This article documents in a practical and concise manner the process of basic penetration testing, port scans, and technical reasoning applied to Apache and CUPS services deployed on an Ubuntu virtual machine. Each test is approached as a production exercise and each interpretation as a step toward a more solid technical digital identity.
What we didApache 2.4.58 and CUPS 2.4.7 services were deployed and evaluated in an Ubuntu environment. Tools such as curl, nikto, and nmap were used to identify attack vectors, open ports, and potential vulnerabilities. Traversal paths, exposed HTTP methods, and server configurations were analyzed to detect misconfigurations, sensitive information, or privilege escalation points.
MethodologyThe methodology combined automated scans with nikto and nmap, manual queries with curl to validate HTTP responses, and configuration tests to evaluate headers, file permissions, and accessible directories. Technical reasoning was performed on potential impacts and mitigation recommendations oriented toward production environments.
Results and documentationThe main findings were recorded indicating the risk, evidence, and suggested steps for remediation. The documents referenced in the repository include test logs and an executive summary for non-technical teams. Key files: penetration-reflection.md and README. Public repository: https://github.com/ahmetsalih353-arch/siber-guvenlik-refleksi-secur-ty-lab-nots
August 2025 real-time tests on Ubuntu VM.
About Q2BSTUDIOQ2BSTUDIO is a company specialized in custom software and application development. We offer comprehensive solutions including custom software, applied artificial intelligence for businesses, custom AI agents, cybersecurity services, and AWS and Azure cloud services consulting. We also deliver business intelligence services and dashboards with Power BI to transform data into strategic decisions. Our approach combines development, security, and operations to ensure robust and scalable solutions.
How to collaborateWe invite the community to review the results, contribute additional tests, comments, and corrections to enrich the documentation. Collaborating strengthens collective knowledge and improves security practices in production.
Keywords for positioningcustom applications, custom software, artificial intelligence, AI for businesses, AI agents, cybersecurity, AWS and Azure cloud services, business intelligence services, Power BI, pentest, Apache server, CUPS, nmap, nikto, technical documentation, open source
Author's noteTechnical production is not just a set of commands; it is an exercise in reasoning, ethics, and character. Each documented test is a reflection of the commitment to operational security and continuous improvement.




