Root Access Club
284 subscribers
90 photos
1 video
109 links
RootAccessClub ๐Ÿ’Ž

Security knowledge & research ๐Ÿ”Ž

Understanding systems, not abusing them โ›”๏ธ

โš ๏ธ Educational purposes only
Download Telegram
LeaksForums โ˜ ๏ธ

A series of leaks from hacker forums ๐Ÿ‘จโ€๐Ÿ’ป

GitHub ๐Ÿง‘โ€๐Ÿ’ป

๐ŸŒŸ@RootAccessClub
Please open Telegram to view this post
VIEW IN TELEGRAM
โคโ€๐Ÿ”ฅ32
๐๐ฎ๐ซ๐ฉ๐€๐๐ˆ๐’๐ž๐œ๐ฎ๐ซ๐ข๐ญ๐ฒ๐’๐ฎ๐ข๐ญ๐ž โญ๏ธ

Professional grade Burp Suite extension for comprehensive API reconnaissance, intelligent fuzzing, and AI powered security testing ๐Ÿ›ก

Features ๐Ÿช™

๐Ÿ˜ต Reconnaissance

โšก๏ธ Advanced Fuzzing

๐Ÿ”Ž Discovery Tools

๐Ÿ”ฅ Export & Integration

Installation ๐Ÿ–ฅ

1๏ธโƒฃ๐Ÿ”ฅBurp โžก๏ธ Extender โžก๏ธ Extensions โžก๏ธ Add โžก๏ธ Python

2๏ธโƒฃ Select๐Ÿ”ฅ BurpAPISecuritySuite.py
Extension loads and starts capturing automatically

Requirements โ‰๏ธ

Burp Suite (Professional or Community Edition) โœ…

Jython Standalone JAR
โœ…

GitHub ๐Ÿฑ

๐Ÿ’Ž@RootAccessClub
๐Ÿ’Ž@BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
3โšก1
UsingBYOVD โค๏ธ

A C++ based BYOVD (Bring Your Own Vulnerable Driver) security research and testing project ๐Ÿ–ฅ

It supports kernel-level operations including privilege escalation, physical memory R/W, and removing process protection via vulnerable drivers ๐Ÿ’ป

โ—๏ธDisclaimer: This project is created strictly for educational purposes, authorized security auditing, and malware research

Github ๐Ÿ“ฑ

๐Ÿ“‰ @RootAccessClub
Please open Telegram to view this post
VIEW IN TELEGRAM
2
Bug Bounty Dorks ๐Ÿคฉ

inurl /bug bounty
inurl : / security
inurl:security.txt
inurl:security "reward"
inurl : /responsible disclosure
inurl : /responsible-disclosure/ reward
inurl : / responsible-disclosure/ swag
inurl : / responsible-disclosure/ bounty


๐Ÿ’Ž@RootAccessClub
Please open Telegram to view this post
VIEW IN TELEGRAM
โคโ€๐Ÿ”ฅ2
unKover โ€“ 403 bypass tester ๐Ÿค”

unKover tests a URL returning 403 Forbidden against a set of proven bypass techniques and stops at the first successful one, returning a ready-to-run curl PoC
โ›ˆ

GitHub ๐Ÿ’ป

๐Ÿ˜Ž @RootAccessClub
Please open Telegram to view this post
VIEW IN TELEGRAM
3
FluxER โ€“ Fluxion Easy Runner for Termux ๐Ÿ“ฒ

Automated installer and launcher for Fluxion โ€“ a wireless security auditing toolkit for WPA/WPA2 testing and network analysis in Termux environments โญ๏ธ

Features โญ๏ธ

โšช๏ธAutomated Setup :
One-command installation of Ubuntu (proot) and Fluxion

โšช๏ธOptimized for Termux : Efficient resource usage and mobile-friendly

โšช๏ธNo Root Required : Works on non-rooted Android devices

โšช๏ธSmart Package Management : Only installs necessary dependencies

โšช๏ธError Handling: Robust installation with detailed progress feedback

โšช๏ธStorage Efficient:
Optional components to minimize space usage

โœ๏ธ Requirements :

๐ŸŸ Minimum Requirements

OS: Termux on Android 9.0+
Architecture: ARM64 (64-bit)
Storage: ~500MB-1GB free space
Internet: Stable connection for downloads
Permissions: Storage access (granted during setup)


๐ŸŸขRecommended

Android 9.0 or higher
2GB+ free storage for optimal performance
Wi-Fi connection for faster downloads


โณ Installation

โžก๏ธInstall Termux from F Droid (recommended) or GitHub

โžก๏ธUpdate Termux packages :

pkg update && pkg upgrade -y

โžก๏ธClone the repository :

git clone https://github.com/0n1cOn3/FluxER.git
cd FluxER

โžก๏ธMake the script executable :

chmod +x fluxer.sh

โžก๏ธRun FluxER :

./fluxer.sh

๐Ÿ“ฑ @RootAccessClub
Please open Telegram to view this post
VIEW IN TELEGRAM
3
New Web Based Subdomain Discovery Service ๐Ÿ”

crt.name is a new web based service for discovering subdomains through Certificate Transparency (CT) logs ๐ŸŒ

It searches publicly available certificate records to identify subdomains associated with a target domain ๐Ÿ”ต

Useful for โ“
โ€ข Subdomain Enumeration
โ€ข Reconnaissance
โ€ข Asset Discovery
โ€ข Bug Bounty Recon


crt.name ๐Ÿ”—

๐Ÿ’Ž @RootAccessClub
๐Ÿ’Ž @BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
2
PDF Exploit Defense Toolkit ๐Ÿ›ก

Two clean, pure-Python tools for handling malicious PDFs:

1๏ธโƒฃPDF Exploit Scanner

Detects high risk indicators (OpenAction, JS, Launch, XFA, heap spraysโ€ฆ) ๐Ÿค”

โžก๏ธ Structural patcher + full image based sanitizer included

GitHub ๐Ÿ˜จ

2๏ธโƒฃ IP Scanner for Exploited PDFs

Pulls hidden IPs/ranges from hijacked PDFs (byte-level) ๐Ÿค”

โžก๏ธ Scans common ports + temporary firewall to block them

GitHub ๐Ÿ˜จ

๐Ÿ›ฉ @RootAccessClub
Please open Telegram to view this post
VIEW IN TELEGRAM
DroneSploit โ€“ Opensource Metasploit alternative for drone pentesting ๐Ÿš

GitHub ๐Ÿ“ฑ

๐Ÿ’Ž @RootAccessClub
Please open Telegram to view this post
VIEW IN TELEGRAM
โšก3
numasec โ€“ The open source AI security agent ๐Ÿง 

numasec is an AI security agent that runs in your terminal โšช๏ธ

It uses the tools already installed on your machine, follows security runbooks, switches between cyber agents, keeps the operation context alive, tracks findings, stores evidence and helps turn the work into reports ๐Ÿค–

GitHub ๐Ÿฑ

๐Ÿ’Ž @RootAccessClub
Please open Telegram to view this post
VIEW IN TELEGRAM
โšก3
AutoCVE โ€“ One Click CVE Discovery: Select Projects, Audit Source Code, Verify Vulnerabilities, Generate Reports, Fully Automated ๐Ÿ’ฅ

GitHub ๐Ÿ˜€

๐Ÿ“ฑ @RootAccessClub
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ”ฅ2
PentestCode ๐Ÿ’ฅ

AI penetration testing agent in your terminal
Multi-agent architecture Engagement state tracking , 20+ LLM providers
โœจ

GitHub ๐Ÿ”—

๐Ÿ’Ž @RootAccessClub
๐Ÿ”ฅ4
How I Found 7 XSS Using a Custom Nuclei Template ๐Ÿ”ฌ

Read Here ๐Ÿ“–

#CyberSecurity #BugBounty #xss

โšก๏ธ@RootAccessClub
DarkTortilla RAT โ€“ Telegram Exfiltration & Payload Extraction โ˜ข

GitHub ๐Ÿ”—

#Payload #CyberSecurity

๐ŸชŽ @RootAccessClub
โšก2
BugScanner ๐Ÿฉป

Automated web security reconnaissance & vulnerability assessment tool for bug bounty hunters. Discover attack surfaces, fingerprint technologies, detect common web vulnerabilities, and generate actionable security reports ๐Ÿ“‹

GitHub

๐ŸŽ–@RootAccessClub
๐Ÿ”ฅ3
๐Ÿฆ  Stuxnet

A new GitHub project provides an educational reconstruction of the infamous Stuxnet worm, based on years of reverse engineering research into the original 2010 samples ๐Ÿ”ฌ

The project explores components such as rootkits, privilege escalation, Step7/S7 hooks, propagation mechanisms, and PLC-related functionality โš™๏ธ๐Ÿ’ป

๐Ÿงช Intended for malware analysis, security research, and academic study

GitHub ๐Ÿ”—

๐Ÿ’Ž @RootAccessClub
๐Ÿ”ฅ3โคโ€๐Ÿ”ฅ1
PSAITO โ€“ New PS5 WebKit Research ToolExperimental toolkit for PS5 ๐Ÿซฏ

firmware 9.00 โ€“ 13.60 โœ…

Browser only exploit that gives memory read/write + syscall primitives inside the WebKit process
โœจ

Research only โš ๏ธ

GitHub ๐Ÿ”—

๐Ÿฅ‡@RootAccessClub
knife โ€“ A reverse engineer's toolkit in Rust ๐Ÿ”ช

Parse, triage, disassemble, and audit PE, ELF, and Mach-O from one small binary. Static only: it reads the bytes on disk and never runs the target ๐ŸŽฏ

GitHub ๐ŸŒ

ยฉ @RootAccessClub
โคโ€๐Ÿ”ฅ2โšก1
Claude Red ๐ŸŒช

Offensive security skills for Claude a collection of "SKILL.md" files designed to turn Claude into a more context aware red team assistant

Covers areas like web security, AD, cloud, recon, exploit development, EDR evasion, and more
โญ๏ธ

GitHub ๐Ÿ”—

๐Ÿ›ก๏ธ@RootAccessClub
๐Ÿ”ฅ3
XSS Labs๐Ÿ”ฌ

An intentionally vulnerable lab environment for practicing XSS across different contexts, including Reflected, Stored, DOM-based, and JavaScript based XSS

A practical resource for learning how XSS works and how to mitigate it ๐Ÿ•ท๏ธ

Github ๐Ÿงช

โšก๏ธ @RootAccessClub
โคโ€๐Ÿ”ฅ4
CVE-2026-12793 โ€“ JetFormBuilder WordPress Plugin ๐Ÿ†˜

Critical vulnerability (CVSS 9.8) โš ๏ธ

Affects versions โ‰ค 3.6.2
Unauthenticated privilege escalation


Fixed in version 3.6.2.1 and later โœ…

Attack Flow :

1โƒฃ Detect JetFormBuilder + version โ‰ค 3.6.2 (readme.txt)

2โƒฃ Discover form ID from public pages (data-form-id, /register/, etc.)

4โƒฃ POST to referer page with ?jet_form_builder_submit=submit&method=ajax

4โƒฃ Register User action runs โ†’ new WP user created


If you're using this plugin, update immediately โ€ผ๏ธ

GitHub โ›“โ€๐Ÿ’ฅ

@RootAccessClub