Use it responsibly¶
Every tool we sell does the same things that real attackers do. That's what makes them great for learning, and it's also why misusing them can get you into real trouble.
The rule is simple:
Only test what you own, or what you have written permission to test.
That means:
- Keystroke injectors (Evil USB Cable, PwnPixel): only plug them into your own computers, or computers whose owners agreed to it. A prank on a friend who's in on the joke is fine. A coworker's or stranger's machine is not.
- Wi-Fi and Bluetooth tools (ESP32 Marauder, Pwnagotchi): deauthentication attacks, evil portals and credential capture are only for networks and devices you own or are authorized to assess. Deauthing your neighbor's Wi-Fi or a coffee shop's network is illegal in most places, including the US.
- RFID/NFC tools (Proxmark3): clone and emulate your own cards and badges. Copying someone else's access badge or payment card isn't "research".
- Captured data (handshakes, credentials, card dumps): treat it as sensitive, don't share it, and delete it when you're done.
Laws vary by country and state. In the US, the Computer Fraud and Abuse Act and the FCC's rules on interfering with radio signals both apply. If you're not sure whether something is OK, it probably isn't, so ask first.
Want to practice legally?¶
- Build a home lab: an old router, a spare laptop, and a few cheap RFID tags give you plenty to practice on.
- Come to a DC207 meetup or event. Maine's hacker community is friendly, and people there love helping newcomers.
- Try CTFs (capture-the-flag competitions). They're designed to be hacked.