Rooted
Credencial verificada - AccesoVigente

BM::drnotsostrange

Md Noor Fairouz Bin Md Asman

@drnotsostrange · Operator · Singapore

Aspiring Penetration Tester

English
ACCESO2RANGO
RANGO
2 · Operator
Puntos verificados
320
TryHackMe
— · 22 rooms
Emitida
2026-08-26
Vence
2027-09-11
Posición
39 de 132
Conocimiento demostrado

Habilidades

Cada señal nace de respuestas únicas del Daily. La dificultad y la evidencia sostenida la hacen crecer; las repeticiones nunca.

35respuestas únicas
Señal más fuerte · Forense y DFIR · 52/100 · Operativo
WEB

Web y AppSec

50/100
Operativo100% de precisión3/3 correctasDifícil superadaestable

12 puntos de señal para Sólido · señal inicial

NETWORK

Redes y protocolos

45/100
Operativo57% de precisión4/7 correctasDifícil superadaestable

17 puntos de señal para Sólido · evidencia creciente

AD

Active Directory

47/100
Operativo80% de precisión4/5 correctasMedia superadaestable

15 puntos de señal para Sólido · evidencia creciente

CRYPTO

Criptografía

48/100
Operativo80% de precisión4/5 correctasDifícil superadaestable

14 puntos de señal para Sólido · evidencia creciente

FORENSICS

Forense y DFIR

52/100
Operativo80% de precisión4/5 correctasDifícil superadaestable

10 puntos de señal para Sólido · evidencia creciente

RECON

Recon y OSINT

47/100
Operativo80% de precisión4/5 correctasMedia superadaestable

15 puntos de señal para Sólido · evidencia creciente

CODE

Código y tooling

41/100
Operativo100% de precisión2/2 correctasDifícil superadaseñal nueva

21 puntos de señal para Sólido · señal inicial

CLOUD

Cloud y contenedores

47/100
Operativo100% de precisión3/3 correctasDifícil superadaestable

15 puntos de señal para Sólido · señal inicial

Annex — how this was earned

29 entries. Nothing scores without one.

320 total
Credentials94

1 entry

Quizzes and labs226

28 entries

Estos totales se apoyan en 29 entradas del registro. El detalle completo lo ven el titular y la revisión de Rooted.

Where your proof lands

Derived from what each verified ledger entry actually covers.

  • Web & AppSec78
    Evidence
    The search route parameterises q but concatenates sort directly into `ORDER BY ${sort}`. A
    A PDF preview endpoint accepts a URL. Supplying http://169.254.169.254/latest/meta-data/ c
    During an authorised pentest, GET /api/invoices/184 returns your invoice. Changing 184 to
    DrNotSoStrange
  • Networks & protocols78
    Evidence
    First night on a hospital SOC: a scan shows TCP 443 open on the patient portal. Which serv
    A compromised test host in the user VLAN can open outbound TCP connections to arbitrary in
    Two hosts suddenly report the gateway IP at a new MAC address; packet capture shows repeat
    A Windows file share is reachable on TCP 445. Which protocol are you looking at?
    DrNotSoStrange
  • Forensics & DFIR35
    Evidence
    The same cloud session token is used from Buenos Aires and Warsaw six minutes apart, with
    EDR records powershell.exe -NoP -W Hidden -EncodedCommand followed by a connection to a ne
    A suspicious email includes an attachment. What is a safe first step?
  • Cryptography31
    Evidence
    An encrypted image still reveals repeated visual blocks. Which AES mode is famous for this
    A startup pastes a Base64 customer token into a public support ticket because it 'looks en
    An API validates webhook HMACs with a loop that returns immediately at the first mismatchi
    Encrypted profile cookies contain repeated 16-byte ciphertext blocks whenever repeated rol
  • Cloud & containers27
    Evidence
    A CI role used to deploy one Lambda has `iam:PassRole` on `*` and permission to update arb
    A URL previewer inside a cloud VM is being abused to hunt for temporary credentials. Which
    A storage bucket denies listing but permits anonymous PutObject to the prefix used by the
  • Active Directory24
    Evidence
    A normal user can add themselves to Domain Admins. What kind of problem is this?
    A typo in a network path makes Windows ask the local network for the name and an attacker
    SMB signing is optional on several servers and LDAP signing/channel binding is not enforce
    A low-privilege domain account requests a service ticket for svc_sql; the SPN account uses
  • Recon & OSINT24
    Evidence
    A scoped staging host returns 200 for /.git/HEAD and exposes refs, while directory listing
    A mobile app references assets-prod-company.s3.amazonaws.com; anonymous listing is denied
    A web root exposes /.git/. What could an attacker recover?
    You discover a company subdomain during a bounty. Can you test it immediately?
  • Code & tooling23
    Evidence
    The build requests `company-auth` without a registry scope; the name is absent publicly an
    A Node route executes `exec('ping -c 1 ' + req.body.host)` after checking only that host i

The road to Hacker

580 pts short

Everything below is priced. Pick the cheapest one and the gap closes.

  1. Connect Hack The Box

    Rank, owns and global standing pulled from your profile.

    +300
    points
    52% of the gap
  2. Claim a CVE

    Any published advisory with your name on the credit line.

    +260
    points
    45% of the gap
  3. Connect GitHub

    Public tooling, exploits and the code you shipped.

    +160
    points
    28% of the gap
  4. Clear another lab

    28 lab entries scored. 1,774 points left before the lab ceiling.

    +60
    points
    10% of the gap
  5. Publish a write-up

    Explain the bug, impact and fix. Peer-reviewed write-ups score after approval.

    +180
    points
    31% of the gap
  6. Submit a vulnerability report

    A confirmed low, medium, high or critical report is the cleanest path up the ladder.

    +160
    points
    28% of the gap

Not one figure above was typed in by drnotsostrange.

Read how points are earned
Get your credential
Rank requirements beyond points
  • Rank 4+ - One verified credential or one confirmed report
  • Rank 7+ - One confirmed report or one credited CVE
  • Rank 9+ - A credited CVE at CVSS 9.0+, or three critical confirmed reports