Logo of «2Captcha»To home page
Captcha bypass tutorials

Was this helpful?

How to bypass POW Captcha on Filecrypt

Gregory Fisher
Gregory Fisher

Technical engineer

The Filecrypt website (filecrypt.cc) uses a specific Proof-of-Work (POW) captcha to protect download and container decryption processes. The main feature of this captcha is that providing only the page URL is not enough to solve it.

The system requires passing a unique link to a session JSON file (data_session), which is generated dynamically every time the captcha appears. In this guide, we will break down how to intercept this parameter, send the task via the API, and receive the token to bypass the protection.

Note: Currently, there is no official text documentation for this specific method. This guide is based on a working code example and analysis of the website's network traffic.

Task Parameters (API v1)

To send a task, the classic in.php method is used.

Parameter Type Required Description
key String Yes Your API key
method String Yes Must be set to pow_captcha
pageurl String Yes Full URL of the page where the captcha is located
data_session String Yes Unique URL to the captcha session JSON file (e.g., https://filecrypt.cc/captchasession/XXXX.json)
useragent String Yes Browser User-Agent. Must exactly match the one used in the request
proxy String No Proxy in LOGIN:PASS@IP:PORT format (if required)
proxytype String No Proxy type (HTTP, HTTPS, SOCKS4, SOCKS5)
json Integer No Set to 1 to get the response in JSON format

How to find parameters

The data_session parameter is dynamic and changes with every new download attempt. It must be intercepted from network traffic.

  1. Open the container or download page on https://filecrypt.cc in your browser.
  2. Press F12 to open Developer Tools (DevTools) and go to the Network tab.
  3. Enable Preserve log.
  4. Click the button that triggers the check (e.g., "Download", "Decrypt", or "Show Download Links").
  5. In the Network tab filter, type captchasession or .json.
  6. You will see a request to a file similar to https://filecrypt.cc/captchasession/DFE4FE0B68.json.
  7. Copy the full URL of this request. This is the value for the data_session parameter.
  8. Copy the main page URL from the address bar (this is pageurl) and your current User-Agent from the headers of any request.

Code Examples

Python + requests

Corrected and optimized example of sending a task and polling for the result based on the provided code. Note that trailing spaces in dictionary keys (like "method ") have been removed to prevent API errors.

python Copy
import os
import requests
import time

# It is recommended to store the key in environment variables
my_key = os.environ.get("APIKEY", "YOUR_DEFAULT_API_KEY")

API_URL = "https://api.2captcha.com/in.php"
API_RES_URL = "https://api.2captcha.com/res.php"

# Proxy is specified only if the site requires it
# proxy_target = "LOGIN:PASS@IP:PORT" 

data = {
    "method": "pow_captcha",
    "key": my_key,
    # "proxy": proxy_target,
    # "proxytype": "HTTP",
    "pageurl": "https://filecrypt.cc/Container/8CF37462DC.html",
    "useragent": "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/146.0.0.0 Safari/537.36",
    "data_session": "https://filecrypt.cc/captchasession/DFE4FE0B68.json",
    "json": 1
}

# Important: for the in.php method, it is safer to send data as form-data (data=data) 
# rather than json=data, as the v1 API expects application/x-www-form-urlencoded.
response = requests.post(API_URL, data=data)
result = response.json()

print("Response:", result)

if result.get("status") == 1:
    captcha_id = result['request']
    print(f"Task created, ID: {captcha_id}")
    
    # Initial delay before the first poll
    time.sleep(15)
    
    for i in range(10):
        time.sleep(2)
        check_data = {
            "id": captcha_id,
            "key": my_key,
            "action": "get",
            "json": 1
        }
        check_response = requests.get(API_RES_URL, params=check_data)
        check_result = check_response.json()
        
        print(f"Attempt {i + 1}: {check_result}")
        
        if check_result.get("status") == 1:
            print(f"Captcha solved! Token: {check_result['request']}")
            break
        elif "CAPCHA_NOT_READY" in str(check_result):
            continue
        else:
            print("Error getting result.")
            break
else:
    print(f"Task creation error: {result.get('request')}")

Python + Playwright (Automatic Interception)

This script automatically finds the data_session link when the button is clicked, sends the task, and receives the token.

python Copy
from playwright.sync_api import sync_playwright
import requests
import time
import os

API_KEY = os.environ.get("APIKEY", "YOUR_DEFAULT_API_KEY")
TARGET_URL = "https://filecrypt.cc/Container/8CF37462DC.html"

def solve_filecrypt_pow():
    with sync_playwright() as p:
        browser = p.chromium.launch(headless=False)
        page = browser.new_page()
        
        session_url = None

        # Intercept server responses to find the session JSON
        def handle_response(response):
            nonlocal session_url
            if "captchasession" in response.url and response.url.endswith(".json"):
                session_url = response.url

        page.on("response", handle_response)
        
        try:
            page.goto(TARGET_URL)
            
            # Action that triggers the captcha should go here
            # For example, clicking the download button. Update the selector as needed.
            # page.click("button:has-text('Download')")
            
            # Wait for the session URL to appear or timeout
            for _ in range(20):
                if session_url:
                    break
                time.sleep(1)
                
            if not session_url:
                raise Exception("Failed to intercept data_session. Check page actions.")
            
            print(f"Intercepted data_session: {session_url}")
            
            # Formulate API request
            api_url = "https://api.2captcha.com/in.php"
            payload = {
                "method": "pow_captcha",
                "key": API_KEY,
                "pageurl": page.url,
                "useragent": page.evaluate("navigator.userAgent"),
                "data_session": session_url,
                "json": 1
            }
            
            # Send task
            response = requests.post(api_url, data=payload).json()
            if response.get("status") != 1:
                raise Exception(f"Task creation error: {response.get('request')}")
                
            captcha_id = response['request']
            print(f"Task created, ID: {captcha_id}")
            
            # Wait for solution
            res_url = "https://api.2captcha.com/res.php"
            token = None
            for _ in range(15):
                time.sleep(3)
                check_params = {"id": captcha_id, "key": API_KEY, "action": "get", "json": 1}
                res = requests.get(res_url, params=check_params).json()
                
                if res.get("status") == 1:
                    token = res['request']
                    break
                if "CAPCHA_NOT_READY" not in str(res):
                    print(f"Error: {res}")
                    break
                    
            if token:
                print(f"Token received: {token}")
                # Note: The exact mechanism for applying the token depends on Filecrypt's internal logic.
                # Usually, it must be passed in the headers or body of the subsequent download request,
                # or a specific JS callback must be executed on the page.
            else:
                print("Failed to get token.")
                
        except Exception as e:
            print(f"Error: {e}")
        finally:
            # browser.close()

if __name__ == '__main__':
    solve_filecrypt_pow()

How to use the received token

Since official documentation on injecting this specific token is unavailable, based on the behavior of similar POW systems, the token is typically used in one of two ways:

  1. It must be added as a parameter or header to the next HTTP request for downloading/decrypting that you send after solving the captcha.
  2. In some cases, the site expects a specific JavaScript function to be executed with this token to unlock the interface. It is recommended to analyze the network traffic (Network tab) during a manual successful download to see exactly where this token is sent.

Common Errors and Solutions

Error / Problem Cause Solution
ERROR_WRONG_USER_KEY Invalid or empty API key. Check the APIKEY environment variable or specify the key directly.
ERROR_BAD_PARAMETERS Missing required parameter or typos. Ensure there are no trailing spaces in the dictionary keys (e.g., use "method" instead of "method ").
Session retrieval error The data_session link is outdated or incorrect. Intercept the link to the .json file anew for every new download attempt.
CAPCHA_NOT_READY (infinite) The captcha session expired before it was solved. Increase the speed between the captcha appearing and sending the request to the API.