No project description provided
Project description
PTUPLOADER - The Tool for testing uploads in web apps
Installation
pip install ptuploader
Adding to PATH
If you're unable to invoke the script from your terminal, it's likely because it's not included in your PATH. You can resolve this issue by executing the following commands, depending on the shell you're using:
For Bash Users
echo "export PATH=\"`python3 -m site --user-base`/bin:\$PATH\"" >> ~/.bashrc
source ~/.bashrc
For ZSH Users
echo "export PATH=\"`python3 -m site --user-base`/bin:\$PATH\"" >> ~/.zshrc
source ~/.zshrc
Usage examples
PTUPLOADER -u http://example.com/upload.php -r requestfile.txt -P file -s http://www.example.com/uploads/ -ts EXT
Options
-v --version Show script version and exit
-h --help Show this help message and exit
-j --json Output in JSON format
-vv --verbose Enable verbose mode
-ua --user-agent <user-agent> Set User-Agent header
-c --cookie <cookie> Set Cookie(s)
-t --threads <threads> Set thread count (default: 10)
-H --headers <header:value> Set custom header(s)
-p --proxy <proxy> Set Proxy
-u --url <url> Target upload URL
-f --file <filename> File to upload
-sz --size <size> Size of uploaded file
-n --number <number> Number of uploaded files
-e --extensions <extensions> Extensions of uploaded files
-l --language <language> Target language (PHP, ASP, JSP, NET, PY, JS)
-T --type <type> Upload type: MULTIPART (default, others in development)
-ct --content-type <mimetype> Content-Type of uploaded file (e.g. image/jpeg)
-r --request <request> Raw request file or base64 request (headers included)
-d --data <data> Custom request data
-P --parameter <parameter> Parameter to test (e.g. file, upload, POST param)
-s --storage <url_to_dir> URL to uploaded files directory
-w --wordlist <file> Custom wordlist file for storage path discovery
-sy --string-yes <string> Required string in response for success
-sn --string-no <string> Forbidden string in response for success
-ts --tests <test> Select test type:
ANTIVIR Detect antivirus presence
FINDSTORAGE Find uploaded file via dictionary attack
MAXSIZE Max file size limit
COUNT Max file count limit
EXT Allowed extensions (+ execution test)
CHARS Allowed filename characters
EXEC Execution bypass techniques
ADS Alternate Data Streams
TRAVERSAL Path traversal vulnerability
CONTENT File content validation
CT Content-Type validation
XXE XXE vulnerability
ZIPBOMB Zip bomb vulnerability
Dependencies
ptlibs
External tools
None at this moment.
License
Copyright (c) 2025 Penterep Security s.r.o.
ptuploader is free software: you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version.
ptuploader is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for more details.
You should have received a copy of the GNU General Public License along with ptuploader. If not, see https://www.gnu.org/licenses/.
Warning
You are only allowed to run the tool against the websites which you have been given permission to pentest. We do not accept any responsibility for any damage/harm that this application causes to your computer, or your network. Penterep is not responsible for any illegal or malicious use of this code. Be Ethical!
Project details
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file ptuploader-0.0.4.tar.gz.
File metadata
- Download URL: ptuploader-0.0.4.tar.gz
- Upload date:
- Size: 24.4 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.2.0 CPython/3.13.12
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
70d786de096d4a9105250dac1d051be42bd4d814db79174250976503e33edc3e
|
|
| MD5 |
34def3a1637604f31647f6a5bfba6e4b
|
|
| BLAKE2b-256 |
d626211a0fe36817b3887718789d5d8928f019340a325b5d4e5b4f7bfb12460a
|
File details
Details for the file ptuploader-0.0.4-py3-none-any.whl.
File metadata
- Download URL: ptuploader-0.0.4-py3-none-any.whl
- Upload date:
- Size: 25.9 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.2.0 CPython/3.13.12
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
207d625c6e5955bc87ce0124f8757abe92f488299e2621d9ac7e49276f20b411
|
|
| MD5 |
8111280492567ee23b2180d495dc7fcb
|
|
| BLAKE2b-256 |
159902a9beabfba3038ed7c2f4d1e709a512a55a286106da29f354ac7edf3e45
|