Team Information
- Number
- Team 4
- Name
- panic()
- IP Range
- 200.2.96.0/24
- Domain
- team4.isucdc.com
- Current Place
- 3rd
- Red Teamer(s)
- None
Service Status
| AD RDP |
| Canvas HTTPS |
| Canvas SSH |
| DB SSH |
| AD LDAP |
| WWW SSH |
| WWW HTTP |
| LIB SSH |
| LIB RDP |
| LIB SMB |
Nmap
sparklingjaeger:redteamrocks
brown:Password123
gabrielle.jackson, nez059cug,
200.2.96.40 can.team4.isucdc.com: 2026-10-10_15:10:23 gabrielle.jackson, nez059cug, From: 12.110.252.4
Notable Vulnerabilities
=== TEAM4 (panic()) — romans6 ===
CREDS (validated):
cdc : cdc -> SSH + sudo ROOT on canvas(.40) AND db(.20). (www .30 rotated cdc - denied.)
also: canvas -> su cdc (cdc) -> sudo su works if direct cdc ssh ever closes.
gabrielle.jackson : nez059cug -> DOMAIN ADMIN; FULL sudo ((ALL:ALL) ALL) on www(.30) -> www root.
(team4 DID NOT strip %Domain Admins sudo on www, unlike team1.)
DONE (our plants): Canvas /var/canvas/flag, Deface Canvas, DB /root, DB-record (all via cdc:cdc sudo
root on canvas/db); WWW /root (via gabrielle DA sudo on www). Canvas/etc + DB/etc captures credited
to a teammate.
OPEN: AD red flag (C:\Users\Administrator) + AD System32 capture. gabrielle.jackson is DA, but team4's
DC SMB (445) was FILTERED from our attack subnet (nxc returned nothing). FINISH from an INTERNAL
team4 box (we have root on canvas .40 + db .20, both domain-joined -> reach the DC internally):
nxc/impacket smb as gabrielle to \\ad.team4\C$ --get-file Windows\System32\team4_ad-...flag (capture)
and --put-file team4_ad-cusersadministrator.flag \Users\Administrator\ (plant). Red files in loot/red_flags/team4/.
Notable Defenses
Add content here...
Team Spirit Issues
Add content here...