Leaking the secret with runtime instrumentation - Frida. Frida is a dynamic runtime instrumentation toolkit using which we can hook functions, spy on crypto APIs or trace private application code on...Take the OSCP course, it is relatively cheap for the value of the content and it is one of the few certs in security that is respected. From your profile it looks like you work for a big company. Ping some people in security and find out who runs your "Red Team" (if you have one). Make friends with them. Jan 27, 2020 · Here is another beginner writeup. Thanks for reading! Full Writeup TLDR: Connect to vpn, run nmap scan on IP. Ports 22 and 80 are open. Use gobuster to find directories. Find upload page. Upload reverse shell code. Listen with netcat on my machine. Work around php file upload limitation. Get the shell and search for first flag.