Ethical Hacking Practice Guide
Safe Lab Setup with Kali Linux, DVWA & OWASP Juice Shop
Author: FIROS F
Table of Contents
• 1. Introduction to Ethical Hacking
• 2. Legal & Safety Guidelines
• 3. Setting Up VirtualBox
• 4. Installing Kali Linux
• 5. Creating a Safe Practice Network
• 6. Setting up DVWA
• 7. Setting up OWASP Juice Shop
• 8. SQL Injection Basics (Legal Lab Only)
• 9. Cross-Site Scripting (XSS) Basics
• 10. Network Monitoring & Packet Capture
• 11. Hardening & Defense Basics
• 12. Career Path & Next Steps
1. Introduction to Ethical Hacking
Ethical hacking involves testing systems legally to identify vulnerabilities before malicious attackers
exploit them. It includes penetration testing, vulnerability assessment, and security auditing. Ethical
hackers must always obtain permission before testing any system.
2. Legal & Safety Guidelines
Never attack live websites without written authorization. Practice only in controlled lab environments
such as DVWA and OWASP Juice Shop. Follow your country’s cyber laws strictly. Always
document your testing procedures responsibly.
3. Setting Up VirtualBox
Download and install VirtualBox. Create a new virtual machine with at least 4GB RAM and 2 CPU
cores. Use NAT or Host-Only Adapter for safe internal networking.
4. Installing Kali Linux
Download Kali Linux ISO from the official website. Mount it in VirtualBox and complete installation.
Update system using: sudo apt update && sudo apt upgrade
5. Creating a Safe Practice Network
Use Host-Only networking mode to isolate lab traffic. This ensures your testing does not impact
external networks. You may also create an internal network between vulnerable apps and Kali.
6. Setting up DVWA
Install XAMPP or LAMP server. Download DVWA and place it inside htdocs directory. Configure
[Link] and create database via phpMyAdmin.
7. Setting up OWASP Juice Shop
Install [Link]. Clone Juice Shop repository and run: npm install then npm start. Access via
[Link]
8. SQL Injection Basics (Legal Lab Only)
SQL Injection occurs when user input is improperly sanitized. Practice basic payloads inside DVWA
only. Understand how prepared statements prevent injection attacks.
9. Cross-Site Scripting (XSS) Basics
XSS allows injection of malicious scripts into web pages. Test reflected and stored XSS inside lab
apps only. Learn how input validation and output encoding prevent XSS.
10. Network Monitoring & Packet Capture
Use tools like Wireshark or tcpdump inside your lab environment. Analyze HTTP requests, DNS
queries, and TCP handshakes to understand traffic flow.
11. Hardening & Defense Basics
Apply patches regularly. Use firewalls and IDS systems. Understand how attackers think to build
stronger defense systems.
12. Career Path & Next Steps
Pursue certifications such as CEH, Security+, or OSCP. Build a home lab. Participate in CTF
challenges. Always continue learning responsibly.