The legal situation in Germany is similar to Austrian case law. A law was passed in May 2007 against “arranging to spy and intercept data“ for criminal prosecution against cybercrime. The so-called “hacker paragraph“ is governed by the German Criminal Code (StGB) §202c:

(1) A person planning a criminal offence according to § 202a or § 202b by

1. producing passwords or other security codes that allow access to data (§ 202a (2))

2. computer programs whose purpose is the commission of such an act, for themselves, a third party, for sale, distributes or otherwise makes available to others is punishable by imprisonment for up to two years or a fine. (2) §149 para. 2 and 3 apply accordingly.

- Criminal code (StGB), § 202c preparing to spy and intercept data

As in Austria, we are not allowed to give ourselves or a third party unauthorised access to an IT system. This also pertains to data of non-public data transmissions, such as encrypted communication or private Wi-Fis. Even if the protection against unauthorised access is trivial at best, we are not allowed to bypass it. From a legal standpoint, e.g. standard accounts are a legitimate safeguard. Furthermore, merely acquiring hacker tools is punishable by law if these are not used for benign purposes. This means that in Germany too, we may only attack an IT system if a statement of agreement has been given by the operator.

Last modified: Dec. 15, 2022

Penetation Testing Course

About Pentest Training

Discover the world of penetration testing. Learn how to infiltrate networks and successfully penetrate systems and applications. Acquire the necessary hacking skills and use them when conducting professional penetration tests. Become a real penetration tester. Here you will find the free documents for the Pentest Training of binsec academy GmbH. The binsec academy GmbH offers the corresponding security training lab environments and certifications. However, the knowledge and wiki articles on hacking and penetration testing is universal.

About binsec academy GmbH

binsec academy GmbH is the European provider of online security training with virtual laboratory environments. The core component of all security training is the focus on practice, practice and more practice. In the wiki here you will find the public and freely available course materials. You can put the theory into practice at binsec-academy.com.