you're allowed to test. DEFINING A SCOPE Gathering information about all the subdomains, hidden directories, etc. RECONNAISSANCE Creating a report where you mention the summary, POC, impact & mitigations. REPORTING Testing manually for XSS, SQLi,& other bugs. MANUAL INSPECTION A Beginner's Guide to Ethical Hacking by Prerit Pathak