Root Access Club
284 subscribers
90 photos
1 video
109 links
RootAccessClub πŸ’Ž

Security knowledge & research πŸ”Ž

Understanding systems, not abusing them ⛔️

⚠️ Educational purposes only
Download Telegram
New Web Based Subdomain Discovery Service πŸ”

crt.name is a new web based service for discovering subdomains through Certificate Transparency (CT) logs 🌐

It searches publicly available certificate records to identify subdomains associated with a target domain πŸ”΅

Useful for ❓
β€’ Subdomain Enumeration
β€’ Reconnaissance
β€’ Asset Discovery
β€’ Bug Bounty Recon


crt.name πŸ”—

πŸ’Ž @RootAccessClub
πŸ’Ž @BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
2
PDF Exploit Defense Toolkit πŸ›‘

Two clean, pure-Python tools for handling malicious PDFs:

1️⃣PDF Exploit Scanner

Detects high risk indicators (OpenAction, JS, Launch, XFA, heap sprays…) πŸ€”

➑️ Structural patcher + full image based sanitizer included

GitHub 😨

2️⃣ IP Scanner for Exploited PDFs

Pulls hidden IPs/ranges from hijacked PDFs (byte-level) πŸ€”

➑️ Scans common ports + temporary firewall to block them

GitHub 😨

πŸ›© @RootAccessClub
Please open Telegram to view this post
VIEW IN TELEGRAM
DroneSploit – Opensource Metasploit alternative for drone pentesting 🚁

GitHub πŸ“±

πŸ’Ž @RootAccessClub
Please open Telegram to view this post
VIEW IN TELEGRAM
⚑3
numasec – The open source AI security agent 🧠

numasec is an AI security agent that runs in your terminal βšͺ️

It uses the tools already installed on your machine, follows security runbooks, switches between cyber agents, keeps the operation context alive, tracks findings, stores evidence and helps turn the work into reports πŸ€–

GitHub 🐱

πŸ’Ž @RootAccessClub
Please open Telegram to view this post
VIEW IN TELEGRAM
⚑3
AutoCVE – One Click CVE Discovery: Select Projects, Audit Source Code, Verify Vulnerabilities, Generate Reports, Fully Automated πŸ’₯

GitHub πŸ˜€

πŸ“± @RootAccessClub
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ”₯2
PentestCode πŸ’₯

AI penetration testing agent in your terminal
Multi-agent architecture Engagement state tracking , 20+ LLM providers
✨

GitHub πŸ”—

πŸ’Ž @RootAccessClub
πŸ”₯4
How I Found 7 XSS Using a Custom Nuclei Template πŸ”¬

Read Here πŸ“–

#CyberSecurity #BugBounty #xss

⚑️@RootAccessClub
DarkTortilla RAT – Telegram Exfiltration & Payload Extraction ☒

GitHub πŸ”—

#Payload #CyberSecurity

πŸͺŽ @RootAccessClub
⚑2
BugScanner 🩻

Automated web security reconnaissance & vulnerability assessment tool for bug bounty hunters. Discover attack surfaces, fingerprint technologies, detect common web vulnerabilities, and generate actionable security reports πŸ“‹

GitHub

πŸŽ–@RootAccessClub
πŸ”₯3
🦠 Stuxnet

A new GitHub project provides an educational reconstruction of the infamous Stuxnet worm, based on years of reverse engineering research into the original 2010 samples πŸ”¬

The project explores components such as rootkits, privilege escalation, Step7/S7 hooks, propagation mechanisms, and PLC-related functionality βš™οΈπŸ’»

πŸ§ͺ Intended for malware analysis, security research, and academic study

GitHub πŸ”—

πŸ’Ž @RootAccessClub
πŸ”₯3❀‍πŸ”₯1
PSAITO – New PS5 WebKit Research ToolExperimental toolkit for PS5 🫯

firmware 9.00 – 13.60 βœ…

Browser only exploit that gives memory read/write + syscall primitives inside the WebKit process
✨

Research only ⚠️

GitHub πŸ”—

πŸ₯‡@RootAccessClub
knife – A reverse engineer's toolkit in Rust πŸ”ͺ

Parse, triage, disassemble, and audit PE, ELF, and Mach-O from one small binary. Static only: it reads the bytes on disk and never runs the target 🎯

GitHub 🌐

Β© @RootAccessClub
❀‍πŸ”₯2⚑1
Claude Red πŸŒͺ

Offensive security skills for Claude a collection of "SKILL.md" files designed to turn Claude into a more context aware red team assistant

Covers areas like web security, AD, cloud, recon, exploit development, EDR evasion, and more
⭐️

GitHub πŸ”—

πŸ›‘οΈ@RootAccessClub
πŸ”₯3
XSS LabsπŸ”¬

An intentionally vulnerable lab environment for practicing XSS across different contexts, including Reflected, Stored, DOM-based, and JavaScript based XSS

A practical resource for learning how XSS works and how to mitigate it πŸ•·οΈ

Github πŸ§ͺ

⚑️ @RootAccessClub
❀‍πŸ”₯4
CVE-2026-12793 – JetFormBuilder WordPress Plugin πŸ†˜

Critical vulnerability (CVSS 9.8) ⚠️

Affects versions ≀ 3.6.2
Unauthenticated privilege escalation


Fixed in version 3.6.2.1 and later βœ…

Attack Flow :

1⃣ Detect JetFormBuilder + version ≀ 3.6.2 (readme.txt)

2⃣ Discover form ID from public pages (data-form-id, /register/, etc.)

4⃣ POST to referer page with ?jet_form_builder_submit=submit&method=ajax

4⃣ Register User action runs β†’ new WP user created


If you're using this plugin, update immediately ‼️

GitHub ⛓‍πŸ’₯

@RootAccessClub
OWASP Amass πŸ”Ž

An open source framework for network mapping and attack surface discovery

β€’ Subdomain & DNS enumeration
β€’ OSINT-based asset discovery
β€’ Infrastructure mapping
β€’ External attack surface analysis


Built by OWASP, Amass is a solid reconnaissance tool for security researchers and bug bounty hunters ⭐️

GitHub πŸ”—

πŸ’Ž @RootAccessClub
πŸ”₯2
Legion β€” Automated Network Pentesting πŸ›‘οΈ

Legion is a GUI based network penetration testing framework built to automate reconnaissance, scanning, service enumeration, and vulnerability discovery

πŸ”Έ Nmap, Nikto, WhatWeb, Hydra, SMBenum

πŸ”Ή CVE & vulnerability mapping

πŸ”Έ Automated scanning & enumeration

Github πŸ”—

πŸ“‘ @RootAccessClub
❀‍πŸ”₯2
CVE-2026-21858 + CVE-2025-68613 - n8n Full Chain πŸ’₯

Unauthenticated Arbitrary File Read β†’ Admin Token Forge β†’ Sandbox Bypass β†’ RCE πŸŒͺ

CVSS : 10.0 + 9.9 (Critical) ⚠️
Fixed : 1.121.0 (AFR) / 1.120.4+ (RCE) βœ…


Github 🌐

πŸͺŽ @RootAccessClub
❀‍πŸ”₯1
Osintgram πŸ‘₯

An open source OSINT framework for Instagram reconnaissance and information gathering πŸ”Ž

Key Features:

β€’ Profile & content analysis
β€’ Followers / Following analysis
β€’ Hashtag & location searches
β€’ Media and metadata analysis
β€’ Account comparison
β€’ Interactive Web UI
β€’ AI assisted mode with local Ollama support
β€’ JSON & HTML report generation


GitHub πŸ”—

⚠️ Use responsibly and only with data you are authorized to investigate

πŸ’Ž @RootAccessClub
❀‍πŸ”₯4
WordPress Critical RCE 🚨

CVE-2026-87902 | CVSS 9.2 🫯

A critical unauthenticated path traversal vulnerability in WordPress Core can, under specific conditions, lead to Remote Code Execution (RCE) through page template resolution πŸ’£

Affected versions span 4.7 β†’ 7.1.1 🦠

πŸ›‘οΈ Fix: Update to the latest patched WordPress release for your branch

GitHub πŸ”—

@RootAccessClub
πŸ”₯2