~/challenges $ cat weekly/09_skeleton_key_at_stadtwerke.md
Active Directory Security / Cryptography Hard
Live · Week 09
CHALLENGE #09 · Released 2 June 2026

Skeleton Key at Stadtwerke

REWARD +450 pts

Briefing

intel://sss/briefing_09.txt

INTELStadtwerke Oberzentrum, 03:14 local. A leak forum lights up. One line. The unmistakable signature of a Kerberos Ticket Granting Service reply, lifted from a domain that was supposed to be air-gapped.

The username says everything: svc-pumping-jh2. The service account that drives automated pressure overrides on every pump from the riverworks to the high tanks. Crack it and you own the physical grid.

A scraped wordlist surfaces alongside the leak — German industrial terms, facility codes, year stamps. The broker has done their homework, and they’re already running rules.

Operator, the adversary is mid-attack. Beat them to the password and pull the flag before the master payload compiles.

Objective

Crack the leaked TGS-REP hash and submit the flag hidden in the cracked password.

Evidence

.txt
leak_tgs_rep.txt
hash · Kerberos 5 TGS-REP, ETYPE 23 (RC4) · Hashcat mode 13100
↓ Download
.txt
sw_wordlist.txt
wordlist · tailored Stadtwerke dictionary
↓ Download

Capture the Flag

Submit your solution · +450 pts on success
Format: GRID-2026-XXXX
One submission per solve. Points post to the leaderboard on verify.