaw without permission and report it, am I in trouble?
You may be, and this is what people underestimate. The definition of the offence does not depend on your intent, it depends on having permission, and reporting afterwards does not change the position though it may affect what gets decided. The safe route is to check first whether the company runs a bug bounty or publishes a security.txt; if it does, the permission has been given in advance and its terms are written down.
Do I need a certificate first to start working in security?
To learn, no; to be seen, often yes. The skill is built in labs and competitions, and nobody there asks for a certificate. But in the job market a certificate is still an initial filter and a CV without one may never be read. The right order is to do the work first and then, if needed, take the certificate as a key to the front door.
As a site owner, how do I know the team I hire is the real thing?
From two things they give you before the work starts. First a scope and rules document saying what will be tested, what will not, in which hours, and who gets called if something stops working. Second a sample report, even anonymised, so you can see what the output looks like. A team that is ready with neither is probably only going to hand you the output of an automated scanner.