Training at Singapore Cybersecurity Camp (SCC)

On 9 September 2026, two of our Vantage Point Security consultants in Singapore had the opportunity to run a hands-on mobile penetration testing workshop and training at the Singapore Cybersecurity Camp (SCC), organised by Div0.
The session, “Beyond the App Store: PenTesting Mobile Apps & Their APIs,” was designed around one principle: less theory, more breaking things.
We ran it as a flipped-classroom workshop, with pre-reading provided beforehand and a Kahoot at the start to see who had actually done their homework before getting into the hands-on exercises.
The participants started with an unhardened mobile application and exploited an IDOR vulnerability in the Forgot Password workflow, taking it all the way to full account takeover.
Then we made things harder.
They were given a hardened version of the same application, this time protected with root detection and SSL pinning. To continue testing it, participants had to:
Set up and work with a rooted Android emulator • Perform static analysis using jadx • Understand how the application’s defensive controls worked • Write their own Frida scripts to bypass root detection and SSL pinning • Get the application’s traffic flowing through Burp Suite • Re-exploit the underlying API vulnerabilities despite the additional mobile controls
For many participants, it was their first time writing Frida scripts rather than simply running an existing bypass script or tool — exactly the kind of practical learning we wanted the workshop to deliver.
We finished with a capstone challenge, with an unexpected birthday twist.
It happened to be Ibrahim’s birthday, so the final scenario required participants to put everything they had learned together, exploit a series of vulnerabilities, uncover the details of his “secret” birthday party, and ultimately RSVP their way in.
A particularly satisfying moment came when two participants told us that, of the three workshops they had attended at the camp so far, ours had been their favourite — specifically because they spent their time actually doing the work rather than sitting through theory.
That made our trainers’ day.
A big thank you to Div0 and the Singapore Cybersecurity Camp team for having Vantage Point Security and for continuing to create opportunities for the next generation of cybersecurity practitioners to learn by doing.
And well done to everyone who survived the Frida scripting.
spreading the #hacktheplanet attitude
#CyberSecurity #MobileSecurity #MobilePentesting #PenetrationTesting #AppSec #Frida #BurpSuite #Singapore #Div0