Iqra Bibi
Centre of Excellence in Education, Innovation & Research, Pakistan
ORCID: 0009-0002-3865-8951
Email: iqrabibiiqrabibi75@gmail.com
https://doi.org/10.63711/ijdr.net20260305
ABSTRACT
The rapid development of digital technologies has increased both the efficiency of information systems and the complexity of cybersecurity threats. As organizations increasingly depend on digital infrastructures, identifying vulnerabilities before they can be exploited has become an essential part of cybersecurity management. This study examines the role of penetration testing in identifying security weaknesses and evaluates several commonly used penetration-testing approaches, frameworks, and techniques. The paper combines a review of established approaches, including OSSTMM, OWASP, PTES, and NIST, with a practical penetration-testing demonstration using Nmap. The experimental scan identified several accessible network services, including Telnet (port 23), DNS (port 53), and HTTP (port 80), while FTP (port 21) and SSH (port 22) were found to be filtered. The scan also provided information about the target device and its operating environment. These findings demonstrate how penetration testing can reveal potentially exposed services and provide useful information for assessing security risks and improving system protection. The study concludes that regular, authorized penetration testing can support vulnerability identification, risk assessment, and the implementation of appropriate remediation measures. However, the practical demonstration is limited to a single target environment and should therefore be interpreted as an illustrative case rather than a comprehensive security assessment.
Keywords: Cybersecurity, Penetration Testing, Vulnerability Assessment, Ethical Hacking, Nmap, Network Security, Reconnaissance.
Research Area: Cybersecurity, Penetration Testing and Vulnerability Assessment, Network Security
Copyright © 2026 The Author(s). This article is licensed under CC BY 4.0.
