Skip to main content

penterepTools

PTACCOUNT

Testing tool for web application account/login security.

Installation

pip install ptaccount

Adding to PATH

If you're unable to invoke the script from your terminal, it's likely because it's not included in your PATH. You can resolve this issue by executing the following commands, depending on the shell you're using:

For Bash Users

echo "export PATH=\"`python3 -m site --user-base`/bin:\$PATH\"" >> ~/.bashrc
source ~/.bashrc

For ZSH Users

echo "export PATH=\"`python3 -m site --user-base`/bin:\$PATH\"" >> ~/.zshrc
source ~/.zshrc

Usage examples

ptaccount --login-file login_workflow.json --login bob --password Secret123
ptaccount --login-file login_workflow.json --login bob --password Secret123 -ts LGENUM -wl logins.txt

The login request is described by --login-file, a JSON array of steps (a file path, or the JSON itself base64-encoded). Each step sends a raw HTTP request - with {{login}}/{{password}} (and any value extracted by an earlier step) substituted in - and pulls values out of the response via named regexes; a plain match-only pattern acts as a presence check. A workflow with more than one step lets you describe a CSRF-token fetch, a 2FA step, etc. before the request that actually submits the credentials.

A single-request login:

[
  {
    "action": "send_request",
    "schema": "https",
    "content": "POST /user/login.php HTTP/1.1\r\nHost: www.example.com\r\nContent-Type: application/x-www-form-urlencoded\r\n\r\nlogin={{login}}&heslo={{password}}",
    "regex": {
      "sid": "PHPSESSID=([^;]+)",
      "fail": "Přihlášení se nezdařilo"
    }
  }
]

A login preceded by a CSRF-token fetch:

[
  {
    "action": "send_request",
    "schema": "https",
    "content": "GET / HTTP/1.1\r\nHost: www.example.com\r\n\r\n",
    "regex": {"csrf": "csrftoken=([^;]+)"}
  },
  {
    "action": "send_request",
    "schema": "https",
    "content": "POST /user/login.php HTTP/1.1\r\nHost: www.example.com\r\nContent-Type: application/x-www-form-urlencoded\r\n\r\nlogin={{login}}&heslo={{password}}&csrftoken={{csrf}}",
    "regex": {
      "sid": "PHPSESSID=([^;]+)",
      "fail": "Přihlášení se nezdařilo"
    }
  }
]

The last step's regex must extract a variable named success or fail for LGPWCASE, LGREFLEXPW, LGSESSFIX and LGMETHODS, so ptaccount can tell a successful login from a failed one.

--register-file takes the same shape for a future registration-testing workflow; no test uses it yet.

Options

        --login-file        <file|base64>     JSON workflow describing how to submit the login request (required)
        --register-file     <file|base64>     JSON workflow describing how to submit a registration request
   -ts  --tests             <test>            Specify one or more tests to perform:
                             LGENUM            Test for login user enumeration
                             LGPWCASE          Test login password case sensitivity
                             LGREFLEXPW        Test whether login reflects submitted password

   -wl  --wordlist-login    <file>            Login wordlist file
   -wp  --wordlist-passwords <file>           Password wordlist file
        --login             <login>           Known-valid login
        --password          <password>        Known-valid password for --login
        --invalid-login     <login>           A login known not to exist (default: random)
        --invalid-password  <password>        A wrong password to use where a real one isn't needed (default: random)
   -p   --proxy             <proxy>           Set proxy (e.g. http://127.0.0.1:8080)
   -T   --timeout                             Set timeout (default 10)
   -t   --threads           <threads>         Set thread count for LGENUM wordlist mode (default 10)
   -r   --redirects                           Follow redirects (default False)
   -C   --cache                               Cache HTTP communication
   -vv  --verbose                             Enable verbose mode
   -v   --version                             Show script version and exit
   -h   --help                                Show this help message and exit
   -j   --json                                Output in JSON format

Tests

LGPWCASE     Sends the known-valid login with case-altered variants of the known-valid
             password (UPPER/lower/sWAP) and flags the login as vulnerable if the server
             still accepts any of them - i.e. password comparison is not case sensitive.

LGREFLEXPW   Sends three login requests (correct credentials, wrong login, wrong password)
             and checks whether the submitted password value is echoed back in the response.

LGENUM       Compares the login response for a known-existing login against a known-nonexistent
             login (status code, response content similarity, response time). If they differ,
             the app is vulnerable to user enumeration. Adding -wl/--wordlist-login enumerates every
             login in the wordlist against the two learned response signatures and returns the
             list of logins that appear to exist.

Dependencies

ptlibs

License

Copyright (c) 2026 Penterep Security s.r.o.

ptaccount is free software: you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version.

ptaccount is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for more details.

You should have received a copy of the GNU General Public License along with ptaccount. If not, see https://www.gnu.org/licenses/.

Warning

You are only allowed to run the tool against the websites which you have been given permission to pentest. We do not accept any responsibility for any damage/harm that this application causes to your computer, or your network. Penterep is not responsible for any illegal or malicious use of this code. Be Ethical!

Metadata

Release files for ptaccount 0.0.4

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for ptaccount 0.0.4
File Size Uploaded
ptaccount-0.0.4.tar.gz 33.6 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for ptaccount 0.0.4
File Interpreter ABI Platform
ptaccount-0.0.4-py3-none-any.whl Python 3 none any Details

Total release size: 71.8 kB

Release files / ptaccount-0.0.4.tar.gz

Download URL ptaccount-0.0.4.tar.gz
Size 33.6 kB
Tags Source
SHA-256 checksum
How to use checksums
cca04e866daaacbbf182b182bd499513fda7ca117b17d454d43f9d4df6aaa026
BLAKE2b-256 checksum
How to use checksums
74a7747ff2352df7e9c886295fc13c8fddcdb87c1fc6c09f7e4102ef4c0aed0a
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.15

Release files / ptaccount-0.0.4-py3-none-any.whl

Download URL ptaccount-0.0.4-py3-none-any.whl
Size 38.2 kB
Tags Python 3
SHA-256 checksum
How to use checksums
d8134bfe49f6982261de62b1ae87a724d0bfe1ed678af38b049bc6c99e970706
BLAKE2b-256 checksum
How to use checksums
b333268390d254ec2a77e118ac3bd2c18c0096ab3480b3e49d01392e01fa7b89
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.15

Release history Release notifications | RSS feed

This release

0.0.4 This release

2 release files

0.0.3

2 release files

0.0.2

2 release files

0.0.1

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page