{"owner":"dinosn","github":"https://github.com/dinosn","claimed":false,"inventory":[],"indexed":[{"repo":"dinosn/fastjson-jsontype-rce-lab","github":"https://github.com/dinosn/fastjson-jsontype-rce-lab","description":"Docker labs + defensive scanner for fastjson remote-class-load RCE. fastjson 1.2.66-1.2.83: @JSONType resource probe (CVE-2026-16723). fastjson2 2.0.57: attacker @type reaches loadClass with autoType DISABLED via polymorphic types (@JSONType(seeAlso) / Jackson @JsonSubTypes). Marker-only payloads; safeMode + JDK17 controls.","language":"Python","stars":203,"topics":["appsec","deserialization","fastjson","jsontype","poc","rce","security","security-lab","spring-boot","ssrf"],"license":"MIT","category":"security-tools"},{"repo":"dinosn/wp2shell-lab","github":"https://github.com/dinosn/wp2shell-lab","description":"Non-destructive detector + Docker lab for wp2shell (CVE-2026-63030 REST /batch/v1 route confusion + CVE-2026-60137 author__not_in SQLi) in WordPress core 6.9.0-6.9.4 / 7.0.0-7.0.1","language":"Python","stars":55,"topics":["security","sql-injection","vulnerability-lab","wordpress","wp2shell","cve-2026-60137","cve-2026-63030"],"license":"MIT","category":"security-tools"}],"how_to_buy":"GET /r/dinosn/<repo> (Accept: application/json) for any listed repo here: tree, README, price and the checkout to pay (x402; rehearse first at its test twin, simulated money). Repos under 'indexed' are free: clone them from GitHub."}