Skip to main content

penterepTools

PTMULTIREQUEST

ptmultirequest sends two or more identical HTTP requests at the exact same moment to help identify race condition vulnerabilities.

Use cases

  • Can a user make two payments simultaneously when balance allows only one?
  • Can two accounts be registered with the same login at the exact same time?

How it works

All requests are dispatched in parallel threads synchronized by a barrier — every thread waits until all are ready, then fires at once.

Responses are compared across all requests:

Field What is checked
Status code Are all responses the same HTTP status?
Response length Does content length differ between responses?
Page title Does the HTML <title> differ?
Keywords Are error, warning, notice, or sql present in any response?

Any difference may indicate a race condition — manual review is always recommended.

Installation

pip install ptmultirequest

Usage

ptmultirequest -u https://example.com/pay -c 2
ptmultirequest -u https://example.com/register -d "login=admin" -c 2
ptmultirequest --request-file ./request.txt -c 5

Options

Flag Description
-u, --url <url> Target URL
-d, --data <post-data> POST body (switches method to POST)
--request-file <file|base64> Raw HTTP request from file or base64
-c, --count <n> Number of synchronized requests (default: 2)
-p, --proxy <proxy> Proxy URL (e.g. http://127.0.0.1:8080)
-T, --timeout <seconds> Request timeout (default: 10)
--cookie <cookie> Cookie header
-a, --user-agent <agent> User-Agent header
-H, --headers <header:value> Additional custom headers
-r, --redirects Follow redirects
-j, --json Output results as JSON
-v, --version Show version
-h, --help Show help

Dependencies

License

Copyright (c) 2026 Penterep Security s.r.o.

ptmultirequest is free software licensed under the GNU General Public License v3.0 or later.

Legal notice

Only run this tool against targets you are explicitly authorized to test. Penterep bears no responsibility for unauthorized or malicious use. Be ethical.

Metadata

Release files for ptmultirequest 0.0.3

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for ptmultirequest 0.0.3
File Size Uploaded
ptmultirequest-0.0.3.tar.gz 20.1 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for ptmultirequest 0.0.3
File Interpreter ABI Platform
ptmultirequest-0.0.3-py3-none-any.whl Python 3 none any Details

Total release size: 40.7 kB

Release files / ptmultirequest-0.0.3.tar.gz

Download URL ptmultirequest-0.0.3.tar.gz
Size 20.1 kB
Tags Source
SHA-256 checksum
How to use checksums
87dbcf91e2e6d1bfa330a0d3e3ad87644946fc05d98659cf68d6421a3967565f
BLAKE2b-256 checksum
How to use checksums
01f035a50bca67c2bc87b04b04c4e28abb9ce04c2ea24bfebd8febadbd65f729
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.15

Release files / ptmultirequest-0.0.3-py3-none-any.whl

Download URL ptmultirequest-0.0.3-py3-none-any.whl
Size 20.6 kB
Tags Python 3
SHA-256 checksum
How to use checksums
48b96a2a7b8b6f0a41cbc63526da86c1f7e88e6a6b10322e117e12bf246f55fa
BLAKE2b-256 checksum
How to use checksums
f33bdc41790a49f1add13fe04b813d234f47691f6eded7195d7faa1f74abfd3c
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.15

Release history Release notifications | RSS feed

This release

0.0.3 This release

2 release files

0.0.2

2 release files

0.0.1

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page