Skip to content

Read this one properly

Disclaimer

What this programme is, what it is not, and where you may and may not point the techniques it teaches.

Educational content only, for authorised security testing. Every technique in this programme is demonstrated against deliberately vulnerable practice targets — PortSwigger Labs, Hacker101, picoCTF and the instructor's own AWS account. Using any of it against a system you do not own or have written permission to test is a criminal offence under the Information Technology Act, 2000 and equivalent law elsewhere, and is entirely your own responsibility. Rootpath Academy is an independent training provider and is not affiliated with, endorsed by or sponsored by OWASP, PortSwigger, Amazon Web Services, Cisco, HackerOne or any other organisation named in these courses; all trademarks belong to their respective owners. Course outcomes depend on the effort you put in — we do not guarantee employment, placement, a certification pass or a salary increase.

Independent training, no affiliation

Rootpath Academy is an independent training provider. It is not affiliated with, endorsed by, sponsored by or certified by OWASP, PortSwigger, Amazon Web Services, Cisco, HackerOne, Google, the picoCTF project, Offensive Security, EC-Council, CompTIA, or any other company, project or tool referred to in the material. All product names, logos and trademarks are the property of their respective owners and are used only to describe what is taught.

Authorised testing only

Every technique in this programme is demonstrated against targets that exist to be attacked: the PortSwigger Web Security Academy, Hacker101, picoCTF, deliberately vulnerable applications and the instructor’s own cloud account. Practising on those is lawful.

Using any technique taught here against a computer system, network, application or account that you do not own, or for which you do not hold explicit written authorisation, is a criminal offence in India under the Information Technology Act, 2000 — in particular sections 43, 66 and 66C — and under comparable legislation elsewhere, including the Computer Misuse Act 1990 and the Computer Fraud and Abuse Act. Scanning, enumerating or probing a third party’s infrastructure without permission counts, even where nothing is damaged and nothing is taken.

Rootpath Academy teaches these techniques for defensive, educational and authorised-testing purposes only. It accepts no liability whatsoever for any use made of them, and misuse is the sole responsibility of the person who chose to misuse them.

Not a certification

Finishing this programme does not award a certificate recognised by any employer, university or standards body. It is not CEH, OSCP, Security+, or any other certification, and there is no accreditation behind it. What you take away is the material, the recordings and the practice.

No guarantee of employment

We do not promise a job, an interview, a placement, a referral or a salary increase, and we do not offer placement assistance. Hiring outcomes depend on your existing experience, your location, the market and the work you put in — none of which we control. Treat any training provider who guarantees a job with suspicion.

Software and lab changes

Tools such as Nmap, SQLMap, Burp Suite and the AWS console are released frequently, and the third-party lab platforms used in the recordings — PortSwigger, Hacker101, picoCTF — add, retire and renumber their challenges without notice. Sessions were recorded at a point in time, so a flag, an interface or a specific lab may have moved since. The concepts carry over; exact syntax should always be checked against current official documentation, and access to those third-party platforms is between you and them, not something this programme grants.

Running times are estimated

Session running times and the total-hours figure shown across this site are currently derived estimates rather than measured values, and every page quoting a total says so. They are proportionally accurate and will be replaced with measured figures. Do not treat the hours figure as a contractual quantity.

Your own code and accounts

Some sessions connect to third-party services — practice labs, public CTF platforms, GitHub, Shodan and Amazon Web Services. You are responsible for your own accounts, credentials, tokens and any charges those services incur, and for complying with their terms of service. AWS in particular bills real money: shut down every instance and bucket you create while following along. Never commit a real secret to a repository.

No warranty on the material

The code, scripts and configuration shared in this programme are teaching material, provided as-is. Review and test anything before using it in production, and never run a script from a training course against a system that matters without reading it first. Rootpath Academy accepts no liability for losses arising from its use.

Contact

Questions about this disclaimer: support@slips.co.in.