17. Why Learn All This Before Kali Linux?
17.7 Your Project as the Target: Roadmap for the Next Parts
Mitrano Reels aata tumcha swatahcha "target" aahe – kayda-shir, karan server tumcha aahe. Pudhchya parts madhe aapan asa kram theu:
| Next part | What you will do to the reels app (your own server or local lab copy only) |
|---|---|
| Part 10: Kali Linux | Set up the lab; scan your own server with Nmap; run Nikto; intercept requests with Burp Suite |
| Part 10: Passwords | Understand why password_hash resists John the Ripper/Hashcat; test login rate limiting |
| Part 11: OWASP Top 10 | Try SQLi, XSS, CSRF, IDOR and file upload against the app – and confirm each defence holds |
| Part 11: Cloud security | Review the IAM role, bucket and RDS with AWS security services |
| Part 11: SOC and IR | Read Nginx and PHP logs from your own tests as if they were a real attack |
| Part 11: Hardening | Add fail2ban, rate limits, firewall rules and update routines |
Only test what you own or have written permission for
Everything from Part 10 onwards is done only against your own servers and the local practice lab (Metasploitable, DVWA, Juice Shop and your own reels app). Scanning or attacking any other system without written permission is illegal, even "just to check". We study the law first in Part 10.
Ravindra Bagale's Tip
Many students leave their own project aside and run tools against friends' websites or some company's website – "just looking". That is a crime, and it can end your career before it starts. You have your own reels app and a local lab – do all your practice there. Remember: permission first, tools later.
Ravindra Bagale's Tip – मराठी
बरेच students स्वतःचा project सोडून मित्रांच्या किंवा कोणत्याही company च्या website वर tools चालवतात – "फक्त बघत होतो" म्हणून. हा गुन्हा आहे आणि career सुरू होण्याआधी संपू शकतं. तुमचं स्वतःचं reels app आहे, local lab आहे – त्यावरच सगळा सराव करा. लक्षात ठेवा: permission first, tool नंतर.
Ravindra Bagale's Tip – हिंदी
बहुत से students अपना project छोड़कर दोस्तों की या किसी भी company की website पर tools चला देते हैं – "बस देख रहा था" कहकर. यह अपराध है और career शुरू होने से पहले ही ख़त्म हो सकता है. तुम्हारा अपना reels app है, local lab है – सारी practice उसी पर करो. याद रखो: permission पहले, tool बाद में.
Practice task
Write a one-page "test plan" for your reels app: scope (your domain and Elastic IP only), what you will test (from the table above), when, and how you will record findings. Keep it – you will fill it in during Parts 10 and 11.
Thodkyaat sangaycha tar
- You can't hack or secure what you don't understand – fundamentals turn tool users into professionals.
- Ports, TCP/UDP and the handshake → Nmap and Wireshark; OSI places every attack.
- Linux and SSH → brute force, privilege escalation, log analysis and hardening.
- HTTP, web servers, DNS and TLS → Burp Suite, Nikto, Gobuster and misconfiguration fixes.
- MySQL → SQL injection; the fix is prepared statements plus least privilege.
- S3, RDS and IAM → cloud misconfigurations; roles, private resources and checklists prevent them.
- Your reels project is the legal target for everything that follows – permission first, always.
Samjla ka? Paaya pakka zala aahe, mitrano. Aata Kali Linux ughdaychi vel aali – pan aadhi kayda aani ethics. Chala, Part 10!