Ravindra BagaleCourses & study guides

17. Why Learn All This Before Kali Linux?

17.7 Your Project as the Target: Roadmap for the Next Parts

Mitrano Reels aata tumcha swatahcha "target" aahe – kayda-shir, karan server tumcha aahe. Pudhchya parts madhe aapan asa kram theu:

Next part What you will do to the reels app (your own server or local lab copy only)
Part 10: Kali Linux Set up the lab; scan your own server with Nmap; run Nikto; intercept requests with Burp Suite
Part 10: Passwords Understand why password_hash resists John the Ripper/Hashcat; test login rate limiting
Part 11: OWASP Top 10 Try SQLi, XSS, CSRF, IDOR and file upload against the app – and confirm each defence holds
Part 11: Cloud security Review the IAM role, bucket and RDS with AWS security services
Part 11: SOC and IR Read Nginx and PHP logs from your own tests as if they were a real attack
Part 11: Hardening Add fail2ban, rate limits, firewall rules and update routines

Only test what you own or have written permission for

Everything from Part 10 onwards is done only against your own servers and the local practice lab (Metasploitable, DVWA, Juice Shop and your own reels app). Scanning or attacking any other system without written permission is illegal, even "just to check". We study the law first in Part 10.

Ravindra Bagale's Tip

Khup students swatahcha project sodun mitranchya kiwa kontyahi company chya website var tools chalavtat – "fakt baghat hoto" mhanun. He gunha aahe aani career suru honyaadhi sampu shakto. Tumcha swatahcha reels app aahe, local lab aahe – tyavarach sagla sarav kara. Lakshat theva: permission first, tool nantar.

Practice task

Write a one-page "test plan" for your reels app: scope (your domain and Elastic IP only), what you will test (from the table above), when, and how you will record findings. Keep it – you will fill it in during Parts 10 and 11.

Thodkyaat sangaycha tar

  • You can't hack or secure what you don't understand – fundamentals turn tool users into professionals.
  • Ports, TCP/UDP and the handshake → Nmap and Wireshark; OSI places every attack.
  • Linux and SSH → brute force, privilege escalation, log analysis and hardening.
  • HTTP, web servers, DNS and TLS → Burp Suite, Nikto, Gobuster and misconfiguration fixes.
  • MySQL → SQL injection; the fix is prepared statements plus least privilege.
  • S3, RDS and IAM → cloud misconfigurations; roles, private resources and checklists prevent them.
  • Your reels project is the legal target for everything that follows – permission first, always.

Samjla ka? Paaya pakka zala aahe, mitrano. Aata Kali Linux ughdaychi vel aali – pan aadhi kayda aani ethics. Chala, Part 10!