Ethical hacking for freshers: how to build your first lab and what to learn first
By VA2PT Team, . 9 min read

Most freshers who want to get into security start in the wrong place. They watch a video about "hacking Wi-Fi", install Kali on their only laptop, run a tool they do not understand against a website they do not own, and either break something or learn nothing. This guide is the opposite of that. It gives you a safe lab, a short list of fundamentals that actually matter, and a 12-week plan you can follow after college or alongside a job.
One rule before anything else: you only test systems you own or have written permission to test. In India, unauthorised access is an offence under Section 43 and Section 66 of the IT Act, 2000. "I was just learning" is not a defence. Everything in this article runs inside your own lab, on deliberately vulnerable software built for practice.
What a home lab is, and why you need one
A lab is a small, isolated network of virtual machines on your own computer. One machine is the attacker (Kali Linux). The others are targets that are intentionally broken so you can find and exploit real vulnerabilities without harming anyone. The isolation matters: your target machines should never be reachable from the internet, and your scans should never leave your laptop.
The lab lets you do three things safely:
- Run every tool at full aggression without worrying about consequences.
- Break things, restore a snapshot, and try again.
- Build the habit of writing down what you found and why it matters, which is the real job.
Hardware you actually need
You do not need a gaming machine. A laptop with 8 GB of RAM and 60 GB of free disk works for a two-machine lab. 16 GB is comfortable. If you have an Apple Silicon Mac, use UTM instead of VirtualBox and pick ARM builds of Kali.
Step 1: install the hypervisor
On Windows or Intel Mac, install VirtualBox. On Apple Silicon, install UTM. Both are free.
After installing, create a host-only or internal network. In VirtualBox: File, Tools, Network Manager, create a host-only adapter. This is the private network your attacker and targets will share. Machines on it can talk to each other and to your laptop, but not to the internet unless you add a second adapter.
Step 2: install Kali Linux as the attacker
Download the official Kali VirtualBox or UTM image from kali.org (verify the checksum; it is printed next to the download). Import it, give it 2 vCPUs and 4 GB RAM, and attach it to your host-only network.
Boot it, then update it:
sudo apt update && sudo apt full-upgrade -y
Check your lab IP address:
ip -4 addr show | grep inet
You will see something like 192.168.56.101. Write it down. Kali ships with the tools you will use for months: nmap, Burp Suite Community, sqlmap, gobuster, hydra, and hundreds more.
Step 3: install your first targets
Start with two web targets, because web application testing is where most Indian VAPT work is.
DVWA (Damn Vulnerable Web Application) is a PHP app with adjustable difficulty. The quickest way to run it is Docker inside a small Ubuntu VM, or directly on Kali for a first lab:
sudo apt install -y docker.io
sudo systemctl enable --now docker
sudo docker run -d --name dvwa -p 80:80 vulnerables/web-dvwa
Open http://<kali-ip>/ in a browser, log in with admin / password, click "Create / Reset Database", and set the security level to Low in the DVWA Security page.
OWASP Juice Shop is a modern JavaScript app with a scoreboard of challenges:
sudo docker run -d --name juice -p 3000:3000 bkimminich/juice-shop
Open http://<kali-ip>:3000/.
Running targets on the same VM as your attacker is fine for a first lab. As you progress, move them to a separate VM so you practise scanning across a network.
Step 4: take a snapshot
Before you break anything, snapshot the VM (VirtualBox: Machine, Take Snapshot). When an exploit leaves the target in a strange state, restore and continue. This one habit removes most of the frustration beginners feel.
The fundamentals to learn before tools
Tools are easy. What is hard, and what interviewers test, is understanding what the tool is doing. Spend your first weeks here.
Linux
You need to be comfortable in a shell: navigating, permissions, users and groups, processes, services, cron, logs in /var/log, and reading configuration files. Practise on your Kali box daily.
# Who am I, what can I run as root, what is listening?
id
sudo -l
ss -tulpn
Understand what each line of that output means before moving on.
Networking
Learn the TCP three-way handshake, what a port is, the difference between TCP and UDP, how DNS resolution works, what HTTP requests and responses look like, and how TLS sits on top. Wireshark on your lab network makes this concrete: capture a page load from Kali to DVWA and read the packets.
How web applications work
Requests, responses, headers, cookies, sessions, and how the server talks to a database. If you cannot explain what a session cookie does, SQL injection and XSS will stay magic tricks instead of understood bugs.
A little programming
Python and basic JavaScript. You do not need to be a developer, but you need to read code, modify a script, and write a small tool. Start with Python's requests library and write a script that logs in to DVWA.
A 12-week self-study plan
This assumes about ten hours a week. Adjust, but keep the order.
Weeks 1 to 2: foundations. Linux command line, networking basics, set up the lab. Complete the Linux Fundamentals and Network Fundamentals rooms on TryHackMe (free tier is enough).
Weeks 3 to 4: HTTP and the browser. Learn to read requests in the browser developer tools, then in Burp Suite Community. Start PortSwigger's Web Security Academy (free) and finish the "Information disclosure" and "Access control" labs.
Weeks 5 to 6: reconnaissance. nmap against your own lab, service enumeration, directory brute forcing with gobuster against DVWA. Write your first findings document.
Weeks 7 to 8: injection. SQL injection and XSS on DVWA at Low, then Medium. Read the vulnerable PHP source in DVWA (it has a "View Source" button) and explain to yourself why the bug exists.
Weeks 9 to 10: authentication and authorisation. Session handling, IDOR, broken access control on Juice Shop. Aim for ten Juice Shop challenges.
Weeks 11 to 12: a full mock engagement. Pick one target. Scope it, enumerate, test, and write a proper report with severity ratings and remediation. This report becomes the first item in your portfolio.
Certifications: an honest view for India
Certifications help HR filters more than they help skill. They are worth doing when you can afford them and after you have lab experience to back them up.
- eJPT (INE): affordable, fully practical, beginner-friendly. The best first certification for most freshers.
- CEH: widely recognised by Indian HR and government tenders, expensive, mostly multiple choice. Useful for the name on the CV, weak as proof of skill. Do not take it first.
- PNPT (TCM Security): practical, includes a real-style report and a debrief. Good value and closer to actual work.
- OSCP: the one hiring managers respect most. Hard, 24-hour practical exam, costly in rupees. Aim for it after a year of practice, not before.
Many good testers at Indian firms have no certification and a strong portfolio of write-ups. Skill first, certificate second.
Common beginner mistakes
- Installing Kali as your main operating system. Keep it in a VM; your daily laptop should not be a hacking distro.
- Running tools against real websites "just to see". Illegal, and you learn nothing because you cannot read the source afterwards.
- Collecting tools instead of understanding one. Learn nmap deeply before touching the next scanner.
- Skipping notes. If you cannot reproduce a finding from your own notes a week later, you did not really find it.
- Chasing exploits before fundamentals. Metasploit will wait; TCP will not.
Try it yourself
- Build the lab above and take a snapshot of both the attacker and target.
- From Kali, run
nmap -sV <kali-ip>and identify DVWA and Juice Shop by port and version. - Open DVWA's SQL Injection page at Low security, enter
1' OR '1'='1in the User ID field, and explain in one paragraph why it returned every user. - Restore the snapshot. Repeat step 3 at Medium security and note what changed.
How this maps to a real VAPT engagement
A professional penetration test at a firm like VA2PT follows the same shape as your lab exercise, with three additions: written authorisation and scope before a single packet is sent, a methodology (OWASP Testing Guide, PTES) so nothing is missed, and a report that a developer can act on and an auditor can accept. The lab teaches the technical middle. The next articles in this series cover reconnaissance, the OWASP Top 10 hands-on, Burp Suite, and how to turn practice into a first job.
Build the lab this week. Everything else in security starts from a place where you are allowed to break things.
- ethical-hacking
- freshers
- lab-setup
- kali-linux
- careers