Hydra is a fast network login cracker that supports numerous attack protocols.

Basic Usage

Hydra’s basic syntax is

hydra [login_options] [password_options] [attack_options] [service_options]

Some important parameters:

ParameterExplanationUsage Example
-l LOGIN or -L FILELogin options: Specify either a single username (-l) or a file containing a list of usernames (-L).hydra -l admin ... or hydra -L usernames.txt ...
-p PASS or -P FILEPassword options: Provide either a single password (-p) or a file containing a list of passwords (-P).hydra -p password123 ... or hydra -P passwords.txt ...
-t TASKSTasks: Define the number of parallel tasks (threads) to run, potentially speeding up the attack.hydra -t 4 ...
-fFast mode: Stop the attack after the first successful login is found.hydra -f ...
-s PORTPort: Specify a non-default port for the target service.hydra -s 2222 ...
-v or -VVerbose output: Display detailed information about the attack’s progress, including attempts and results.hydra -v ... or hydra -V ... (for even more verbosity)
service://serverTarget: Specify the service (e.g., ssh, http, ftp) and the target server’s address or hostname.hydra ssh://192.168.1.100
/OPTService-specific options: Provide any additional options required by the target service.hydra http-get://example.com/login.php -m "POST:user=^USER^&pass=^PASS^" (for HTTP form-based authentication)

Hydra also supports targeting multiple SSH servers via the -M flag with arguments a text file of your targets.

Attacking Login Forms

Many web application employ custom login forms as their primary authentication mechanism. At their core, login forms are essentially HTLM forms embedded within a webpage, capturing username and password in an input field with a submit button.

Hydra’s http-post-form service is specifically designed to target login forms. It automates POST requests. Generally look like:

hydra [options] target http-post-form "path:params:condition_string"

Failure conditions (F=) define when a login attempts has failed, it just checks whether a specific string exsits in the server’s response. You can also specify a success condition (S=).

The params string consists of key-value pairs, similar to how data is encoded in a POST request. Each pair represents a field in the login form, with its corresponding value.

  • Form Parameters: These are the essential fields that hold the username and password. Hydra will dynamically replace placeholders (^USER^ and ^PASS^) within these parameters with values from your wordlists.
  • Additional Fields: If the form includes other hidden fields or tokens (e.g., CSRF tokens), they must also be included in the params string. These can have static values or dynamic placeholders if their values change with each request.
  • Success Condition: This defines the criteria Hydra will use to identify a successful login. It can be an HTTP status code (like S=302 for a redirect) or the presence or absence of specific text in the server’s response (e.g., F=Invalid credentials or S=Welcome).
/:username=^USER^&password=^PASS^:F=Invalid credentials

The most common default username for HTTP logins is admin, typically paired with passwords like admin, password, or a blank field.