PT403BYPASS
Testing tool for identifying 401/403 bypass opportunities in web applications. It loads payload lists from templates/ (verbs, headers, IPs, user agents, path fuzz strings, extensions, default credentials, and other *.txt lists) and runs grouped tests similar in spirit to byp4xx, with Penterep-style output.
Bypass detection treats 401 and 403 as blocked responses (fixed in code). -s / -e only affect what is printed in the terminal, not which tests run.
Installation
pip install pt403bypass
Usage examples
pt403bypass -u https://example.com/admin
pt403bypass -u https://example.com/private -vv
pt403bypass -u https://example.com/secret -s 200 -m 500
pt403bypass -u https://example.com/secret -e 404
Without -s, only result lines whose HTTP status differs from the baseline are printed. -s 200 prints only lines (and the baseline URL line, if applicable) whose status is in the given list. -e 404 hides lines (and baseline) with those codes. -s and -e can be combined (must pass both filters). Use -vv / --verbose to print every line when -s is not set.
Options
-u --url Protected URL to test
-p --proxy Set proxy (e.g. http://127.0.0.1:8080)
-T --timeout Set timeout in seconds (default 10)
-c --cookie Set cookie
-a --user-agent Set User-Agent header
-H --headers Set custom header(s) as header:value
-r --redirects Follow redirects (default False)
-s --show-status Only print lines with these HTTP status codes (optional)
-e --hide-status Do not print lines with these HTTP status codes (e.g. hide 404)
-x --methods HTTP methods (default: templates/verbs.txt); merged with verbs.txt
-m --max-tests Limit number of payload tests (0 = unlimited)
-C --cache Cache compatibility flag (ptlibs)
-vv --verbose Enable verbose mode (show all result lines when -s is not set)
-v --version Show script version and exit
-h --help Show help and exit
-j --json Output in JSON format
--templates-dir Directory for *.txt templates (default: package templates/)
Path-heavy payloads (built-in paths, mid/end path lists, extensions, case tricks, extra tricks) are sent with ptlibs RawHttpClient when available so encoded paths are not normalized like requests/urllib3.
Dependencies
ptlibs
Warning
Run this tool only against systems you are explicitly authorized to test.
Metadata
Release files for pt403bypass 0.0.11
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| pt403bypass-0.0.11.tar.gz | 47.0 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| pt403bypass-0.0.11-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 94.6 kB
Release files / pt403bypass-0.0.11.tar.gz
| Download URL | pt403bypass-0.0.11.tar.gz |
|---|---|
| Size | 47.0 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
f0028ac5453a0124e95349f90cfae1505c94fa29b232d804e4c57d4aba943da8
|
|
BLAKE2b-256 checksum How to use checksums |
3289f80656b2bdbc3cc0badbf6fea71be999cdeb7f2a72d97cc0dd63f05876b5
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.13.15
|
Release files / pt403bypass-0.0.11-py3-none-any.whl
| Download URL | pt403bypass-0.0.11-py3-none-any.whl |
|---|---|
| Size | 47.6 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
f517b96e0b30d64adf35c0d7f5ce3e60fa7ae570f154bf4f920dd844bb04856b
|
|
BLAKE2b-256 checksum How to use checksums |
2751652d29b158043993ad72acde8a99da38537beef6cff355b9be9136dc2127
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.13.15
|