Skip to main content

penterepTools

PTWEBDISCOVER - Web Source Discovery Tool

Installation

pip install ptwebdiscover

Adding to PATH

If you're unable to invoke the script from your terminal, it's likely because it's not included in your PATH. You can resolve this issue by executing the following commands, depending on the shell you're using:

For Bash Users

echo "export PATH=\"`python3 -m site --user-base`/bin:\$PATH\"" >> ~/.bashrc
source ~/.bashrc

For ZSH Users

echo "export PATH=\"`python3 -m site --user-base`/bin:\$PATH\"" >> ~/.zshrc
source ~/.zshrc

Usage examples

ptwebdiscover -u https://www.example.com -src robots.txt sitemap.xml -scy 200
ptwebdiscover -u https://www.example.com -bf -ch lowercase,numbers,123abcdEFG*
ptwebdiscover -u https://www.example.com -bf -lx 4
ptwebdiscover -u https://www.example.com -w
ptwebdiscover -u https://www.example.com -w wordlist.txt
ptwebdiscover -u https://www.example.com -w wordlist.txt --begin_with admin
ptwebdiscover -u https://*.example.com -w wordlist.txt
ptwebdiscover -u https://www.example.com -Po -tr
ptwebdiscover -u https://www.example.com/exam*.txt
ptwebdiscover -u https://www.example.com -bf -e "" bak old php~ php.bak
ptwebdiscover -u https://www.example.com -w wordlist.txt-E extensions.txt"
ptwebdiscover -u https://www.example.com -w wordlist.txt -sn "Page Not Found"
ptwebdiscover -u https://www.example.com -arch checked
ptwebdiscover -u https://www.example.com -ba
ptwebdiscover -u https://www.example.com -sm

Options

-bf      --bruteforce                              Enable brute force mode
-u       --url                    <url>            URL for test (usage of a star character as anchor)
-ch      --charsets               <charsets>       Specify charset for brute force (example: lowercase,uppercase,numbers,[custom_chars])
                                                   Modify wordlist (lowercase,uppercase,capitalize)
-scy     --status-code-yes        <status codes>   Include only sources returned with provided status codes
-scn     --status-code-no         <status codes>   Not include sources returned with provided status codes
-src     --source                 <sources>        Check for presence of only specified <source> (eg. -src robots.txt)
-fp      --forbidden-paths        <paths>          Paths that should not be tested
-lm      --length-min             <length-min>     Minimal length of brute-force tested string (default 1)
-lx      --length-max             <length-max>     Maximal length of brute-force tested string (default 6 bf / 99 wl)
-w       --wordlist               <filename>       Use specified wordlist(s)
-pf      --prefix                 <string>         Use prefix before tested string
-sf      --suffix                 <string>         Use suffix after tested string
-bw      --begin-with             <string>         Use only words from wordlist that begin with the specified string
-ci      --case-insensitive                        Case insensitive items from wordlist
-e       --extensions             <extensions>     Add extensions behind a tested string (\"\" for empty extension)
-E       --extension-file         <filename>       Add extensions from default or specified file behind a tested string.
-ew      --extensions-whitelist   <extensions>     Check for extensions whitelisting on the server (default are common backup and config extensions)
-eo      --extensions-output      <extensions>     Include only sources with specified extensions in output
-r       --recurse                                 Recursive browsing of found directories
-md      --max_depth              <integer>        Maximum depth during recursive browsing (default: 20)
-b       --backups                                 Search for backups of disclosed files
-ba      --backup-all                              Search for backups of the website or db
-P       --parse                                   Parse HTML response for URLs discovery
-Po      --parse-only                              Brute force method is disabled, crawling started on specified url
-D       --directory                               Add a slash at the ends of the strings too
-nd      --not-directories        <directories>    Not include listed directories when recursive browse run
-sy      --string-in-response     <string>         Print findings only if string in response (GET method is used)
-sn      --string-not-in-response <string>         Print findings only if string not in response (GET method is used)
-d       --delay                  <miliseconds>    Delay before each request in seconds
-T       --timeout                <miliseconds>    Manually set timeout (default 10000)
-cl      --content-length         <kilobytes>      Max content length to download and parse (default: 1000KB)
-m       --method                 <method>         Use said HTTP method (default: HEAD)
-se      --scheme                 <scheme>         Use scheme when missing (default: http)
-p       --proxy                  <proxy>          Use proxy (e.g. http://127.0.0.1:8080)
-H       --headers                <headers>        Use custom headers
-a       --user-agent             <agent>          Use custom value of User-Agent header
-c       --cookie                 <cookies>        Use cookie (-c \"PHPSESSID=abc; any=123\")
-A       --auth                   <name:pass>      Use HTTP authentication
-rc      --refuse-cookies                          Do not use cookies set by application
-t       --threads                <threads>        Number of threads (default 20)
-wd      --without-domain                          Output of discovered sources without domain
-wh      --with-headers                            Output of discovered sources with headers
-ip      --include-parameters                      Include GET parameters and anchors to output
-fd      --foreign-domains                         Output of discovered sources with foreign domains
-tr      --tree                                    Output as tree
-o       --output                 <filename>       Output to file
-S       --save                   <directory>      Save content localy
-tg      --target                 <ip or host>     Use this target when * is in domain
-nr      --not-redirect                            Do not follow redirects
-s       --silent                                  Do not show statistics in realtime
-C       --cache                                   Cache each request response to temp file
-ne      --non-exist                               Check, if non existing pages return status code 200
-vy      --vuln-yes               <vuln_code>      Add provided VULN to JSON if source is found
-vn      --vuln-no                <vuln_code>      Add provided VULN to JSON if source is not found
-er      --errors                                  Show all errors
-v       --version                                 Show script version
-h       --help                                    Show this help message
-j       --json                                    Output in JSON format
-gl      --google                                  Use Google Custom Search API for URL discovery
-gak     --google-api             <api_key>        Google Custom Search API key
-gcx     --google-cx              <cx_key>         Google Custom Search CX key
-sm      --sitemap                                 Parse sitemap.xml for URL discovery
-arch    --archive                [checked]        Passive scan via webarchive, accepts optional arguments: (checked)

Dependencies

ptlibs
bs4
treelib

License

Copyright (c) 2025 Penterep Security s.r.o.

ptwebdiscover is free software: you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version.

ptwebdiscover is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for more details.

You should have received a copy of the GNU General Public License along with ptwebdiscover. If not, see https://www.gnu.org/licenses/.

Warning

You are only allowed to run the tool against the websites which you have been given permission to pentest. We do not accept any responsibility for any damage/harm that this application causes to your computer, or your network. Penterep is not responsible for any illegal or malicious use of this code. Be Ethical!

Metadata

Release files for ptwebdiscover 1.1.8

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for ptwebdiscover 1.1.8
File Size Uploaded
ptwebdiscover-1.1.8.tar.gz 51.0 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for ptwebdiscover 1.1.8
File Interpreter ABI Platform
ptwebdiscover-1.1.8-py3-none-any.whl Python 3 none any Details

Total release size: 105.8 kB

Release files / ptwebdiscover-1.1.8.tar.gz

Download URL ptwebdiscover-1.1.8.tar.gz
Size 51.0 kB
Tags Source
SHA-256 checksum
How to use checksums
0a0b2af180ecb111f0acc73ab18006eed7486f7ad4beb9b5d136c74b10ac6a0f
BLAKE2b-256 checksum
How to use checksums
321c47acd638907cb9a1c15f94bfd611974d0913ad471e6e48898c2da3f8c3ec
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.15

Release files / ptwebdiscover-1.1.8-py3-none-any.whl

Download URL ptwebdiscover-1.1.8-py3-none-any.whl
Size 54.8 kB
Tags Python 3
SHA-256 checksum
How to use checksums
7f90db93ad29add90edb9951a53919fae276bfb8206acaca87995002a919934c
BLAKE2b-256 checksum
How to use checksums
0961afb2cecc32d5fa59ef61ce066d81ea46cafac20a01a2dbba9ce23caa45d3
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.15

Release history Release notifications | RSS feed

This release

1.1.8 This release

2 release files

1.1.7

2 release files

1.1.6

2 release files

1.1.5

2 release files

1.1.4

2 release files

1.1.3

2 release files

1.1.2

2 release files

1.1.1

2 release files

1.1.0

2 release files

1.0.21

2 release files

1.0.20

2 release files

1.0.19

2 release files

1.0.18

2 release files

1.0.17

2 release files

1.0.16

2 release files

1.0.15

2 release files

1.0.14

2 release files

1.0.13

2 release files

1.0.10

2 release files

1.0.9

2 release files

1.0.8

2 release files

1.0.7

2 release files

1.0.6

2 release files

1.0.5

2 release files

1.0.4

2 release files

1.0.3

2 release files

1.0.2

2 release files

1.0.1

2 release files

1.0.0

2 release files

0.0.5

2 release files

0.0.4

1 release file

0.0.3

1 release file

0.0.1

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page