Rooted
Verified credential - ControlCurrent

BM::n4h

Yuval Miller

@n4h · Pro Hacker · Israel

Penetration Tester & Security Researcher

EnglishHebrew
CONTROL4RANK
RANK
4 · Pro Hacker
Verified points
3,055
Hack The Box
Pro Hacker · 2 owns
Credited CVEs
6 · CVSS 9.8
Public tooling
162 ★
Issued
2026-08-25
Valid until
2027-08-29
Standing
13 of 132
Certifications held
OSCPOSCP+OSWP
Demonstrated knowledge

Skills

Every channel comes from unique Daily answers. Difficulty and sustained evidence move the signal; repeats never do.

10unique answers
Strongest signal · Web & AppSec · 59/100 · Operational
WEB

Web & AppSec

59/100
Operational86% accuracy6/7 correctHard clearedsteady

3 signal points to Strong · growing evidence

NETWORK

Networks & protocols

24/100
Developing100% accuracy1/1 correctMedium clearednew signal

16 signal points to Operational · early signal

AD

Active Directory

22/100
Developing50% accuracy1/2 correctEasy clearednew signal

18 signal points to Operational · early signal

Annex — how this was earned

19 entries. Nothing scores without one.

3,055 total
Credentials3,000

11 entriescapped at 3,000

Quizzes and labs55

8 entries

19 ledger entries back these totals. The full derivation is visible to the holder and to Rooted review.

Where your proof lands

Derived from what each verified ledger entry actually covers. You have nothing in cryptography, forensics & dfir, recon & osint, cloud & containers.

  • Web & AppSec1,773
    Evidence
    CVE-2026-64628
    CVE-2026-64954
    OSCP+
    CVE-2026-19200
    CVE-2026-18972
    CVE-2026-65008
    CVE-2026-65007
    OSCP
    The search route parameterises q but concatenates sort directly into `ORDER BY ${sort}`. A
    An API accepts a JWT whose header was changed from RS256 to HS256 and signed with the publ
    A PDF preview endpoint accepts a URL. Supplying http://169.254.169.254/latest/meta-data/ c
    A comment containing `<script>alert(1)</script>` runs for every visitor. What is the bug?
    A page on another site can submit a form that changes your email while you are logged in.
    An image-from-URL feature can fetch http://127.0.0.1/admin from the server. What is this?
  • Code & tooling1,538
    Evidence
    CVE-2026-64628
    CVE-2026-64954
    CVE-2026-19200
    CVE-2026-18972
    CVE-2026-65008
    CVE-2026-65007
    YuvalMil
  • Networks & protocols802
    Evidence
    OSCP+
    OSWP
    1675716
    OSCP
    A workstation sends hundreds of long, unique TXT queries under one domain every 30 seconds
  • Active Directory178
    Evidence
    1675716
    A service account has an SPN and a weak password. Which common attack tries to crack its s
  • Cryptographyno proof yet
  • Forensics & DFIRno proof yet
  • Recon & OSINTno proof yet
  • Cloud & containersno proof yet

The road to Exploit Hunter

945 pts short

Everything below is priced. Pick the cheapest one and the gap closes.

  1. Connect TryHackMe

    Points and completed rooms.

    +180
    points
    19% of the gap
  2. Clear another lab

    8 lab entries scored. 1,945 points left before the lab ceiling.

    +60
    points
    6% of the gap
  3. Publish a write-up

    Explain the bug, impact and fix. Peer-reviewed write-ups score after approval.

    +180
    points
    19% of the gap
  4. Submit a vulnerability report

    A confirmed low, medium, high or critical report is the cleanest path up the ladder.

    +160
    points
    17% of the gap
  5. Own 10 more machines

    Each user or system own is worth 4 points, and rank bonuses compound.

    +40
    points
    4% of the gap
  6. Earn Security+

    Verified against your credential URL.

    +80
    points
    8% of the gap

Not one figure above was typed in by n4h.

Read how points are earned
Get your credential
Rank requirements beyond points
  • Rank 4+ - One verified credential or one confirmed report
  • Rank 7+ - One confirmed report or one credited CVE
  • Rank 9+ - A credited CVE at CVSS 9.0+, or three critical confirmed reports