Skip to content

Payloads All The Things (Chinese Translation Edition)

A list of useful payloads and bypasses for Web Application Security. Feel free to contribute your payloads and techniques!

banner

Twitter

This is the 100% full Chinese translation version of the well-known security repository PayloadsAllTheThings. It aims to provide the Chinese security community with a precise, readable, and synchronized technical reference manual.


🌐 Multi-language Support

This repository integrates MkDocs multi-language switching functionality. You can visit the online document preview (if deployed) or switch between English and Chinese locally via MkDocs.

  • English Original (Default): See README.md under each subdirectory.
  • Chinese Translation: See README.zh.md under each subdirectory or corresponding exclusive technical documents.

πŸ“– Documentation

Each topic contains the following structure. You can use the _template_vuln folder to create a new chapter:

  • README.md - Vulnerability descriptions, how to exploit them, and multiple payloads.
  • Intruder - A set of files provided to Burp Intruder.
  • Images/Files - Images and files referenced in the documentation.

Core Topic Coverage


πŸ§‘β€πŸ’» Learning Resources

Looking for more advanced content? Check out our curated resources:


🀝 Contributions & Feedback

Your contributions are highly welcome! Before submitting a PR, please make sure to read our Contributing Guidelines.

This project follows the open-source spirit of the original repository. Thanks to all global contributors who have contributed to PayloadsAllTheThings! ❀️

🍻 Sponsors

This project is proudly sponsored by the following companies.

Company Logo Description
sponsor-serpapi SerpApi is a real-time API to access Google search results. It solves the issues of renting proxies, handeling CAPTCHAs and JSON parsing.
sponsor-projectdiscovery ProjectDiscovery - Detect real, exploitable vulnerabilities. Harness the power of Nuclei for fast, accurate discovery with zero false positives.
sponsor-vaadata VAADATA - Ethical Hacking Services.