Skip to content
View cowbe0x004's full-sized avatar

Block or report cowbe0x004

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
62 stars written in PHP
Clear filter

SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, se…

PHP 66,753 24,748 Updated Nov 7, 2025

Modern, Crazy Fast, Ridiculously Easy and Amazingly Powerful Flat-File CMS powered by PHP, Markdown, Twig, and Symfony

PHP 15,239 1,424 Updated Nov 6, 2025

Damn Vulnerable Web Application (DVWA)

PHP 12,095 4,342 Updated Nov 6, 2025

This is a webshell open source project

PHP 10,583 5,609 Updated Dec 24, 2024

Dictionary of attack patterns and primitives for black-box application fault injection and resource discovery.

PHP 8,722 2,118 Updated Nov 10, 2023

A curated list of resources for learning about application security

PHP 6,708 769 Updated Feb 22, 2025

MISP (core software) - Open Source Threat Intelligence and Sharing Platform

PHP 5,995 1,523 Updated Nov 6, 2025

A PHP static analysis tool for finding errors and security vulnerabilities in PHP applications

PHP 5,769 683 Updated Oct 15, 2025

SQLI labs to test error based, Blind boolean based, Time based.

PHP 5,621 1,549 Updated Dec 11, 2023

Community-based GPL-licensed network monitoring system

PHP 4,439 2,530 Updated Nov 6, 2025

Bolt is a simple CMS written in PHP. It is based on Silex and Symfony components, uses Twig and either SQLite, MySQL or PostgreSQL.

PHP 4,150 810 Updated Jun 27, 2023

一个想帮你总结所有类型的上传漏洞的靶场

PHP 4,058 826 Updated Jun 26, 2023
PHP 3,738 628 Updated Mar 14, 2024

PHPGGC is a library of PHP unserialize() payloads along with a tool to generate them, from command line or programmatically.

PHP 3,635 533 Updated Sep 29, 2025

Collection of CTF Web challenges I made

PHP 2,793 481 Updated Aug 31, 2025

Single-file PHP shell

PHP 2,604 674 Updated Aug 11, 2025

A database of PHP security advisories

PHP 2,100 308 Updated Aug 29, 2025

Webshell && Backdoor Collection

PHP 1,950 1,037 Updated Apr 6, 2020

Common PHP webshells you might need for your Penetration Testing assignments or CTF challenges. Do not host the file(s) on your server!

PHP 1,924 780 Updated Mar 3, 2021

Pwn stuff.

PHP 1,804 389 Updated May 31, 2022

XVWA is a badly coded web application written in PHP/MySQL that helps security enthusiasts to learn application security.

PHP 1,743 352 Updated Sep 12, 2020

Detect potentially malicious PHP files

PHP 1,479 283 Updated Oct 20, 2023

OWASP Mutillidae II is a free, open-source, deliberately vulnerable web application providing a target for web-security training. This is an easy-to-use web hacking environment designed for labs, s…

PHP 1,428 510 Updated Aug 3, 2025

Systems Password Manager

PHP 994 215 Updated Dec 21, 2024

A laboratory for learning secure web and mobile development in a practical manner.

PHP 963 463 Updated Sep 25, 2024

PHP Secure Configuration Checker

PHP 818 130 Updated Apr 11, 2024

Hardening Script for Linux Servers/ Secure LAMP-LEMP Deployer/ CIS Benchmark

PHP 781 244 Updated Oct 2, 2023

🎯 PHP / ASP - Shell Backdoor List 🎯

PHP 768 561 Updated Nov 18, 2023

This Lab contain the sample codes which are vulnerable to Server-Side Request Forgery attack

PHP 741 198 Updated Aug 21, 2023

A ready to use JSONP endpoints/payloads to help bypass content security policy (CSP) of different websites.

PHP 731 110 Updated May 6, 2024
Next