Root Access Club
前往频道在 Telegram
RootAccessClub 💎 Security knowledge & research 🔎 Understanding systems, not abusing them ⛔️ ⚠️ Educational purposes only
显示更多未指定国家未指定类别
289
订阅者
+224 小时
+147 天
+3030 天
帖子存档
Toxssin – An XSS exploitation command line interface and payload generator
toxssin is an open source penetration testing tool that automates the process of exploiting Cross-Site Scripting (XSS) vulnerabilities. It consists of an https server that works as an interpreter for the traffic generated by the malicious JavaScript payload that powers this tool (toxin.js) 🦠
GitHub 🌐
💎 @RootAccessClub
Open redirects filter bypass payloads 💥
---->\/evil.com
---->\/\/evil.com
---->\\evil.com
----//evil.com
---->//theirsite@evil.com
---->////evil.com
----//google%E3%80%82com
---->//%2F/evil.com
---->////evil.com
---->/%2F/yoururl.com
@RootAccessClub
Path Traversal Bypasses ⚡️
Null Byte Injection
../../../etc/./passwd%00.png
Stripped Dot-Dot-Slash
..././..././..././e../tc..//pas../swd
Multi-Stage Decoding
..%2%35%32F..%2%35%32F..%2%35%32Fetc%2%35%32F/passwd
Truncation Appending (4096 bytes)
../../../etc/./passwd/././././././
⭐️ @RootAccessClub
Relapse – PS5 Jailbreak Exploit 🎮
A new exploit chain called Relapse has been released, targeting PS5 firmware versions 7.00 through 13.60 🎯
🔹 WebKit Exploit
🔹 Kernel Exploit
🔹 Execution of unofficial payloads
🔹 Support for payloads such as kstuff and etaHEN
When successfully executed, Relapse can enable a Jailbreak environment and allow execution of unofficial code and payloads on the PS5 💥
⚠️ Check your console's firmware version before attempting anything
GitHub 🔗
@RootAccessCLUB
AutoPWN Suite ⚡️
An automated penetration testing framework designed to streamline reconnaissance, vulnerability discovery, and security testing ✨
• Nmap-based network & service enumeration
• CVE & vulnerability discovery
• Automated exploit searching
• Web vulnerability testing
• Directory enumeration
• Web UI + REST API
• Scan scheduling & automation
• Email / Webhook notifications
• Optional evasion techniques
GitHub 🔗
🌪 @RootAccessClub
Prompt Injection in the Wild 💉
A look at real world In Page Prompt Injection attacks, where malicious instructions are hidden inside web content and processed by AI systems
Link 🔗
@RootAccessClub
CVE-2026-87902 – WordPress Core – PHP Template Path Traversal 🧩
Nuclei Template ⚙
⚠️ Authorized security testing, education, and defensive research only
⚡️@RootAccessClub
CVE-2026-87902 🪤
PoC for CVE-2026-87902 – unauthenticated path traversal in WordPress page-template resolution (local PHP inclusion, conditional RCE) with a pinned vulnerable lab
GitHub 🔗
⚠️ Authorized security testing, education, and defensive research only
💎 @RootAccessClub
CVE-2026-87902 🧪
WordPress unauthenticated LFI → conditional RCE 💉
Github 📎
⚠️ Authorized security testing, education, and defensive research only
💠 @RootAccessClub
WordPress Critical RCE 🚨
CVE-2026-87902 | CVSS 9.2
A critical unauthenticated path traversal vulnerability in WordPress Core can, under specific conditions, lead to Remote Code Execution (RCE) through page-template resolution 💣
Affected versions span 4.7 → 7.1.1 🦠
🛡️ Fix: Update to the latest patched WordPress release for your branch
GitHub 🔗
@RootAccessClub
Osintgram 👥
An open-source OSINT framework for Instagram reconnaissance and information gathering 🔎
Key Features:
• Profile & content analysis
• Followers / Following analysis
• Hashtag & location searches
• Media and metadata analysis
• Account comparison
• Interactive Web UI
• AI-assisted mode with local Ollama support
• JSON & HTML report generation
GitHub 🔗
⚠️ Use responsibly and only with data you are authorized to investigate
💎 @RootAccessClub
CVE-2026-21858 + CVE-2025-68613 - n8n Full Chain 💥
Unauthenticated Arbitrary File Read → Admin Token Forge → Sandbox Bypass → RCE 🌪
CVSS : 10.0 + 9.9 (Critical) ⚠️
Fixed : 1.121.0 (AFR) / 1.120.4+ (RCE) ✅
Github 🌐
@RootAccessClub
Legion — Automated Network Pentesting 🛡️
Legion is a GUI based network penetration testing framework built to automate reconnaissance, scanning, service enumeration, and vulnerability discovery
Nmap, Nikto, WhatWeb, Hydra, SMBenum 🔎
CVE & vulnerability mapping 🧩
Automated scanning & enumeration ⚙️
Github 🔗
📡 @RootAccessClub
OWASP Amass 🔎
An open source framework for network mapping and attack surface discovery
• Subdomain & DNS enumeration
• OSINT-based asset discovery
• Infrastructure mapping
• External attack surface analysis
Built by OWASP, Amass is a solid reconnaissance tool for security researchers and bug bounty hunters ⭐️
GitHub 🔗
💎 @RootAccessClub
CVE-2026-12793 – JetFormBuilder WordPress Plugin 🆘
Critical vulnerability (CVSS 9.8) ⚠️
Affects versions ≤ 3.6.2
Unauthenticated privilege escalation
Fixed in version 3.6.2.1 and later ✅
Attack Flow :
1⃣ Detect JetFormBuilder + version ≤ 3.6.2 (readme.txt)
2⃣ Discover form ID from public pages (data-form-id, /register/, etc.)
4⃣ POST to referer page with ?jet_form_builder_submit=submit&method=ajax
4⃣ Register User action runs → new WP user created
If you're using this plugin, update immediately ‼️
GitHub ⛓💥
@RootAccessClub
XSS Labs🔬
An intentionally vulnerable lab environment for practicing XSS across different contexts, including Reflected, Stored, DOM-based, and JavaScript based XSS
A practical resource for learning how XSS works and how to mitigate it 🕷️
Github 🧪
⚡️ @RootAccessClub
Claude Red 🌪
Offensive security skills for Claude a collection of "SKILL.md" files designed to turn Claude into a more context aware red team assistant
Covers areas like web security, AD, cloud, recon, exploit development, EDR evasion, and more ⭐️
GitHub 🔗
🛡️@RootAccessClub
knife – A reverse engineer's toolkit in Rust 🔪
Parse, triage, disassemble, and audit PE, ELF, and Mach-O from one small binary. Static only: it reads the bytes on disk and never runs the target 🎯
GitHub 🌐
© @RootAccessClub
PSAITO – New PS5 WebKit Research ToolExperimental toolkit for PS5
firmware 9.00 – 13.60.Browser only exploit that gives memory read/write + syscall primitives inside the WebKit process ✨
Research only ⚠️
GitHub 🔗
🥇@RootAccessClub
