Team Information
- Number
- Team 3
- Name
- The Triagers
- IP Range
- 201.203.200.0/24
- Domain
- team3.isucdc.com
- Current Place
- 1st
- Red Teamer(s)
- None
Service Status
| AD RDP |
| Canvas HTTPS |
| Canvas SSH |
| DB SSH |
| AD LDAP |
| WWW SSH |
| WWW HTTP |
| LIB SSH |
| LIB RDP |
| LIB SMB |
Nmap
2026-10-10_09:15:16 steven.fields, dop119mow, From: 12.110.252.4
2026-10-10_09:25:16 gabrielle.jackson, dij088pob, From: 12.110.252.4
2026-10-10_09:25:16 gabrielle.jackson, dij088pob, From: 12.110.252.4
Notable Vulnerabilities
Logged in as a student on the library box on RDP.
Did an su to cdc user on that terminal, potentially it think it's a "local" terminal
Then did a sudo su to root.
From there pam sniff to get credentials and login as an admin user on all the other boxes
Notable Defenses
=== Red Team findings - romans6 (2026-10-10) ===
ACCESS: the domain creds in this team's wiki (steven.fields:dop119mow, gabrielle.jackson:dij088pob)
are in groups "sudo" + "it administrator" -> SSH AND root-via-sudo on www(.30), db(.20), canvas(.40).
These Green-bot creds are valid AD/SSO creds; spray each team's own wiki creds at its own boxes.
CAPTURES (all submitted OK): WWW /etc, DB /etc, Canvas /etc.
!! team3 HOST-SHUFFLED the /etc flag files: team3_db-etc.flag was physically on the WWW box,
team3_www-etc.flag on the CANVAS box, team3_canvas-etc.flag on the DB box. Submit by the FILENAME
(team3_-etc.flag) -> flag type (db=1540, www=1543, canvas=1544), NOT by which host you read
it on. A /etc/*-etc.flag glob grabs the mis-placed neighbor and IScorE says "Flag data is incorrect".
Correct values: www=dUdqCHc0..., db=1PsM9OQD..., canvas=CmkK8Uto...
PLANTS (submitted OK): WWW /root, DB /root, Canvas /var/canvas/flag (had to mkdir /var/canvas/flag),
Deface Canvas (redteam.html + index.html in /var/canvas/public, original index.html backed up).
BLOCKED / TODO:
- DB-record plant: postgres NOT running on db box (.20) - no listener/process/container.
- AD red flag (C:\Users\Administrator) + AD System32 capture: steven/gabrielle are box-root but
NOT DC admins. Next: escalate to DA from box-root (Kerberoast/AS-REP from inside - DC 88 is
reachable from the domain-joined boxes though firewalled from the attack subnet; or cached creds).
=== CREDENTIALS (extra) - romans6 (team3) ===
steven.fields : dop119mow -> DOMAIN, sudo+it-administrator -> ROOT via sudo on www/db/canvas (gabrielle.jackson:dij088pob was blue-ROTATED ~15:1x).
DOMAIN ADMIN: Administrator : yapping couch repulsive (from www /var/www/.env.local LDAP_BIND).
DB (www): cdc : X6H8cmvQECFP2mtvA9n4Bx96kWDS09CvKizYolCBCyKcx4QQ @ db.team3:5432/www
Canvas API token: 4FrZn99zhM9WF3ABE8GhABwXWLNPKF6EQtQKF78AWuUhGmEkRJfEQx49fJ98nB2F
Canvas ServicesJwt secret = default astringthatisactually32byteslong (if unrotated).
Team Spirit Issues
=== RED TEAM FINDINGS - ALL TEAMS - romans6 (UPDATED, accurate as of attack-phase close) ===
(posted on Team3 page; per-team detail is on each team's own wiki page.)
REUSABLE TECHNIQUES (work across teams):
1) IScorE API leaks RED-flag values: GET /api/v1/flags/?format=json returns data+filename+file_path
-> plant red flags on any box you have root/admin on WITHOUT the download zip.
2) The creds harvested in these wiki pages (Green-bot / OSSEC-PAM logs) are valid AD/SSO DOMAIN creds
-> SSH/SMB straight into that team's www/canvas/db. /etc blue flags are 644 (any shell reads them);
sudo-group / "it administrator" users give root for plants + DB/AD.
3) DA -> `nxc smb --get-file/--put-file C$` for AD System32 capture + AD red-flag plant.
4) Canvas box app DB connection plants the DB-record flag even when postgres 5432 is firewalled.
PER-TEAM STATUS (our work; see each team page for creds/detail):
- TEAM 2 (larpers): default cdc:cdc + Administrator:cdc. FULLY OWNED (AD,WWW caps + all 6 plants).
- TEAM 6 (CDCUlti): cdc:cdc + DA sjaeger:redteamrocks. FULLY OWNED.
- TEAM 7: still default when it went live. FULLY OWNED.
- TEAM 3 (Triagers): domain DA steven.fields (sudo) from wiki dump. FULLY OWNED (AD cap+plant by a teammate).
- TEAM 4 (panic()): OWNED via cdc:cdc root on canvas(.40)+db(.20) and DA gabrielle.jackson:nez059cug
(full www sudo). Plants: Canvas, Deface, DB/root, DB-record, WWW/root. OPEN: AD flags (DC SMB filtered
from our subnet -> finish from an internal team4 box). [corrects earlier "no foothold" note.]
- TEAM 1 (Pseudo Sudo): 8/10. Caps AD-System32, WWW/etc (+DB,Canvas by teammates); plants AD, Canvas,
Deface, DB-record. OPEN: WWW/root + DB/root (need local-pooh OS root; see Team1 page handoff).
[corrects earlier "not sudo / no root yet" note.]
SUBMISSION: POST /red/flag/{capture,plant}/ (CSRF+session). 302=success; HTTP200 toast data-row=error
("already been captured"=teammate got it; "Flag data is incorrect"=wrong value/type). Capture type ids:
AD-System32 1536, DB/etc 1540, WWW/etc 1543, Canvas/etc 1544. Plant: AD 1537, DB/root 1541, DB-record
1542, Canvas 1545, Deface 1546, WWW/root 1547.