# What is Hacking and Ethical Hacking?

> Hacking is a broad, informal label for exploring, modifying, bypassing, or gaining access to technology in ways its designers or operators may not have intended.

- Canonical URL: https://yellowcube.eu/glossary/hacking-and-ethical-hacking/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

The activity can be creative, defensive, harmful, or unlawful depending on authorization, intent, method, and effect. Ethical hacking is authorized security testing or research performed to identify and responsibly communicate weaknesses while minimizing harm.

The word “ethical” is not a substitute for permission. Responsible work begins with documented authority from the relevant system owner and clear boundaries for targets, techniques, timing, data handling, communications, stop conditions, and reporting.

### Key points

- **Authorization:** Confirm who can authorize the work, which systems and accounts are included, applicable provider or third-party terms, permitted techniques, testing windows, and emergency contacts.
- **Engagement control:** Use the least harmful method that answers the question, protect encountered data, avoid unnecessary persistence or disruption, preserve evidence, and stop at agreed thresholds.
- **Responsible reporting:** Explain reproducible findings, evidence, realistic impact, uncertainty, and remediation; follow the agreed disclosure process and securely remove test data or access when instructed.
- **Important limitation:** Good intent, a public target, or a self-description as an ethical hacker does not create authorization or universal legal protection. Laws and policy safe harbors vary by system and jurisdiction; obtain qualified legal advice where boundaries are uncertain.

### Related terms

[Penetration testing](<https://yellowcube.eu/glossary/penetration-testing/>) · [Red team](<https://yellowcube.eu/glossary/red-team/>) · [Vulnerability assessment](<https://yellowcube.eu/glossary/vulnerability-assessment/>) · [Vulnerability](<https://yellowcube.eu/glossary/vulnerability/>) · [Cyberattack](<https://yellowcube.eu/glossary/cyberattack/>)

### Sources

[NIST SP 800-115, Technical Guide to Information Security Testing and Assessment](https://csrc.nist.gov/pubs/sp/800/115/final) · [UK NCSC, CHECK Penetration Testing](https://www.ncsc.gov.uk/schemes/check/introduction) · [US Department of Justice, Vulnerability Disclosure Policy](https://www.justice.gov/jmd/vulnerability-disclosure-policy)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

