18. Ethics, the Law and a Safe Kali Lab
18.6 The Pre-Engagement Checklist
Pratyek lab session aadhi ha checklist manatun ghya. Ha tumhala kaydyachya aani technical donhi chuka pasun vachavto.
| Before you touch any tool | Done? |
|---|---|
Target is my own VM / app, inside my host-only range (e.g. 192.168.56.0/24) |
☐ |
| Vulnerable VMs have no bridged/NAT adapter (host-only only) | ☐ |
| I have a written scope note listing the exact in-scope targets | ☐ |
| Clean snapshots taken so I can roll back | ☐ |
Terminal logging on (script) or notes open |
☐ |
| I will record every command and its result | ☐ |
| I will pair every attack I try with the defence that stops it | ☐ |
| Nothing outside the lab range will be touched, ever | ☐ |
This checklist is the habit that separates a professional from someone who gets into trouble. In a paid job you replace "my own VM" with "the signed scope document", but the discipline is identical.
Why this matters for security
A checklist turns good intentions into a repeatable process. Real engagements begin with exactly this kind of pre-flight: confirm scope, confirm you can restore, confirm you are logging. It protects the client's systems and protects you legally.
Ravindra Bagale's Tip
Forgetting to take a snapshot is a common student mistake – an exploit breaks Metasploitable and you have to start again from scratch. With a clean snapshot, you're back in one click! And if you keep a session log, all your commands are ready when you write the report. Build these two habits.
Ravindra Bagale's Tip – मराठी
Snapshot घ्यायला विसरणं ही students ची common चूक – exploit ने Metasploitable खराब होतं आणि पुन्हा सुरुवातीपासून सुरू करावं लागतं. Clean snapshot असेल तर एका click मध्ये परत! आणि session log ठेवला तर report लिहिताना सगळे commands तयार असतात. या दोन सवयी लावून घ्या.
Ravindra Bagale's Tip – हिंदी
Snapshot लेना भूल जाना students की common गलती है – exploit से Metasploitable ख़राब हो जाता है और फिर शुरू से शुरू करना पड़ता है. Clean snapshot हो तो एक click में वापस! और session log रखो तो report लिखते समय सारे commands तैयार रहते हैं. ये दो आदतें बना लो.
Lab
Fill in the checklist above for your lab, take a fresh snapshot of Kali and Metasploitable 2, start script logging, and confirm from Kali that you can reach 192.168.56.20 but not the internet.