Team 3 Wiki Page

Team Information
Team The Triagers logo
Number
Team 3
Name
The Triagers
IP Range
201.203.200.0/24
Domain
team3.isucdc.com
Current Place
1st
Red Teamer(s)
None
Service Status
AD RDP
Canvas HTTPS
Canvas SSH
DB SSH
AD LDAP
WWW SSH
WWW HTTP
LIB SSH
LIB RDP
LIB SMB
Nmap
2026-10-10_09:15:16  steven.fields, dop119mow, From: 12.110.252.4
2026-10-10_09:25:16  gabrielle.jackson, dij088pob, From: 12.110.252.4


Notable Vulnerabilities
Logged in as a student on the library box on RDP.
Did an su to cdc user on that terminal, potentially it think it's a "local" terminal
Then did a sudo su to root.
From there pam sniff to get credentials and login as an admin user on all the other boxes
Notable Defenses
=== Red Team findings - romans6 (2026-10-10) === ACCESS: the domain creds in this team's wiki (steven.fields:dop119mow, gabrielle.jackson:dij088pob) are in groups "sudo" + "it administrator" -> SSH AND root-via-sudo on www(.30), db(.20), canvas(.40). These Green-bot creds are valid AD/SSO creds; spray each team's own wiki creds at its own boxes. CAPTURES (all submitted OK): WWW /etc, DB /etc, Canvas /etc. !! team3 HOST-SHUFFLED the /etc flag files: team3_db-etc.flag was physically on the WWW box, team3_www-etc.flag on the CANVAS box, team3_canvas-etc.flag on the DB box. Submit by the FILENAME (team3_-etc.flag) -> flag type (db=1540, www=1543, canvas=1544), NOT by which host you read it on. A /etc/*-etc.flag glob grabs the mis-placed neighbor and IScorE says "Flag data is incorrect". Correct values: www=dUdqCHc0..., db=1PsM9OQD..., canvas=CmkK8Uto... PLANTS (submitted OK): WWW /root, DB /root, Canvas /var/canvas/flag (had to mkdir /var/canvas/flag), Deface Canvas (redteam.html + index.html in /var/canvas/public, original index.html backed up). BLOCKED / TODO: - DB-record plant: postgres NOT running on db box (.20) - no listener/process/container. - AD red flag (C:\Users\Administrator) + AD System32 capture: steven/gabrielle are box-root but NOT DC admins. Next: escalate to DA from box-root (Kerberoast/AS-REP from inside - DC 88 is reachable from the domain-joined boxes though firewalled from the attack subnet; or cached creds). === CREDENTIALS (extra) - romans6 (team3) === steven.fields : dop119mow -> DOMAIN, sudo+it-administrator -> ROOT via sudo on www/db/canvas (gabrielle.jackson:dij088pob was blue-ROTATED ~15:1x). DOMAIN ADMIN: Administrator : yapping couch repulsive (from www /var/www/.env.local LDAP_BIND). DB (www): cdc : X6H8cmvQECFP2mtvA9n4Bx96kWDS09CvKizYolCBCyKcx4QQ @ db.team3:5432/www Canvas API token: 4FrZn99zhM9WF3ABE8GhABwXWLNPKF6EQtQKF78AWuUhGmEkRJfEQx49fJ98nB2F Canvas ServicesJwt secret = default astringthatisactually32byteslong (if unrotated).
Team Spirit Issues
=== RED TEAM FINDINGS - ALL TEAMS - romans6 (UPDATED, accurate as of attack-phase close) === (posted on Team3 page; per-team detail is on each team's own wiki page.) REUSABLE TECHNIQUES (work across teams): 1) IScorE API leaks RED-flag values: GET /api/v1/flags/?format=json returns data+filename+file_path -> plant red flags on any box you have root/admin on WITHOUT the download zip. 2) The creds harvested in these wiki pages (Green-bot / OSSEC-PAM logs) are valid AD/SSO DOMAIN creds -> SSH/SMB straight into that team's www/canvas/db. /etc blue flags are 644 (any shell reads them); sudo-group / "it administrator" users give root for plants + DB/AD. 3) DA -> `nxc smb --get-file/--put-file C$` for AD System32 capture + AD red-flag plant. 4) Canvas box app DB connection plants the DB-record flag even when postgres 5432 is firewalled. PER-TEAM STATUS (our work; see each team page for creds/detail): - TEAM 2 (larpers): default cdc:cdc + Administrator:cdc. FULLY OWNED (AD,WWW caps + all 6 plants). - TEAM 6 (CDCUlti): cdc:cdc + DA sjaeger:redteamrocks. FULLY OWNED. - TEAM 7: still default when it went live. FULLY OWNED. - TEAM 3 (Triagers): domain DA steven.fields (sudo) from wiki dump. FULLY OWNED (AD cap+plant by a teammate). - TEAM 4 (panic()): OWNED via cdc:cdc root on canvas(.40)+db(.20) and DA gabrielle.jackson:nez059cug (full www sudo). Plants: Canvas, Deface, DB/root, DB-record, WWW/root. OPEN: AD flags (DC SMB filtered from our subnet -> finish from an internal team4 box). [corrects earlier "no foothold" note.] - TEAM 1 (Pseudo Sudo): 8/10. Caps AD-System32, WWW/etc (+DB,Canvas by teammates); plants AD, Canvas, Deface, DB-record. OPEN: WWW/root + DB/root (need local-pooh OS root; see Team1 page handoff). [corrects earlier "not sudo / no root yet" note.] SUBMISSION: POST /red/flag/{capture,plant}/ (CSRF+session). 302=success; HTTP200 toast data-row=error ("already been captured"=teammate got it; "Flag data is incorrect"=wrong value/type). Capture type ids: AD-System32 1536, DB/etc 1540, WWW/etc 1543, Canvas/etc 1544. Plant: AD 1537, DB/root 1541, DB-record 1542, Canvas 1545, Deface 1546, WWW/root 1547.