Medusa

Medusa is a fast, parallel login brute-forcer.

Follows the following syntax

medusa [target_options] [credential_options] -M module [module_options]

Some parameters include

ParameterExplanationUsage Example
-h HOST or -H FILETarget options: Specify either a single target hostname or IP address (-h) or a file containing a list of targets (-H).medusa -h 192.168.1.10 ... or medusa -H targets.txt ...
-u USERNAME or -U FILEUsername options: Provide either a single username (-u) or a file containing a list of usernames (-U).medusa -u admin ... or medusa -U usernames.txt ...
-p PASSWORD or -P FILEPassword options: Specify either a single password (-p) or a file containing a list of passwords (-P).medusa -p password123 ... or medusa -P passwords.txt ...
-M MODULEModule: Define the specific module to use for the attack (e.g., ssh, ftp, http).medusa -M ssh ...
-m "MODULE_OPTION"Module options: Provide additional parameters required by the chosen module, enclosed in quotes.medusa -M http -m "POST /login.php HTTP/1.1\r\nContent-Length: 30\r\nContent-Type: application/x-www-form-urlencoded\r\n\r\nusername=^USER^&password=^PASS^" ...
-t TASKSTasks: Define the number of parallel login attempts to run, potentially speeding up the attack.medusa -t 4 ...
-f or -FFast mode: Stop the attack after the first successful login is found, either on the current host (-f) or any host (-F).medusa -f ... or medusa -F ...
-n PORTPort: Specify a non-default port for the target service.medusa -n 2222 ...
-v LEVELVerbose output: Display detailed information about the attack’s progress. The higher the LEVEL (up to 6), the more verbose the output.medusa -v 4 ...