Welcome to the first lesson of the course. Before you learn a single attack technique, you need the frame that makes those techniques lawful and professional rather than criminal: authorization and ethics.
The skills taught in this course are identical whether the person using them is a professional penetration tester or an attacker. The one thing that separates the two is permission. That is why this lesson comes first.
In this lesson you will:
- Understand the difference between authorized and unauthorized access, and why the difference is absolute.
- See what a written scope and rules of engagement define, and why testing anything outside them is unauthorized.
- Learn how legal frameworks such as the Computer Fraud and Abuse Act and the Computer Misuse Act treat unauthorized access.
- Learn how bug-bounty programs, safe harbor, and coordinated disclosure let researchers test and report safely.
- Treat the bundled NovaCart instance as your authorized lab boundary for the rest of the course.
This lesson is reflective rather than offensive — there is nothing to exploit here, only the discipline that governs everything you do next.
Estimated time: 10 minutes.
When you are ready, send the Continue signal.