seth
Cloudy with a Chance of Breach

Cloudy with a Chance of Breach

July 31, 2026
0
2 min

← US Cyber Open Season VI Writeups

image.png

We are dropped into a linux shell. One of the first things I do is check the shell history of my user with history

image.png

Looks like the attacker stores some aws credentials in /tmp/creds_bkp_4e8f21.txt

yup:

image.png

Checking the crontab entry that was previously viewed shows us the aws region as well as s3 bucket name

image.png

Now we can just list what’s in this bucket by entering in the auth details in aws configure then reading what’s in the bucket with aws s3 ls s3://meridian-netmon-logs

image.png

image.png

Cool, there’s the flag. Let’s copy it out with aws s3 cp s3://meridian-netmon-logs/flag.txt /tmp/flag.txt. Now we can just read it from /tmp/flag.txt:

image.png

Flag: SVIUSCG{l00ks_4_l1ttl3_cl0udy}