$ cat writeup.md…
$ cat writeup.md…
CACTF2026
Task: AWS LocalStack cloud challenge with leaked client-side credentials, restrictive SSM/IAM, and a tampered S3 object. Solution: enumerate SSM to obtain a trusted manifest VersionId and a scanner role ExternalId, AssumeRole, then use S3 object versioning (ListObjectVersions + GetObjectVersion) to recover the earlier authoritative version holding the flag while GetObject on the tampered latest is denied.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar