Some help with starting out

Live life on the edge. Attack something real. Testing in a pen-testing enviornment will never give you experience. Most secrity experts were Blackhat.

Yes it's illegal, but it's thouroughly enjoyable and educationally rewarding. But, when you hack, only do it for the intention of learning. Do not steal anything. Do not do anything with the intent of causing damage. If you find a bug, FIX IT! If you can't fix it, it means you don't understand what it is you're doing. I always fix things like SQL Injection vulnrabilities for site owners, then send them an email explaining I hacked their site, and fixed it. Anonymously of course.

I'm not saying that's what you should do, but I'm saying it's an option.

Now, the staying safe part. You need to strap up. Go secure. For ultimate security you will need:

1) A Rasberry Pi 2) Mobile 3G/4G dongle. Prepaid 3) Wifi card for Pi 4) Long life rechargable power source

The idea is to drop the RPi in a location far from your home. I've put them in the toilets of McDonalds, into their ceiling. They sometimes have those ceiling panels you can lift up. You then connect to the McDonalds wifi. Connect the mobile dongle. You will use this to connect to your RPi via SSH. Now you can hack from the RasberryPi which is miles away from your home. It's more involved than this. I can write a tutorial to demonstrate how to set it all up.

Still not 100%, but good enough for most cases.

You can use an old desktop machine, install Whonix, and set up some proxy servers on servers in countries where the US has no juristiction. Countries that completely ignore the US. Chain 3 proxy servers, all on servers in seperate countries who ignore the US. Even better. Hack them, buy them, who cares.

Go eztra paranoid. Have a new persona for each project. Never use your real identity. Completely wipe your boxes after each project. DBAN style. Or, install OSes on cheap USB sticks. Remove internal HDD. Buy new USB's on a regular basis. Securely destroy them after use.

I could go on. But, it is possible to hack and not get caught. Just don't hit targets that would cause problems for Governments, finance, personal and sensitive data stores etc.

Just my 2 cents.

Ex Blackhat

/r/HowToHack Thread