Skip to content
View fl0ydsec's full-sized avatar

Block or report fl0ydsec

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
fl0ydsec/README.md

FloydRoot banner
visitors   followers   region

0x01 · whoami

FloydRoot — fl0ydsec

Security researcher working the quiet routes: misconfigurations, trust boundaries and the code paths nobody audits. I don't chase the front door — I read what the system promised and never checked.

Every system trusts something. That's where I start.

dossier
callsign — FloydRoot
base — Brazil
mode — quiet
focus — web / binary / net
privileges — root
opsec — clean

0x02 · scope

domain practice
web application pentesting · source-code auditing
binary reverse engineering · exploit development
net protocol analysis · security tooling & automation

0x03 · loadout

python C bash php rust
kali linux docker postgres git
burp nmap wireshark metasploit ghidra
sqlmap hashcat

0x04 · signal

stats
streak
languages

0x05 · records

0x06 · hunt log

id class impact status
0DAY-XXXX RCE · firmware/IoT root shell in the wild
CVE-2025-XXXXX auth bypass · web full takeover reporting
CHAIN-XXXX deserialization → RCE reverse shell built
PRIV-ESC-XXXX kernel module ring 0 auditing

0x07 · bug classes

RCE · SQLi · AuthZ bypass · LFI/RFI · SSRF · deserialization · race conditions · PrivEsc · kernel

0x08 · contact

telegram


pgp key
-----BEGIN PGP PUBLIC KEY BLOCK-----
(cole sua chave publica aqui)
-----END PGP PUBLIC KEY BLOCK-----

man floydroot
NAME
    floydroot — quiet-route operator

SYNOPSIS
    floydroot [--target TARGET] [--mode quiet]

DESCRIPTION
    Studies trust boundaries, audits the unaudited,
    ships findings with proof.

FLAGS
    --exploit   build working PoCs
    --reverse   read binaries like prose
    --report    proof over noise

EXIT STATUS
    0   rooted. logs clean.

FloydRoot

access granted · logs clean


Popular repositories Loading

  1. fl0ydsec fl0ydsec Public

    FloydRoot

  2. CVE-2026-63030 CVE-2026-63030 Public

    WP2Shell - CVE-2026-63030 + CVE-2026-60137 WordPress Core pre-auth RCE mass exploit

    Python