Skip to content
View winmin's full-sized avatar
🤣
Read the fucking source code
🤣
Read the fucking source code

Organizations

@FlappyPig @r3kapig

Block or report winmin

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
winmin/README.md

Typing SVG

CVEs Blog Twitter

About Me

  • Security Researcher | CTF Player @FlappyPig @r3kapig
  • Focus on Vulnerability Discovering | Active in CTF, PWN/Reverse

Publications

  • CTF特训营:技术详解、解题方法与竞赛技巧 - Author
  • 硬件系统模糊测试技术解密与案例分析 - Translator

Awards

Year Team Award
2025 0x300 天网杯信创关键产品漏洞挖掘挑战赛 1st
2024 0x300 天网杯信创关键产品漏洞挖掘挑战赛 1st & 矩阵杯国产软硬件安全检测赛 1st
2023 跃哥我真不会啊 / 0x300 Datacon 漏洞分析赛道 Champion / CSST 天网杯 2nd
2021 0x300 首届信创关键产品安全挑战赛 2nd / 天府杯最佳漏洞复现奖 / 天府杯 Docker Escape & Ubuntu LPE
2019 Chaitin GeekPwn & HUAWEI Smart Device Security Challenge / MAXHUB Exploit
2018 Piggy mine GeekPwn Best Demo Award

CVEs

HUAWEI: CVE-2019-5268 | CVE-2019-5269

DrayTek: CVE-2020-14472 | CVE-2020-14473

QNAP: CVE-2020-2490 | CVE-2020-2492

CISCO: CVE-2021-1207 | CVE-2021-1209 | CVE-2021-1164 | CVE-2021-1307 | CVE-2021-1293 | CVE-2021-1295 | CVE-2021-1609 | CVE-2021-1610

D-Link: CVE-2020-25506

ZYXEL: CVE-2020-29299

XIAOMI: CVE-2020-14102

Linux Kernel: CVE-2021-4001 | CVE-2025-38477 | CVE-2025-40083 | CVE-2025-68325 | CVE-2026-22977 | CVE-2026-23276 | CVE-2026-23277

Netgear: CVE-2021-45527 | CVE-2023-36187

ASUS: CVE-2023-35086 | CVE-2023-35087 | CVE-2023-39238 | CVE-2023-39239 | CVE-2023-39240 | CVE-2024-3079 | CVE-2024-3080

Other: CVE-2021-33630 | CVE-2021-33631 | CVE-2021-29629 | CVE-2020-15137 | CVE-2020-24074 | CVE-2020-15173 | CVE-2020-28194 | CVE-2020-36109 | CVE-2023-24805 | CVE-2022-43294 | CVE-2026-22777

Synology: 2021 Acknowledgement

OPPO: 2021 IoT Bug Bounty Top 18

GitHub Stats

Github Stats

Pinned Loading

  1. PwnBox PwnBox Public

    Script to setup pwn environment with Docker

    Python 49 9

  2. evil-opencode evil-opencode Public

    Forked from anomalyco/opencode

    The open source coding agent. (Unleashed 、Removing LLM safety guardrails)

    TypeScript 201 15

  3. ida-pro-mcp ida-pro-mcp Public

    Forked from mrexodia/ida-pro-mcp

    AI-powered reverse engineering assistant that bridges IDA Pro with language models through MCP.

    Python 57 2

  4. kernel-vuln-analyzer kernel-vuln-analyzer Public

    Claude Code skill for Linux kernel vulnerability analysis — from crash log triage to patch verification

    Shell 23

  5. vulhub/vulhub vulhub/vulhub Public

    Pre-Built Vulnerable Environments Based on Docker-Compose

    Dockerfile 20.4k 4.8k

  6. ctf-wiki/ctf-wiki ctf-wiki/ctf-wiki Public

    Come and join us, we need you!

    Python 9.3k 1.4k