{"id":13538614,"url":"https://github.com/zhuifengshaonianhanlu/pikachu","last_synced_at":"2025-10-09T12:07:04.017Z","repository":{"id":37735428,"uuid":"142127816","full_name":"zhuifengshaonianhanlu/pikachu","owner":"zhuifengshaonianhanlu","description":"一个好玩的Web安全-漏洞测试平台","archived":false,"fork":false,"pushed_at":"2023-12-19T09:02:12.000Z","size":3548,"stargazers_count":4123,"open_issues_count":26,"forks_count":781,"subscribers_count":56,"default_branch":"master","last_synced_at":"2025-10-09T12:07:03.267Z","etag":null,"topics":["web"],"latest_commit_sha":null,"homepage":"","language":"PHP","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/zhuifengshaonianhanlu.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2018-07-24T08:21:19.000Z","updated_at":"2025-10-07T13:29:14.000Z","dependencies_parsed_at":"2024-08-01T09:21:59.256Z","dependency_job_id":"3edf8db4-ca4c-44d3-938d-61163f3dc47c","html_url":"https://github.com/zhuifengshaonianhanlu/pikachu","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"purl":"pkg:github/zhuifengshaonianhanlu/pikachu","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/zhuifengshaonianhanlu%2Fpikachu","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/zhuifengshaonianhanlu%2Fpikachu/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/zhuifengshaonianhanlu%2Fpikachu/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/zhuifengshaonianhanlu%2Fpikachu/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/zhuifengshaonianhanlu","download_url":"https://codeload.github.com/zhuifengshaonianhanlu/pikachu/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/zhuifengshaonianhanlu%2Fpikachu/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":279001441,"owners_count":26083078,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","status":"online","status_checked_at":"2025-10-09T02:00:07.460Z","response_time":59,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["web"],"created_at":"2024-08-01T09:01:14.172Z","updated_at":"2025-10-09T12:07:03.990Z","avatar_url":"https://github.com/zhuifengshaonianhanlu.png","language":"PHP","funding_links":[],"categories":["PHP","PHP (184)","\u003ca id=\"683b645c2162a1fce5f24ac2abfa1973\"\u003e\u003c/a\u003e漏洞\u0026\u0026漏洞管理\u0026\u0026漏洞发现/挖掘\u0026\u0026漏洞开发\u0026\u0026漏洞利用\u0026\u0026Fuzzing","Wargames"],"sub_categories":["\u003ca id=\"9d1ce4a40c660c0ce15aec6daf7f56dd\"\u003e\u003c/a\u003e未分类-Vul"],"readme":"![](https://img.shields.io/badge/web安全-靶场-PTEST)\n![](https://img.shields.io/badge/version-1.0-success)\n![](https://img.shields.io/github/stars/zhuifengshaonianhanlu/pikachu.svg)\n![](https://img.shields.io/github/forks/zhuifengshaonianhanlu/pikachu.svg)\n![](https://img.shields.io/github/license/zhuifengshaonianhanlu/pikachu.svg)\n\n“如果你想搞懂一个漏洞，比较好的方法是：你可以自己先制造出这个漏洞（用代码编写），然后再利用它，最后再修复它”。\n\n\u003cbr\u003e\n# pikachu\n\nPikachu是一个带有漏洞的Web应用系统，在这里包含了常见的web安全漏洞。 如果你是一个Web渗透测试学习人员且正发愁没有合适的靶场进行练习，那么Pikachu可能正合你意。\u003cbr\u003e\n\n## Pikachu上的漏洞类型列表如下：\u003cbr\u003e\n* Burt Force(暴力破解漏洞)\u003cbr\u003e\n* XSS(跨站脚本漏洞)\u003cbr\u003e\n* CSRF(跨站请求伪造)\u003cbr\u003e\n* SQL-Inject(SQL注入漏洞)\u003cbr\u003e\n* RCE(远程命令/代码执行)\u003cbr\u003e\n* Files Inclusion(文件包含漏洞)\u003cbr\u003e\n* Unsafe file downloads(不安全的文件下载)\u003cbr\u003e\n* Unsafe file uploads(不安全的文件上传)\u003cbr\u003e\n* Over Permisson(越权漏洞)\u003cbr\u003e\n* ../../../(目录遍历)\u003cbr\u003e\n* I can see your ABC(敏感信息泄露)\u003cbr\u003e\n* PHP反序列化漏洞\u003cbr\u003e\n* XXE(XML External Entity attack)\u003cbr\u003e\n* 不安全的URL重定向\u003cbr\u003e\n* SSRF(Server-Side Request Forgery)\u003cbr\u003e\n* 管理工具\u003cbr\u003e\n* More...(找找看?..有彩蛋!)\u003cbr\u003e\n\n管理工具里面提供了一个简易的xss管理后台,供你测试钓鱼和捞cookie,还可以搞键盘记录！~\u003cbr\u003e\n后续会持续更新一些新的漏洞进来,也欢迎你提交漏洞案例给我,最新版本请关注pikachu\u003cbr\u003e\n每类漏洞根据不同的情况又分别设计了不同的子类\u003cbr\u003e\n同时,为了让这些漏洞变的有意思一些,在Pikachu平台上为每个漏洞都设计了一些小的场景,点击漏洞页面右上角的\"提示\"可以查看到帮助信息。\u003cbr\u003e\n\n\n## 如何安装和使用\nPikachu使用世界上最好的语言PHP进行开发-_-\u003cbr\u003e\n数据库使用的是mysql，因此运行Pikachu你需要提前安装好\"PHP+MYSQL+中间件（如apache,nginx等）\"的基础环境，建议在你的测试环境直接使用 一些集成软件来搭建这些基础环境,比如XAMPP,WAMP等,作为一个搞安全的人,这些东西对你来说应该不是什么难事。接下来:\u003cbr\u003e\n--\u003e把下载下来的pikachu文件夹放到web服务器根目录下;\u003cbr\u003e\n--\u003e根据实际情况修改inc/config.inc.php里面的数据库连接配置;\u003cbr\u003e\n--\u003e访问h ttp://x.x.x.x/pikachu,会有一个红色的热情提示\"欢迎使用,pikachu还没有初始化，点击进行初始化安装!\",点击即可完成安装。\u003cbr\u003e\n\u003cbr\u003e\n\u003cbr\u003e\n\n如果阁下对Pikachu使用上有什么疑问，可以在QQ群：532078894（已满），973351978（未满） 咨询，虽然咨询了，也不一定有人回答-_-。\n\n## Docker\n\n使用已有构建：\n```bash\ndocker run -d -p 8765:80 8023/pikachu-expect:latest\n```\n\n本地构建：\n```bash\n如果你熟悉docker,也可以直接用docker部署\ndocker build -t \"pikachu\" .\ndocker run -d -p 8080:80 pikachu\n```\n\n## 切记\n\n\"少就是多,慢就是快\"\n\n\n## WIKI\n[点击进入](https://github.com/zhuifengshaonianhanlu/pikachu/wiki/01:%E6%89%AF%E5%9C%A8%E5%89%8D%E9%9D%A2)\n\n\n\n\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fzhuifengshaonianhanlu%2Fpikachu","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fzhuifengshaonianhanlu%2Fpikachu","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fzhuifengshaonianhanlu%2Fpikachu/lists"}