Hmm sounds like fun.
Since they are creating their own server chances are you will be most benefited by exploiting the server rathar then the operating system or any of the web content.
I suggest start learning from the bottom up, learn about TCP/IP in a way which you are familiar with the process the packets will take. Once you are comfortable with that learn how the web service handles the data. How does it process POST/GET requests.
My general idea would be to use any type of input, whether it be packet injection or error handeling to your advantage.
A+, Network+, MCTS(70-620), Security+, CCNA