beginner-first · no login

Learn ethical hacking,
from zero.

A structured, opinionated path into VAPT, taught in plain language, with a practice terminal in the browser. Nothing to install, nothing to sign up for.

open lessons in-browser terminal local progress
hackingpath ~ practice/home/learner
booting sandbox shell…
// how it works

Three steps. That's the whole loop.

01

Read the lesson

Short, plain-language chapters. We explain the why before the how, with everyday analogies.

02

Practice in the terminal

Each lesson opens with a sandbox shell. Try the commands as you read, no VM to install.

03

Mark it done, move on

Progress saves locally in your browser. Pick up exactly where you left off, no account required.

// the path

From mindset to first scan.

View full path
phase · 1

Foundations: The Web, Encryption & Traffic

The mental model and the moving parts: how to think about security, how a web request travels from browser to server, how HTTPS keeps it private, and how to read the raw packets on the wire.

Milestone 1
Security Fundamentals
  • Programming Languages for Ethical Hackers
  • CIA Triad & Threat Framing
  • Authentication, Identity & Non-repudiation
  • Anatomy of a Cyber Attack & Security Programs
Milestone 2
How a Website Works
  • How the Internet Works, TCP/IP & Ports
  • The Request Journey & Where Attacks Live
  • HTTP & HTTPS: How the Web Talks
Milestone 3
Protocols, Addressing & Human Attacks
  • Protocols, Ports & TCP vs UDP
  • IP Addresses, Subnetting & CIDR
  • DNS on Linux, localhost & URL Anatomy
  • Social Engineering & Phishing
Milestone 4
TLS, Certificates & Trust
  • TLS, SSL & the Handshake
  • Certificates & the Chain of Trust
Milestone 5
Reading Traffic with Wireshark
  • Meet Wireshark: Packets, Sniffers & Analyzers
  • Wireshark Display Filters
phase · 2

Linux, Networking & Offensive Recon

Get fluent at the Linux shell every tool runs on, understand how networks are built and defended, then enumerate a target end to end.

Milestone 6
Linux Essentials
  • The Terminal & Shell Basics
  • Linux: Files, Folders & Navigation
  • Linux: Searching, Permissions & Processes
  • File Permissions in Depth: Octal, SUID, SGID & the Sticky Bit
  • sudo & the sudoers File: Borrowing Root's Powers
  • Linux: Network Commands
  • Processes, Services & Packages
  • Scheduled Tasks: cron & systemd Timers
  • Reading Linux Logs: journalctl, auth.log & syslog
  • Linux Wargame: 20 Levels
Milestone 7
Networking & Defense
  • Proxies, Traffic & Routing
  • Network Segmentation & VLANs
  • Firewalls: Stateless, Stateful & WAF
Milestone 8
Enumeration & Scanning
  • The Big Picture: Recon, Scanning & Enumeration
  • Reconnaissance & The Enumeration Workflow
  • Search Engines, Crawlers & robots.txt
  • Search Engine Dorking: Google, GitHub & Beyond
  • OSINT: Open Source Intelligence, Finding the Puzzle Pieces
  • Subdomain Enumeration: Passive & Active Recon
  • Enumeration & Port Scanning with nmap
  • Service Enumeration: Fingerprinting the Ports
  • Wordlists: Fuzzing & Password Cracking
  • Directory & Content Discovery
  • Deeper Web Recon: Crawling, Params & Screenshots
Milestone 9
Remote Access & File Transfer
  • Configuring SSH & FTP: Login, Transfer, Tunnels
phase · 3

Exploitation & Post-Exploitation

The rest of the methodology: turn enumeration into an actual foothold, escalate all the way to full control, then clean up and report like a professional.

Milestone 10
The Hacker Methodology
  • The Hacker Methodology: From Recon to Reporting
Milestone 11
Gaining Access: Web Exploitation
  • How Web Apps Get Hacked: The OWASP Top 10
  • OWASP Top 10 2025: What Changed and Why It Matters
  • SQL Injection: Talking Straight to the Database
  • Cross-Site Scripting (XSS): Turning a Page Against Its Users
  • Broken Access Control & IDOR: Reading Other People's Data
  • Command Injection: Escaping to the Shell
  • CSRF: Tricking a User Into Doing Something
Milestone 12
Privilege Escalation
  • Privilege Escalation: Vertical & Horizontal
  • Post-Exploitation Enumeration: Know the Box
  • GTFOBins: SUID & sudo to Root
  • Cron Jobs for Privilege Escalation
  • Weak Permissions & Credential Hunting
  • Linux Capabilities for Privilege Escalation
  • Writable Files & PATH Hijacking
  • Kernel Exploits: When the OS Itself Is the Bug
  • LinPEAS: Automating Privilege-Escalation Enumeration
Milestone 13
Persistence: Keeping Your Foothold
  • Persistence: Keeping Your Foothold
  • SSH Keys & Account Backdoors
  • Cron, systemd & Startup Persistence
// the terminal

A safe shell, right beside the lesson.

Every lesson comes with a sandboxed terminal. Try the commands as you read - nothing to install, nothing to break. When you graduate to a real lab, the muscle memory comes with you.

  • Mocked nmap, ping, dig, cat, ls, instant feedback.
  • Real terminal feel: prompt, history, Ctrl-C.
  • Pluggable boundary, swap the mock for a real backend later, the UI doesn't change.
practice, sandbox shell/home/learner
booting sandbox shell…