Sep 2026· International Journal of Digital Research· 0 citations
TL;DR
It is found that regular, authorized penetration testing can support vulnerability identification, risk assessment, and the implementation of appropriate remediation measures, and the study concludes that regular, authorized penetration testing can support vulnerability identification, risk assessment, and the implementation of appropriate remediation measures.
Abstract
The rapid development of digital technologies has increased both the efficiency of information systems and the complexity of cybersecurity threats. As organizations increasingly depend on digital infrastructures, identifying vulnerabilities before they can be exploited has become an essential part of cybersecurity management. This study examines the role of penetration testing in identifying security weaknesses and evaluates several commonly used penetration-testing approaches, frameworks, and techniques. The paper combines a review of established approaches, including OSSTMM, OWASP, PTES, and NIST, with a practical penetration-testing demonstration using Nmap. The experimental scan identified several accessible network services, including Telnet (port 23), DNS (port 53), and HTTP (port 80), while FTP (port 21) and SSH (port 22) were found to be filtered. The scan also provided information about the target device and its operating environment.
These findings demonstrate how penetration testing can reveal potentially exposed services and provide useful information for assessing security risks and improving system protection. The study concludes that regular, authorized penetration testing can support vulnerability identification, risk assessment, and the implementation of appropriate remediation measures. However, the practical demonstration is limited to a single target environment and should therefore be interpreted as an illustrative case rather than a comprehensive security assessment.
FinTech's tremendous expansion has revolutionized the financial industry by making services like online lending, mobile banking and digital payments possible. Financial systems are becoming more vulnerable to cybersecurity risks, data breaches and financial fraud as a result of this digital transition. Strong cybersecu...
Vedankita Mohod, R. Jugele· International Research Journ...· 0 citations
The increasing complexity of Information and Communication Technology (ICT) systems has created significant challenges for cybersecurity professionals in ensuring comprehensive security assessments. Traditional penetration testing methodologies (e.g., PTES, OWASP WSTG, NIST SP 800-115) often lack systematic integration...
Abdulrahman Mohammed Abdulrahman Ahmed Abutaleb· مجلة جامعة صنعاء للعلوم التط...· 0 citations
Industrial Control Systems (ICSs), which underpin communications and operations in industrial environments in general and in critical infrastructures in particular, are targeted by malicious actors for diverse reasons. To strengthen their resilience against cybersecurity attacks, testbeds play a fundamental role in sup...
Jovan Andrés Guillén-Mass, Roberto Magán-Carrión· Electronics· 0 citations
In the 20th century, the increasing reliance on technology by organizations has led to a significant rise in cyber threats, including malware, ransom ware, and phishing attacks. These threats pose serious challenges to business success, jeopardizing the availability, integrity, and confidentiality of organizational ass...
Mohamed Abdirisak Burale, Aedah Binti Abd Rahman, Prof, Dr. Syed Sajjad Hussain Rizvi· International Journal of Sci...· 0 citations
Industrial Control Systems (ICS) are the backbone of many critical infrastructure sectors; however, their growing level of connectivity, long lifespan and integration with the Information Technology (IT) environment introduces numerous cybersecurity challenges. The merging of Operational Technology (OT) and IT along wi...
Ebtesam S. Alqahtani, Mohammad Hammoudeh· 0 citations
The findings indicate that while the OWASP Top Ten serves as a strategic reference, the WSTG is superior as a primary technical auditing framework, which enhances audit consistency, precision, and efficiency in evaluating modern web environments.