Hacker News new | ask | show | jobs
by freehunter 4845 days ago
It's dangerous if you start running against production sites, or sites that aren't fully owned by you. If you broke into Microsoft.com, for example, expect a lawsuit. However, if you pair two machines together and run Backtrack/Kali on one and something along the lines of Damn Vulnerable Linux on the other and just attacked your own local network, it's fun, safe, and informative.

I would actually encourage developers to learn about pen testing. If you know how people are going to misuse your application, you know what to watch out for when you're designing it. And trying to break your own app gives you some new insight into what you're doing right and what you're doing wrong. You can feel a sense of pride and accomplishment for every attack that fails to break something.