My Aquarium

by sealldev
๐Ÿšฉ CTFs DawgCTF 2025 web
My Aquarium / DawgCTF 2025
My Aquarium

Description

I have this website with some of my favorite sea animal images and facts. I have a secret document containing an my favorite animal, can you find it?

The website is running at http://connect.umbccd.net:20010

We are given a remote web application that has 3 simple buttons: home.png

Checking the source code, one of the buttons has an interesting URL: https://onlineaquarium.blob.core.windows.net/aquarium/resources/sea-animal-facts.txt

Visiting it, it contains a text file:

Sea Animal Facts:
...
- 
Credits to : noaa.gov

But this is likely what we need to look at, as the URL implies there are other resources available!

Looking at the Microsoft Documentation for listing blob storage resources, the user can query the resources with /<NAME>?comp=list&include=metadata.

Letโ€™s test that on the target: https://onlineaquarium.blob.core.windows.net/aquarium?comp=list&include=metadata xml.png

The highlighted entry in the screenshot has a โ€˜secretโ€™ file!

Visiting the file at https://onlineaquarium.blob.core.windows.net/aquarium/resources/SecretFavoriteSeaAnimal.txt contains the flag!

Flag: DawgCTF{Bl0b_F15h_4re_S1lly}

Share this writeup

Contribute

Found an issue or want to improve this writeup?

Edit on GitHub