Skip to content
Pentesting and ethical hacking

Ethical hacking for beginners: what to learn first, and what to skip

Ethical hacking for beginners: learn networking, Linux and the web first, then Nmap and Burp. What to skip, a 16-week roadmap and safe lab exercises.

LearnCyber editorial team, reviewed by Hackrowd Technology’s penetration testers · · 7 min read

Learn how computers talk to each other before you learn how to break them: networking, the Linux command line and how the web works come first, and tools come after. Most beginners stall because they do it the other way round, installing Kali, running tools they don’t understand, and getting results they can’t interpret.

This is an ordering guide. It tells you what to learn first, what to postpone, and what to skip entirely, with exercises you can run in a lab today.

Legal note: only test systems you own or have written permission to test. Everything below targets your own lab, or scanme.nmap.org, which the Nmap project allows for light test scans.

What is ethical hacking, in one paragraph?

Ethical hacking is using an attacker’s techniques, with permission and within an agreed scope, to find weaknesses before real attackers do. The permission is what makes it ethical and legal. In a professional setting it usually takes the form of a penetration test, which follows a methodology (planning, discovery, attack and reporting are the phases in NIST’s SP 800-115 technical testing guide) and ends with a report someone can act on. If that’s the career you’re after, our guide on how to become a penetration tester covers the job itself.

The learn-first, learn-later, skip list

Learn first Learn later Skip (for now or for good)
TCP/IP, ports, DNS, HTTP Active Directory attacks Memorising lists of 100 tools
Linux command line Exploit development and buffer overflows “Hacking” Wi-Fi you don’t own
How web apps work: requests, cookies, sessions Cloud and container attacks Anonymity rabbit holes (Tor chains, VPN stacking)
Nmap, properly Writing your own tools Courses that are only tool demos
Burp Suite or ZAP basics Mobile app testing “Hack any phone” videos
The OWASP Top 10 Evasion and red-team tradecraft Exam dumps
Writing clear notes and reports Advanced certifications Buying a “hacking laptop”

The “learn later” column isn’t unimportant. It’s simply much easier once the first column is solid. The “skip” column is either a distraction, illegal, or both.

Step 1: networking, because every attack crosses a network

You need to understand, without looking it up:

  • What an IP address and a subnet are, and why 192.168.1.0/24 contains 256 addresses.
  • What a port is, and the difference between TCP and UDP.
  • Common services and their default ports: SSH (22), HTTP (80), HTTPS (443), SMB (445), RDP (3389), DNS (53).
  • What DNS does and how a domain becomes an IP address.
  • What happens, step by step, when your browser loads a page.

A quick self-test once your lab from Step 3 is running (here the lab’s DNS server is 10.10.10.1 and the target web app is juice.lab.test): run these and explain every line of output.

$ dig +short juice.lab.test @10.10.10.1
10.10.10.5
$ curl -sI http://juice.lab.test:3000 | head -4
HTTP/1.1 200 OK
Access-Control-Allow-Origin: *
X-Content-Type-Options: nosniff
X-Frame-Options: SAMEORIGIN

If you can explain what dig asked for and who answered, what 200 OK means, and what each of those headers is for, you’re ready to move on.

Step 2: Linux, because your tools live there

You don’t need to be a Linux administrator. You need to move around, read files, find things and understand permissions. Practise until these feel natural:

$ pwd
/home/learner
$ ls -la ~/lab
total 16
drwxr-xr-x 2 learner learner 4096 Oct 10 10:02 .
drwxr-x--- 9 learner learner 4096 Oct 10 10:01 ..
-rw-r--r-- 1 learner learner  311 Oct 10 10:02 notes.md
-rwxr-xr-x 1 learner learner  198 Oct 10 10:02 sweep.sh
$ grep -i “password” ~/lab/notes.md
- check web app login for default password
$ ss -tlnp
State   Recv-Q  Send-Q  Local Address:Port  Peer Address:Port  Process
LISTEN  0       128           0.0.0.0:22         0.0.0.0:*
LISTEN  0       511         127.0.0.1:8080       0.0.0.0:*      users:((“python3”,pid=2142,fd=3))

Know what rwx means, what sudo does, how to use pipes (|), and how to read a short Bash script. That covers a surprising amount of day-to-day testing work.

Step 3: build a lab before you touch any tools

You need somewhere legal to practise. A laptop with 8 GB of RAM (16 GB is more comfortable) can run an attacker machine and one or two deliberately vulnerable targets in VirtualBox on a host-only network. Our guide to building a cybersecurity home lab walks through free and low-cost setups.

Good beginner targets:

  • OWASP Juice Shop, a deliberately insecure web shop maintained by OWASP.
  • PortSwigger’s Web Security Academy, free browser-based labs, with no local setup needed.
  • Deliberately vulnerable virtual machines from reputable sources, running only on an isolated network.

Step 4: Nmap, properly

Nmap is the first real tool to learn because it answers the first real question: what is running here? Learn it deeply rather than learning ten scanners shallowly. The Nmap reference guide is excellent, and the project explains the legal issues around scanning clearly.

A light, permitted scan against the Nmap project’s own test host:

$ nmap -sV -p 22,80 scanme.nmap.org
Starting Nmap 7.95 ( https://nmap.org ) at 2026-10-10 10:15 WAT
Nmap scan report for scanme.nmap.org (45.33.32.156)
Host is up (0.19s latency).

PORT   STATE SERVICE VERSION
22/tcp open  ssh     OpenSSH 6.6.1p1 Ubuntu 2ubuntu2.13 (Ubuntu Linux; protocol 2.0)
80/tcp open  http    Apache httpd 2.4.7 ((Ubuntu))
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel

Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 8.42 seconds

Versions can change over time, so your output may differ. Then do the same against your own lab:

$ sudo nmap -sS -sV -p- --min-rate 1000 10.10.10.5
Nmap scan report for 10.10.10.5
Host is up (0.00041s latency).
Not shown: 65532 closed tcp ports (reset)
PORT     STATE SERVICE VERSION
22/tcp   open  ssh     OpenSSH 8.9p1 Ubuntu 3ubuntu0.10 (Ubuntu Linux; protocol 2.0)
80/tcp   open  http    nginx 1.18.0 (Ubuntu)
3000/tcp open  ppp?

Now the important part, which tools can’t do for you: interpret it. Port 3000 shows ppp? because Nmap couldn’t match the service fingerprint confidently, so you check it by hand:

$ curl -s http://10.10.10.5:3000 | grep -o "<title>.*</title>"
<title>OWASP Juice Shop</title>

That’s the habit that separates ethical hackers from tool operators: don’t trust a label, verify it.

Step 5: web applications, the biggest attack surface you’ll meet

For many organisations, the most exposed systems are web applications and APIs. Learn:

  • How HTTP requests and responses work: methods, headers, cookies, status codes.
  • How sessions and authentication work, and how they fail.
  • The OWASP Top 10, as categories of risk rather than a checklist to memorise.
  • An intercepting proxy, Burp Suite Community Edition or OWASP ZAP, to see and modify traffic between your browser and the app.

A first proper exercise: set up Burp with Juice Shop, log in with a test account, and find where your session token lives. Then try to view another user’s basket by changing an ID in the request. If it works, you’ve found an insecure direct object reference, one of the most common real-world findings, and you understand why it worked.

What to skip, and why

Memorising tool lists. Distributions ship hundreds of tools; working testers use a small core set well. Learn the categories (scanning, proxying, password attacks, exploitation frameworks) and one solid tool in each.

Wi-Fi “hacking” first. It’s a niche skill, it requires specific hardware, and practising on networks you don’t own is illegal. Learn it later, on your own access point, if a role calls for it.

Anonymity obsession. Ethical hackers work with permission and usually from known IP addresses agreed with the client. Hiding is not part of the job.

Exploit development before fundamentals. Buffer overflows and assembly are fascinating and worth learning eventually. As a first topic, they’ll stall you for months.

Exam dumps. Apart from being against certifying bodies' policies, they produce people who can pass a test but can’t do the work, and interviews find that out quickly.

A 16-week roadmap at about eight hours a week

Weeks Focus You can do this by the end
1–3 Networking fundamentals Explain how a page loads; read dig, curl and ping output
4–5 Linux command line Navigate, search files, read permissions, write a 10-line Bash script
6 Lab build Attacker VM plus Juice Shop on an isolated network
7–8 Nmap Scan your lab, explain every open port, verify services by hand
9–12 Web testing Use Burp or ZAP; work through beginner Web Security Academy labs
13–14 Methodology Map what you’ve done to MITRE ATT&CK tactics; follow a testing process end to end
15–16 Reporting Write a professional report on one lab target: findings, evidence, risk, fix

The reporting weeks aren’t optional. A finding nobody understands doesn’t get fixed, and a clear report is what clients pay for.

How do I know I’m making progress?

You’re on track when you can:

  • Look at a scan result and say what you’d test next, and why.
  • Explain a vulnerability to a non-technical person in two sentences.
  • Reproduce a finding from your notes a week later.
  • Spend an hour stuck without giving up, then find the answer in documentation rather than a walkthrough.

If the volume of material feels overwhelming, read is cybersecurity hard to learn?. The short version: it’s broad rather than impossibly deep, and it gets easier once the foundations click.

Questions

Can I learn ethical hacking with no experience?

Yes. Start with networking and Linux rather than hacking tools, build a lab, and progress to web testing. People do move into testing from non-IT backgrounds; it takes patience with the fundamentals.

Do I need to know programming for ethical hacking?

Not at the start. You'll get a long way reading simple scripts. Learning some Python and Bash becomes useful within a few months, especially for automating repetitive tasks.

Is Kali Linux necessary?

No. It's convenient because tools come preinstalled, but any Linux distribution works. Understanding the tools matters far more than which distribution they're on.

Is ethical hacking legal?

It's legal when you have permission from the system owner and stay within the agreed scope. Without permission, the same actions can be criminal offences in most countries.

Should I start with a certification?

Build fundamentals first. Certifications make more sense once you know which direction you're heading, and some entry-level ones help structure your study.