$ cat writeup.md…
$ cat writeup.md…
CACTF2026
Task: Review a Go registry backend and its Android field client, where signed request data selects a privileged house. Solution: Recover the JNI HMAC key, identify broken object-level authorization, and derive operation scope from the verified session.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar