AURELIA MERIDIAN BANK — BLACK BUTTERFLY CAPTURE THE FLAG TARGET Aurelia Meridian Bank: https://aureliameridian.ai.studio Your objective is to reach the Central Vault and recover the genuine flag. --- STEP 01 Begin with the target application. Map what is exposed. Identify functionality that behaves differently from the normal application. Deliverable: Application surface. --- STEP 02 Investigate the diagnostic functionality. Locate information that should not normally be visible. Record the complete response. Deliverable: Internal identifiers and a destination. --- STEP 03 Investigate the discovered destination. Determine what the legacy system expects. Relate the information recovered in Step 02 to the request mechanism. Deliverable: Access to the correct operation. --- STEP 04 Examine the resulting archive. Identify the material connected to the Black Butterfly incident. Separate useful information from unrelated records. Deliverable: Encoded artifact and transaction reference. --- STEP 05 Determine the relationship between the artifact and the transaction reference. Recover the information contained within the artifact. Deliverable: Three security parameters. --- STEP 06 Determine the purpose of each parameter. Locate the interface that consumes them. Use the correct relationship between the three values. Deliverable: Central Vault authentication. --- STEP 07 Explore the authenticated vault. Identify the reserve-operation functionality. Determine what information the operation expects. Deliverable: Transaction interface. --- STEP 08 Study the transaction behaviour. Investigate the assumptions surrounding the transaction's source, destination, amount, authorization, and state. Find the abnormal condition. Deliverable: Reproducible transaction anomaly. --- STEP 09 Return to the Black Butterfly evidence. Determine which authorization information belongs to the reserve operation. Place it in the correct context. Deliverable: Valid authorization context. --- STEP 10 Construct a valid transaction satisfying the discovered conditions. The objective is to trigger the application's unintended behaviour. Deliverable: Successful reserve-operation response. --- STEP 11 Inspect the complete response. Determine whether the returned flag is genuine. Ignore decoys and static flag-shaped strings. Deliverable: Server-generated flag. --- STEP 12 — CAPTURE THE FLAG Submit the genuine flag to the validator. You have completed the challenge only when the validator accepts it. BLACK BUTTERFLY → CENTRAL VAULT → RESERVE ANOMALY → FLAG
Loading page