How to Hack (Legally): Python Edition by Karen Miller

This video features Karen Miller at DjangoCon US 2019 in San Diego, California, USA.

How to Hack (Legally): Python Edition by Karen Miller
0:36:21
Published October 25, 2019
1,131 views

DjangoCon 2019 - How to Hack (Legally): Python Edition by Karen Miller

When it comes to hacking, trainees are at risk of legal implications and developing bad habits. In this talk, I aim to provide an overview of best practices and trusted resources available to attendees who wish to develop penetration testing skills safely, with an emphasis on Python.

This talk was presented at: https://2019.djangocon.us/talks/how-to-hack-legally-python-edition/

LINKS:
Follow Karen Miller 👇
On Twitter: https://twitter.com/kdangm
Official homepage: https://www.hack-hub.com/

Follow DjangCon US 👇
https://twitter.com/djangocon

Follow DEFNA 👇
https://twitter.com/defnado
https://www.defna.org/

Intro music: "This Is How We Quirk It" by Avocado Junkie.
Video production by Confreaks TV.
Captions by White Coat Captioning.

Summary

Karen Miller explains how to learn ethical hacking safely, with a focus on resources useful to Python and Django developers. She defines core security terms, introduces Hack Hub as a directory of training, certifications, competitions, tools, vulnerable virtual machines, and web applications, and highlights options such as Kali Linux, Exploit Database, VulnHub, Hack The Box, and OWASP. Her central argument is that aspiring hackers should practice only in controlled environments with explicit permission, understand tools and exploits before running them, isolate test systems, and avoid malicious activity or they risk damaging systems and facing serious legal consequences.

Key takeaways

  • A bug is a flaw, a vulnerability is an exploitable weakness, and an exploit is the code or action used to take advantage of it.
  • Hack Hub organizes training, certifications, CTFs, penetration-testing tools, vulnerable machines, and web applications for learners.
  • Python learners can start with security-focused courses covering scripting, networking, scanners, and web exploitation.
  • Kali Linux, Exploit Database, VulnHub, Hack The Box, and OWASP provide tools or controlled targets for practice.
  • Never test systems without ownership or explicit legal permission, and always understand an exploit before executing it.
  • Segregated test environments help prevent accidental damage and make it easier to identify artifacts left by testing.

Summarised automatically from the transcript.

Chapters

  1. 1:47 Cybersecurity Terminology The talk defines bugs, vulnerabilities, CVEs, exploits, proof-of-concept code, threats, risk, red teams, blue teams, and capture-the-flag competitions.
  2. 8:25 Penetration Testing Fundamentals The speaker explains what penetration testers do, the kinds of weaknesses they assess, and how findings are reported and mitigated.
  3. 9:59 Hack Hub Resource Guide Karen presents Hack Hub, a curated site for ethical hacking training, certifications, challenges, tools, vulnerable machines, and web applications.
  4. 12:26 Python Security Training The talk reviews free and paid Python courses for security scripting, networking, and penetration testing.
  5. 15:38 Security Certifications The speaker compares certification paths from EC-Council, GIAC, and Offensive Security and discusses choosing one based on personal and career goals.
  6. 19:38 Capture-the-Flag Competitions Karen describes the value of CTFs and highlights PicoCTF, RunCode, Hack This Site, and other ways to practice.
  7. 22:47 Penetration Testing Tools The talk introduces Kali Linux, Exploit Database, SearchSploit, and other tools used by penetration testers.
  8. 24:20 Vulnerable Practice Environments The speaker discusses VulnHub, Metasploitable, Hack The Box, and intentionally vulnerable systems for safe practice.
  9. 26:46 Vulnerable Web Applications Karen covers web application practice targets, common web exploits, OWASP resources, and building vulnerable Django applications in controlled environments.
  10. 27:41 Ethical Hacking Principles The talk introduces the “Be a Trusted Hacker” guidelines for learning patiently, avoiding damage, and staying within legal boundaries.
  11. 33:04 Responsible Use of Hacking Skills Karen warns against malicious use, encourages ethical motivations, and points to further guidance from the Software Engineering Institute.

Transcript

5,027 words · auto-generated Show

Automatically transcribed, so expect mistakes in names and technical terms.

0:15

Okay, so like you said, my name is Karen. I'm an associate cybersecurity engineer. I'm on the penetration testing team at the Software Engineering Institute at Carnegie Mellon University. Welcome to my presentation on how to hack legally with resources that are geared towards Python users and I'll also briefly talk about why these skills might be helpful for you as both Python and Django users. So, my main goal with this talk is to provide you with resources that will help you safely and ethically learn how to hack. Just So you don't end up in prison. So yeah, there is an emphasis on the legally

1:02

part. So first I'm going to go over some terms that you may or may not already be familiar with, just so that we're all on the same page. And then I'm going to dive into a website that I created and some of the ethical hacking resources that you'll find listed there. including training, certifications, challenges, competitions, tools, vulnerable virtual machines, and vulnerable web applications Then I'm going to cover some best practices for avoiding damage to systems and avoiding legal consequences throughout your learning and your hacking experience You might have read the title of this talk and thought that I would be teaching you how to hack in 45

1:47

minutes. And if you did, I'm really sorry. I don't think that's possible. But by the end of this talk, you should know where to start your ethical hacking journey and you should have plenty of resources um to use along the way. So, first let's go through some terms. A lot of the terms I'm going to go over can mean different things in different contexts, but I'm speaking specifically in the offensive security context So we'll start out with an easy one. You all know this one, right? Um let's not kid ourselves. A bug is a flaw in software or systems that causes unintended behavior. A vulnerability is a weakness which can be exploited, and a vulnerability can be the result of a bug.

2:38

Luckily, Django doesn't have any vulnerabilities, right? It's flawless. Um but really 70-ish CVEs since 2009 isn't super terrible. Obviously, it's not ideal. By the way, CVE stands for common vulnerabilities and exposures , which isn't something I'm going to really dive into today, but I do owe you a quick explanation since I just showed you 68 of them. So basically CVE codes like the ones that you see on the screen are part of a database that's maintained by MITRE, which tracks and describes publicly known cybersecurity vulnerabilities.

3:24

And if you want to see a real list, you should go and look up WordPress CVEs. I've used the word exploit already, but um an exploit is uh code or commands or actions that involve taking advantage of a vulnerability. For example, to harm or to access a system. A proof of concept is a demonstration of an exploit to prove its feasibility. The amount of completeness can vary, so it could just be pseudocode that says, theoretically, if you follow these steps. You should be able to exploit some vulnerability, or it might be actual working code, and maybe you have to adjust that code a little bit to make it work for you.

4:19

A pen test or penetration test is a simulated attack on systems for the purpose of discovering and exploiting vulnerabilities in order to Identify weaknesses and offer corresponding guidance on how to better protect those systems from real threats So if you're building a web application, what are some vulnerabilities or some security misconfigurations that someone might test for in order to make sure that your application is hopefully secure? And feel free to shout out any answers. None? All right. So here are some attacks that a pen tester might try in order to access sensitive information that's stored in a database, or

5:09

for example, upload a malicious file to a server. This could aid the pen tester in obtaining access to the server or potentially other resources. Then the pen tester can provide a detailed report outlining those findings and what can be done to mitigate those vulnerabilities in the web application. So it's important that the pen tester find these things and that the pen tester advise whoever asks them to test that application. on how to mitigate those vulnerabilities before a malicious hacker comes along and finds them first. So a great resource for learning about web application security. including some of these items up here, if you're not already familiar with them, is OWASP.

5:59

org and OWASP stands for Open Web Application Security Project. I'll talk a little bit more about that later. A threat is anything that could potentially cause harm to a system or to systems, whether intentional or not. An example of a threat is a hacker. And while we have this picture up, I just want to make you aware that when you're hacking, you have to wear a black hoodie. And you have to sit in a dark room and for some reason binary will be floating around you and it's really crazy. Um but yeah Risk is the amount of damage that could be done if a threat exploits a vulnerability.

6:47

So, for example, taking into consideration how much damage a hacker could do. If they discovered a buffer overflow in a program and they exploited that buffer overflow to gain access to a system. So You might think about what data is on that system, what would happen if that system was taken offline, and what other systems or resources could the hacker maybe access if they were able to get into that particular system. Red team, blue team refers to an exercise that involves one team, the blue team, trying to get into systems and Sorry, red team trying to get into systems, and another team, the blue team, trying to defend those systems.

7:32

Um the key difference here being that there's a training element So instead of focusing on getting into the systems to identify weaknesses in those systems, the red team is getting into the systems to identify uh weaknesses in the blue team's security operations. Um for example their ability to detect, prevent, mitigate, and Hopefully they are ultimately providing um valuable training and actionable data to the Blue Team. A capture the flag competition or a CTF involves security or forensics-related challenges. A lot of times you'll see that these are set up like a Jeopardy board, so the harder the challenge, the more points you'll get.

8:25

Now we're going to go through some resources that you can use to learn how to hack. So I created this website. It's called Hack Hub. And I made it to compile lists of trusted resources that you can use to learn how to hack. And I 'm not paid in any way for anything that's on this website, so there's no reason for me to um put anything sketchy on there. I just wanted to provide easy access to ethical hacking training tools, virtual machines, exploits, and other resources. Because I've found that throughout my own learning experience, sometimes it's difficult to hunt down and keep track of these things. uh especially as a beginner when you're not sure where to start um

9:13

and you're not sure what sources are trustworthy. I also want to emphasize that you absolutely shouldn't limit yourself to what's on this website because there are tons of resources out there that I haven't gotten around to adding or that I'm not even aware exist. So if you look over here There is a contact form. So that if you ever want to share some of your discoveries or if you have any comments, feedback, or questions, please feel free to submit a message here and it will come directly to me and I will respond. Um but this is Hack

9:59

Hub. Um the safety page is an acrostic that goes over some guidelines that I'm going to talk about later that you should keep in mind as you're learning how to hack and also as you are hacking. On each of these sections, there are blurbs about the categories. So I highly encourage you to read those before you dive into some of these resources because it has some helpful information. Um then you can go into the individual categories for actual links to the resources. So I have certification courses, courses that are associated with certifications, some training resources, a lot of these have helpful guides, walkthroughs, tutorials, or

10:50

training. There are challenges in war games if you want to practice your skills in a controlled environment and potentially be competing with other people, but it's not exactly a competition, it's more of like a ongoing scoreboard. If you want um to participate in an actual competition. There are plenty of those here. There's also a link, I believe, to a calendar somewhere. um that has a whole list of all the CTEs, CTFs and um cyber defense competitions that are coming up and since it's almost Cybersecurity Awareness Month, you might want to keep those on your radar

11:38

because that's when a lot of these competitions run. If you find that some of these links don't work, it might be seasonal. For example, Metasploit CTF I know is not going on right now, so the link is broken. And then we have pen testing tools. A lot of these are included in Kali Linux, which is a Linux distribution that I'll talk a little bit more about in a minute. Oops, vulnerable machines. These are virtual machines that you can set up locally to practice your hacking skills on. Vulnerable web applications, um, same deal, you can set them up locally and practice hacking them.

12:26

So that's Hack Hub. Um, all of the resources that I'm going to be talking about in a minute. can be found on Hack Hub. So before we go on, please feel free to take a picture or save this URL or just join me in a brief moment of awkward silence while I wait for people to do that. Alright, let's start with training. There are a lot of free training resources, so don't feel like you have to pay a lot of money to learn how to hack. But that's not to say that you won't find valuable paid training. It really just depends on what you want to learn and what your budget is.

13:11

But for this talk, I found three Python training courses that you might want to check out if you're interested in learning how to apply Python to security and networking. The Python for Security Professionals course on CyberBary is free. It's designed for people with little to no Python coding experience. So if you're new to coding, uh it 's a good course to check out to learn Python functions that are relevant to pen testing. And if you're a Python expert, I think it could still be worth your time. You might find yourself bypassing a lot of the material, but it could be a good exercise to Get into the security scripting mindset or to review concepts that maybe you don't use a lot now, but you might use more in a security context

14:04

Hackersploit has free training videos on Python for ethical hacking, which is also listed as Python for penetration testing on their website for some reason. A little bit confusing. Um but this is a more advanced um it's more advanced than Cybrary, um the Cyberry course that I just mentioned, and it will go over TCP functions and developing network scanners and developing port scanners. And then this This Pentester Academy course called Python for Pentesters requires you to either be subscribed, which I think costs $39 a month for Pen Tester Academy. But it also gets you access to other courses.

14:49

Or you could pay $150 just to have full access to that one course. This course covers a much broader range of topics from scripting and actual exploitation techniques, attacking web applications. So since we all have different levels of experience and goals, it can really be helpful to see what other people have said about these courses or other courses before you commit to it. Especially if it involves spending a lot of money. So I encourage you to do the research before you purchase a course or spend a lot of time on it. Now I'm going to talk a little bit about certifications.

15:38

I didn't list these certifications because I think that you must have them. I just selected some routes that are popular to demonstrate their flexibility, but of course you might decide, you know, pursuing certifications isn't for me. And that's Fine. It all depends on your personal goals. It depends on your employment goals. So that being said, you should consider what your employer values, what your prospective employer values and it varies by organization. So in some cases , maybe your employer will pay for these certifications, or maybe they'll only pay for specific ones. Which would be great considering the price of some of these.

16:26

So these are all things that you should consider. The first row is EC Council certifications, which lead up to the licensed penetration tester or LPT certification. That certification requires a lot more technical knowledge than the first in the series, which you may have heard of, the Certified Ethical Hacker Certification, or CEH. The CEH is considered entry-level friendly for people who want to become familiar with security concepts and ethical hacking. Global Information Assurance Certification, or GIAC, has various pen testing-related certifications that are associated with SANS

17:12

courses. The GIAC penetration tester or GPEN is considered more mid-level because it can be more challenging if you make use of the labs. But since they the labs are optional and since the exam is open book, it's really about what you're willing to put into it. And I hope if you're paying that much or someone is paying that much for you that you're willing to put a lot of time and effort into it. And if you're interested in exploits and research, you can eventually work your way up to the GIAC. Exploit researcher and advanced penetration tester certification, which thank goodness is shortened to GXPIN. The last row includes some offensive security certifications.

18:02

These are highly regarded because of how technical the labs and the exams are. The labs are really wonderful and frustrating and you'll learn a great deal and you'll hear the phrase try harder over and over again, which will probably annoy you to death. But eventually, when you overcome the trauma of the OSCP, you might decide to pursue the web expert certification, the OSWE. Or if you want to focus on exploit development instead of web attacks, then you might pursue the exploitation expert certification or the OSEE. But like I said, there's no right certification, there's no right series for everyone.

18:47

For example You might prefer to go certified ethical hacker. Remember that's the more entry-level friendly certification. And then the GIAC pen tester. Which is a good mid-level certification. And then the offensive security certified professional, which might make you want to throw your keyboard at a wall, but it will be worth it, I promise. Or maybe you want to focus on web application pen testing, in which case you might do the GIAC Web Application Penetration Tester, the GWAP. or the offensive security web expert, OSWE, and those are worth looking into if that's interesting to you. You should really take some time to evaluate which path is right for you if you're interested in pursuing certifications at all.

19:38

And sorry for throwing all of these annoying acronyms at you, but I mean that's why they're on Hack Hub so that you can look into them a little bit more um on your own time. So, like I said, next month is Cybersecurity Awareness Month, which means there will be a lot of competitions, a lot of capture the flags happening. And if you have time to participate in some of those, you should do some research on which of those you're qualified for because some of them target a specific audience. You should see if maybe there are some local competitions that you can participate in, but if there aren't, I know that there are a lot of remote competitions that you can participate in. participate in and oftentimes if you're at a security conference there will be a capture the flag that's ongoing

20:27

and people there who are probably very happy to help you if you ever get stuck. So competitions are very dear to me because they're what transitioned me from computer science into security. And they really challenge you to think outside the box and apply your skills to realistic scenarios. But not always realistic scenarios. Are there any Doctor Who fans out there? Yeah, all right. Um so at one time um I don't know anything about Doctor Who, but one time I ended up learning a Doctor Who language for a capture the flag. I think it's called Gallifrayan

21:14

But I might be pronouncing that wrong. Yeah. Um, but it was still a wonderful challenge um because even though I ended up staring at this thing, For a really long time and I was really frustrated and I didn't know what it was. Um it pushed me to do extensive research and learn something new and that's a really valuable skill to have as a hacker or penetration tester or for anyone to have really. So that's why you should try to participate in capture flags if you're interested. PICO CTF is a capture the flag competition that's run by Carnegie Mellon University, and it's aimed at middle

22:00

schoolers and high schoolers. But the challenges are open year-round. So if you're new to CTFs, this is a great way for you to get experience and get a feel for how the capture the flags are structured and Since you can do it on your own time without anyone around, you know, there's no pressure, and it's a great way to ease into capture flags. Run Code is an annual tournament, which I believe is open to everyone, regardless of whether you're in school or not, or what your age is. But similarly, they also have challenges open year-round, including operating system, network, security, and other coding challenges.

22:47

So I encourage you to look at that one too. And Hack This Site is a source of hacking challenges, and they're broken down in categories, so it's easy for you to figure out what you want to focus on. um like programming challenges for example and then you can easily um do those pen testing tools Kali Linux is a Linux distribution that's used by pen testers and it includes an extensive collection of security and forensics tools. So I um I would start your pen testing tool exploration there because there's tons of them and you might find that some of them you never need but it's still good

23:33

to know what's available to you. Exploit DB is a database of exploits, proofs of concept, and other security resources. And you can access the exploit database using a tool called SearchSploit, which comes with Kali Linux. Vulnerable machines in the form of virtual machines can be set up as targets for you to practice your tools and techniques on. And these can be set up on your own machine, of course, or you know, you obviously want to keep them on your own property since they are vulnerable and you don't want them to be be public facing because then you're just opening a door for hackers.

24:20

So VulnHub is a great source of vulnerable virtual machines and A lot of them have write-ups associated with them, so that if you ever get stuck, or if you just want to see how other people have exploited those machines, then you can reference those. And a lot of times there's a link in the description of the box when you go to download it. But if there isn't, then you can probably find it just with a quick Google search. There are also a few metasploitable boxes. These are Linux virtual machines that are, again, intentionally vulnerable for the purpose of practicing your tools and your exploits. And they're called Metasploitable machines because

25:06

of a tool called Metasploit in Kali Linux, which you will discover very quickly if you decide to explore Kali. But yeah, again, these can be hosted locally. Hack the box is a little bit different because it doesn't provide downloadable virtual machines. It's a lab environment that you VPN into with machines of various difficulty level for you to try to hack. And they only allow write-ups for the retired boxes. Um, and you have to have a subscription to access retired boxes. But since they rotate boxes fairly often, if you're ever wondering how you could have exploited a box, or if you're ever wondering how other people exploited a box.

25:54

You can just wait for that box to retire and then you can watch the write-ups start to pop up. As a side note, I would encourage you to check out Ipsec's YouTube channel for a lot of really good thorough walkthroughs of retired boxes Last, we have vulnerable web applications. There are tons of these, and they're built in various languages and platforms. And you can use them to practice things like cross-site scripting, SQL injection, command injection, a lot of those words that I showed you earlier. If you find a web application exploit on ExploitDB, a lot of times they will provide you with a download link to

26:46

the associated vulnerable version of that web application. If you want something more realistic that's not intentionally vulnerable. Or since we're at a Django conference, you could try building your own vulnerable web application to practice on or you could collaborate with your wonderful peers and when you feel comfortable you can apply the skills that you learn to your own web applications or the web applications that your peers develop. In a very controlled non-production environment with necessary permissions, of course And I mentioned OWASP earlier. It's a great source of all things web application security, and they have their own list of intentionally vulnerable web applications, including a lot that were built by people over at OWASP.

27:41

Okay, so you shouldn't just learn how to hack. You should learn how to hack ethically, and you should also learn how to ethically learn how to hack. So this is the part where I tell you how to hopefully avoid going to prison with this acrostic that I made. Be a trusted hacker. And being a trusted hacker means that you take your time when you're learning and when you're hacking. Because there are a lot of important concepts that you really need to understand, really need to Consider to avoid damaging a system or to avoid facing legal consequences. So be patient and be curious, but don't be impulsive. Here are a few reasons why.

28:28

These are three commands that you could accidentally execute. The first one moves your directory of important data or your customer's directory of important data. Into a sort of black hole, which isn't good. The second one forces the recursive removal of all files below the root directory. And the third command wipes a file that you maybe didn't mean to wipe. So I know it's easy to sit here and think. I would never be that dumb. But I actually know an intelligent person who accidentally executed that second command and it wasn't me, even though I know you're all thinking it's it was her.

29:13

But no, he was joking one day about accidentally deleting all his files. Can't remember the context, and then a couple days later he admitted that he did execute that command and deleted all of his files. Next, you want to refrain from touching systems that you don't own unless you have a legal agreement which permits you to. So set up your own environment or use one that's explicitly designed for you to practice your techniques like some of the resources that I just discussed. Every state and every country has its own laws regarding hacking, but I think that the general consensus is that hacking systems you don't own is

30:00

not a good idea. Some of you might be familiar with this story, but a 14-year-old played a prank on his teacher by logging into the teacher's account and changing their wallpaper At this school, teachers used really weak passwords. They would type their passwords in right in front of their students. They didn't really He didn't have to go to great lengths basically to get into this teacher's computer. Um But there were state exam answers. that he could have accessed when he logged in and potentially a significant amount of damage that he could have done, even if that wasn't in his intention, and even if that's not at all what he did. So at age 14

30:46

he committed a felony and at whatever age you all are um committing a felony is much more serious than what it was for him. So just keep that in mind. Use tools, exploits, and guides from trusted sources because there are malicious tools and exploits. That are designed to compromise your system or even publicly humiliate you. And they are falsely advertised to trick people. More on that in about three slides Segregate and segment appropriately to ensure important data and systems, and especially systems that you don't own, are separate and protected from your test environment.

31:32

And why do you have a test environment so that you can test exploits and tools in a safe space to make sure that they work as expected and make sure that you know how to use them? This can really help you gain a further understanding of what an exploit or a tool does and what artifacts it they might generate. Because You don't want to accidentally leave files on your customer systems so that weeks later they come to you asking, hey, was this left by you or was it left by an actual hacker who's after our data And if that does happen, you want to be able to say with total confidence, yes, that was me, or no, you should probably look into that.

32:18

Exploit smartly, not blindly. Understand how an exploit works, understand what it does before you even try it. Modify it as needed to suit your purposes because it's not a one-size-fits-all type of situation if you're targeting a different operating system or even launching it from a different operating system than it's meant to. Then there's gonna be some modification um needed. Otherwise if you don't um you know, look into what it actually does, you might run into an open SSH, open SSH exploit with this shellcode. And if you don't reverse engineer this shell code, um

33:04

You might not realize that it executes this command, which if you recall from earlier, does delete all of your files. Finally, um, this should go without saying, but I'm going to say it anyway. Don't use your skills maliciously However tempting it might be, just don't because it could cost you a lot of money and a lot of prison time. And I'm not trying to scare you out of security. I really am not. I just think it's good to develop good habits early on when you, if you're interested in pivoting into a security career or just learning more. Here's a quote from a man who did go to prison for hacking

33:49

and who has since used his skills for a more ethical line of work. He said, my motivation for hacking was all about the intellectual challenge, the seduction of adventure, and most importantly, the pursuit of knowledge. The hacker ethic is you never try to make money from it and you never try to harm or destroy. Unfortunately, as you all know, that's not the case for a lot of hackers. People quickly turned hacking into a means of money and destruction. And it's a huge issue that we hear about every day. So if you're going to learn how to hack, please learn for the right reasons because there are already so many people doing it for the wrong reasons.

34:37

If you're interested in reading more about these guidelines that I just went through in blog post form, As of last week, this post is published to the Software Engineering Institute's Insider Threat blog And it's super easy to find, just Google SEI blog or SEI Insights and look for the insider threat blog. My post is really easy to spot. Because for some reason everyone else's headshots are like these professional headshots on a you know subtle background and mine is like outside with a leafy background. So it really stands out. It's weird. I won't be taking questions now as my way of sort of making sure that you utilize the resources and contacts you discover at conferences

35:28

and Let's be real, I also probably won't be able to give you as good of an answer standing in front of a bunch of people in a camera as I would if it was just one-on-one. I could give you a more thoughtful response if you approach me in the hall or if you want, you can email me. You can contact me through Twitter. My Instagram handle is up there if you're interested in urban photography. But I guess you could ask questions on Instagram too, if that's what you want. Um, thank you for your time and stay out of prison.

Questions this talk answers

What is the difference between a bug, a vulnerability, an exploit, and a proof of concept?

A bug causes unintended behavior, while a vulnerability is an exploitable weakness. An exploit takes advantage of that weakness, and a proof of concept demonstrates that the exploit is feasible.

Discussed at 1:47

What is penetration testing and what does a pen tester do?

Penetration testing is a simulated attack used to discover and exploit weaknesses, then report the findings and recommend mitigations before malicious attackers find them.

Discussed at 4:19

Where can I find ethical hacking resources for learning Python security?

Karen’s Hack Hub collects trusted resources for training, certifications, challenges, competitions, tools, vulnerable virtual machines, and vulnerable web applications. She also points to Python-focused courses from Cybrary, Hackersploit, and Pentester Academy.

Discussed at 8:25

What are good Python courses for ethical hacking and penetration testing?

Cybrary’s Python for Security Professionals is free and beginner-friendly; Hackersploit covers more advanced networking and scanner development; and Pentester Academy’s Python for Pentesters covers scripting, exploitation, and web-application attacks but is paid.

Discussed at 13:11

What are good beginner-friendly capture-the-flag competitions?

picoCTF is aimed at middle- and high-school students but is open year-round and is a good low-pressure introduction. RunCode also has year-round operating-system, networking, security, and coding challenges, while Hack This Site organizes challenges by category.

Discussed at 22:00

What tools and environments can I use to practice penetration testing safely?

Kali Linux provides many security and forensics tools, including SearchSploit for accessing Exploit Database. VulnHub and Metasploitable provide intentionally vulnerable virtual machines, while Hack The Box offers VPN-accessible lab machines; vulnerable web applications can also be run locally for practicing attacks.

Discussed at 22:47

How can I practice hacking legally without damaging systems or getting in trouble?

Only test systems you own or have explicit legal permission to test, and use isolated environments or platforms designed for practice. Use trusted tools, separate test systems from important data, understand exploits before running them, and never use hacking skills maliciously.

Discussed at 29:13

Why should I understand an exploit before running it?

Exploits may need modification for a different operating system or environment, and blindly running them can execute destructive commands. Testing and reverse-engineering them first helps you understand their effects and avoid deleting data or leaving unexpected artifacts.

Discussed at 32:18

Presenters

Note: We understand that names change, people change, and bodies change. We respect each individual's journey and privacy. If you have any concerns about a video or need us to remove content, please don't hesitate to contact us. We will handle your request with care and promptly address any issues.

More videos from DjangoCon US