Skip to content
View Ghost-xiaonan's full-sized avatar

Block or report Ghost-xiaonan

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
43 stars written in PHP
Clear filter

SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, se…

PHP 69,727 24,931 Updated Mar 26, 2026

Damn Vulnerable Web Application (DVWA)

PHP 12,813 4,684 Updated Mar 19, 2026

This is a webshell open source project

PHP 10,707 5,611 Updated Dec 24, 2024

Dictionary of attack patterns and primitives for black-box application fault injection and resource discovery.

PHP 8,862 2,125 Updated Nov 10, 2023

Postman汉化中文版

PHP 5,618 635 Updated Mar 2, 2022

ThinkPHP3.2 ——基于PHP5的简单快速的面向对象的PHP框架

PHP 2,903 1,490 Updated May 23, 2019

Collection of CTF Web challenges I made

PHP 2,825 481 Updated Aug 31, 2025

ezXSS is an easy way for penetration testers and bug bounty hunters to test (blind) Cross Site Scripting.

PHP 2,252 378 Updated Jan 8, 2026

h-m-m, or Hackers Mind Map, is a simple, fast, keyboard-centric terminal-based tool for working with mind maps.

PHP 2,229 57 Updated Mar 12, 2026

WDScanner平台目前实现了如下功能:分布式web漏洞扫描、客户管理、漏洞定期扫描、子域名枚举、端口扫描、网站爬虫、暗链检测、坏链检测、网站指纹搜集、专项漏洞检测、代理搜集及部署等功能。

PHP 2,102 548 Updated Jun 22, 2020

Webshell && Backdoor Collection

PHP 1,990 1,036 Updated Apr 6, 2020

Common PHP webshells you might need for your Penetration Testing assignments or CTF challenges. Do not host the file(s) on your server!

PHP 1,936 774 Updated Mar 3, 2021

一个关于PHP的代码审计项目

PHP 1,916 341 Updated Sep 17, 2019

构建优化高效的渗透 fuzz 字典合集

PHP 1,890 337 Updated Jun 17, 2025

一个漏洞扫描器粘合剂,添加目标后30款工具自动调用;支持 web扫描、系统扫描、子域名收集、目录扫描、主机扫描、主机发现、组件识别、URL爬虫、XRAY扫描、AWVS自动扫描、POC批量验证,SSH批量测试、vulmap。

PHP 1,825 295 Updated Mar 26, 2026

Pwn stuff.

PHP 1,806 392 Updated May 31, 2022

CMS漏洞测试用例集合

PHP 1,766 518 Updated Dec 20, 2018

PHP代码审计分段讲解

PHP 1,721 366 Updated Aug 29, 2022

PHP版本的离线IP地址定位库

PHP 1,364 206 Updated Jan 17, 2026

码小六 - GitHub 代码泄露监控系统

PHP 1,177 205 Updated Apr 17, 2024

Various webshells. We accept pull requests for additions to this collection.

PHP 1,015 347 Updated Oct 4, 2023

AppSec Payloads Arsenal for Pentration Tester and Bug Bounty Hunters

PHP 921 190 Updated Mar 12, 2026

ThinkPHP漏洞综合利用工具, 图形化界面, 命令执行, 一键getshell, 批量检测, 日志遍历, session包含,宝塔绕过

PHP 771 105 Updated Jul 2, 2022

Wikitten is a small, fast, PHP wiki, and the perfect place to store your notes, code snippets, ideas, and so on.

PHP 750 165 Updated Dec 25, 2023

一个经典的XSS渗透管理平台

PHP 732 199 Updated Mar 12, 2026

Exploitation for XSS

PHP 730 161 Updated Aug 5, 2021

phpcs-security-audit is a set of PHP_CodeSniffer rules that finds vulnerabilities and weaknesses related to security in PHP code

PHP 726 82 Updated Jan 5, 2023

OpenSource Poc && Vulnerable-Target Storage Box.

PHP 682 219 Updated Feb 6, 2023

适用于一线安服的ctf培训题目,全docker环境一键启动

PHP 553 135 Updated Nov 8, 2023
Next