Rooted
Verified credential - AccessCurrent

BM::midnight-baker

A. Castillo

@midnight-baker · Junior Hacker · Panama

Hands-On Threat Detection, Network Support & Endpoint Troubleshooting

SpanishEnglish
ACCESS1RANK
RANK
1 · Junior Hacker
Verified points
268
Issued
2026-08-15
Valid until
2027-08-21
Standing
29 of 109
Demonstrated knowledge

Skills

Every channel comes from unique Daily answers. Difficulty and sustained evidence move the signal; repeats never do.

14unique answers
Strongest signal · Web & AppSec · 48/100 · Operational
WEB

Web & AppSec

48/100
Operational80% accuracy4/5 correctHard clearedsteady

14 signal points to Strong · growing evidence

NETWORK

Networks & protocols

29/100
Developing67% accuracy2/3 correctEasy clearedsteady

11 signal points to Operational · early signal

FORENSICS

Forensics & DFIR

33/100
Developing100% accuracy2/2 correctMedium clearednew signal

7 signal points to Operational · early signal

RECON

Recon & OSINT

43/100
Operational100% accuracy3/3 correctMedium clearedsteady

19 signal points to Strong · early signal

CODE

Code & tooling

24/100
Developing100% accuracy1/1 correctMedium clearednew signal

16 signal points to Operational · early signal

Annex — how this was earned

12 entries. Nothing scores without one.

268 total
Quizzes and labs268

12 entries

12 ledger entries back these totals. The full derivation is visible to the holder and to Rooted review.

Where your proof lands

Derived from what each verified ledger entry actually covers. You have nothing in active directory, cryptography.

  • Web & AppSec140
    Evidence
    path.join(UPLOADS, req.query.name.replace('../', '')) — why does this still traverse?
    On a cloud host, why is 169.254.169.254 the classic SSRF target?
  • Networks & protocols58
    Evidence
    A host can ping a server but cannot connect to its TCP 8080 service. What should you check
    ¿Qué protocolo suele responder consultas de nombres en el puerto 53?
    Least privilege means an account should have…
    Which service listens on TCP 443 by default?
  • Cloud & containers30
    Evidence
    On a cloud host, why is 169.254.169.254 the classic SSRF target?
  • Recon & OSINT20
    Evidence
    robots.txt lists /admin-old. Does that make the path private?
    Certificate history and passive DNS reveal origin-old.example.com on an address in the com
    Una app móvil referencia assets-prod-company.s3.amazonaws.com; el listado anónimo está neg
  • Forensics & DFIR12
    Evidence
    Proxy logs are quiet, but DNS logs show one endpoint sending sequential 50-character subdo
    Un host puede tener malware sólo en memoria. ¿Qué debería hacerse antes de reiniciarlo?
  • Code & tooling8
    Evidence
    Una ruta Node ejecuta `exec('ping -c 1 ' + req.body.host)` después de validar sólo que hos
  • Active Directoryno proof yet
  • Cryptographyno proof yet

The road to Operator

32 pts short

Everything below is priced. Pick the cheapest one and the gap closes.

  1. Connect Hack The Box

    Rank, owns and global standing pulled from your profile.

    +300
    points
    closes the gap
  2. Claim a CVE

    Any published advisory with your name on the credit line.

    +260
    points
    closes the gap
  3. Connect TryHackMe

    Points and completed rooms.

    +180
    points
    closes the gap
  4. Connect GitHub

    Public tooling, exploits and the code you shipped.

    +160
    points
    closes the gap
  5. Clear another lab

    12 lab entries scored. 1,732 points left before the lab ceiling.

    +60
    points
    closes the gap
  6. Publish a write-up

    Explain the bug, impact and fix. Peer-reviewed write-ups score after approval.

    +180
    points
    closes the gap

Not one figure above was typed in by midnight-baker.

Read how points are earned
Get your credential
Rank requirements beyond points
  • Rank 4+ - One verified credential or one confirmed report
  • Rank 7+ - One confirmed report or one credited CVE
  • Rank 9+ - A credited CVE at CVSS 9.0+, or three critical confirmed reports