Skip to main content

Tactical Race Exploitation & Concurrency Orchestrator

Project description

TRECO

TRECO Logo

Tactical Race Exploitation & Concurrency Orchestrator

A specialized framework for identifying and exploiting race condition vulnerabilities in HTTP APIs with sub-microsecond precision.

Python 3.14t License: MIT Free-Threaded Documentation

Documentation | PyPI Package | Quick Start | Examples

Buy Me A Coffee GitHub Sponsor


🎯 Overview

TRECO enables security researchers to orchestrate highly precise concurrent HTTP attacks with sub-microsecond timing accuracy, making it possible to reliably trigger race conditions in web applications. Built for both Python 3.10+ (with GIL) and Python 3.14t (GIL-free), TRECO achieves unprecedented timing precision for race condition exploitation.

Common Vulnerabilities Tested

  • 💰 Double-spending attacks - Payment processing vulnerabilities
  • 🎁 Fund redemption exploits - Gift cards and coupon abuse
  • 📦 Inventory manipulation - Limited stock bypasses
  • 🔐 Privilege escalation - Authentication/authorization flaws
  • Rate limiting bypasses - API quota exhaustion
  • 🎟️ Voucher abuse - Single-use code reuse
  • 🏦 TOCTOU vulnerabilities - Time-of-Check to Time-of-Use exploits

✨ Key Features

  • ⚡ Sub-Microsecond Precision: Race windows < 1μs with barrier synchronization
  • 🔓 GIL-Free Option: Python 3.14t for true parallel execution
  • 🧵 Thread Groups: Define multiple request patterns with distinct thread counts and delays
  • 🔄 Flexible Synchronization: Barrier, countdown latch, and semaphore mechanisms
  • 🌐 Full HTTP/HTTPS Support: HTTP/1.1 and HTTP/2 with TLS/SSL
  • 🎨 Powerful Templates: Jinja2-based with TOTP, hashing, env vars, and more
  • 🎯 Dynamic Input Sources: Brute-force, enumeration, and combination attacks
  • 📊 Automatic Analysis: Race window calculation and vulnerability detection
  • 🔌 Extensible Architecture: Plugin-based extractors and connection strategies
  • ✅ JSON Schema Validation: IDE integration and real-time validation

📦 Quick Start

Installation

# Install from PyPI
pip install treco-framework

# Or with uv (faster)
uv pip install treco-framework

# Verify installation
treco --version

Your First Test

Create a file test.yaml:

metadata:
  name: "Race Condition Test"
  version: "1.0"
  author: "Security Researcher"
  vulnerability: "CWE-362"

target:
  host: "api.example.com"
  port: 443
  tls:
    enabled: true

entrypoint:
  state: race_attack
  input:
    voucher_code: "DISCOUNT50"

states:
  race_attack:
    description: "Test voucher race condition"
    race:
      threads: 20
      sync_mechanism: barrier
      connection_strategy: preconnect
    
    request: |
      POST /api/vouchers/redeem HTTP/1.1
      Host: {{ target.host }}
      Content-Type: application/json
      
      {"code": "{{ voucher_code }}"}
    
    next:
      - on_status: 200
        goto: end
  
  end:
    description: "Attack completed"

Run the test:

treco test.yaml

📖 Documentation

For detailed documentation, please visit treco.readthedocs.io:


💡 Examples

Check out the examples/ directory for real-world attack scenarios:


🚀 Why Python 3.14t?

Python 3.14t removes the Global Interpreter Lock (GIL) for true parallelism:

Feature Python 3.10-3.13 (GIL) Python 3.14t (GIL-Free)
True Parallelism ❌ Single thread at a time ✅ Multiple threads simultaneously
Race Window ~10-100μs < 1μs (sub-microsecond)
CPU Utilization Limited by GIL Full multi-core usage
Consistency Variable timing Highly consistent
Best for TRECO Good Excellent

Note: TRECO works with both Python 3.10+ and 3.14t, but achieves optimal performance with 3.14t's free-threaded build.

Install Python 3.14t:

uv python install 3.14t
uv pip install treco-framework --python 3.14t

🤝 Contributing

Contributions are welcome! Please see our Contributing Guide for details.

  1. Fork the repository
  2. Create your feature branch (git checkout -b feature/amazing-feature)
  3. Commit your changes (git commit -m 'feat: add amazing feature')
  4. Push to the branch (git push origin feature/amazing-feature)
  5. Open a Pull Request

💖 Support the Project

If you find TRECO useful, please consider supporting its development:

Buy Me A Coffee

GitHub Sponsor

Your support helps maintain and improve TRECO for the security research community.


📄 License

TRECO is released under the MIT License. See LICENSE for details.

Responsible Use

⚠️ AUTHORIZED TESTING ONLY ⚠️

TRECO is designed for authorized security testing. You must:

  • ✅ Obtain written authorization before testing
  • ✅ Test only within agreed scope and boundaries
  • ✅ Comply with all applicable laws and regulations
  • ✅ Report vulnerabilities responsibly

Unauthorized testing may result in criminal prosecution and civil liability.

Users are solely responsible for ensuring their use complies with applicable laws, regulations, and agreements.


🙏 Acknowledgments

  • TREM - The project that inspired TRECO
  • Python Community - For Python 3.14t free-threaded build
  • httpx, Jinja2, PyYAML, PyOTP - Essential libraries
  • Security Community - Researchers and contributors who make this possible

📞 Support


⚠️ USE RESPONSIBLY - AUTHORIZED TESTING ONLY ⚠️

Made with ❤️ by security researchers, for security researchers

⭐ Star on GitHub | 📖 Documentation | 🐛 Report Bug | 💡 Request Feature

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

treco_framework-1.10.0.tar.gz (1.5 MB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

treco_framework-1.10.0-py3-none-any.whl (107.9 kB view details)

Uploaded Python 3

File details

Details for the file treco_framework-1.10.0.tar.gz.

File metadata

  • Download URL: treco_framework-1.10.0.tar.gz
  • Upload date:
  • Size: 1.5 MB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.1.0 CPython/3.13.7

File hashes

Hashes for treco_framework-1.10.0.tar.gz
Algorithm Hash digest
SHA256 a7817b24eb3b6ae01c388ac49c186db92138d31e3e2947de63b754cbd76bfc64
MD5 c30133981e2290ae77577ee2c7406399
BLAKE2b-256 a1d7efe12bcf9a9012cd16b9d43d0f37c565493c9e20570fe2af6cc82f3b0dbd

See more details on using hashes here.

File details

Details for the file treco_framework-1.10.0-py3-none-any.whl.

File metadata

File hashes

Hashes for treco_framework-1.10.0-py3-none-any.whl
Algorithm Hash digest
SHA256 34b2d66b34d8ebe31d59befaba101792a1862d85a6076ed4cb80c628b64bbae3
MD5 1616f5d09e5013cfc5ea427e7da97d65
BLAKE2b-256 267853e236171da9da731b419f259827823b29c68bb49fb61fdcd0cbff3a504b

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page