Password Attacks
Hydra
Online password brute-forcer for many network services.
Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.
Account lockouts can cause operational impact — respect RoE and rates.
When
Authorized credential testing against login services with lockout awareness.
How
Pick protocol module; supply user/pass lists; rate-limit; stop on success.
Why
Covers SSH, FTP, HTTP forms, RDP, etc. for lab auth testing.
Commands & usage
hydra -l admin -P rockyou.txt ssh://192.168.1.10
hydra -L users.txt -P passes.txt 192.168.1.10 http-post-form '/login:user=^USER^&pass=^PASS^:F=Invalid'
hydra -l admin -P passes.txt rdp://192.168.1.10
Commands are educational examples. Adapt hosts, paths, and rates to your authorized scope.
Comparisons
ATT&CK
Tags
Related in Password Attacks
Hashcat
GPU-accelerated password recovery tool supporting hundreds of hash types.
John the Ripper
CPU-focused password cracker with jumbo community builds.
Medusa
Parallel, modular online credential brute-forcing tool.
Crowbar
Brute force tool specializing in RDP, VPN, VNC key/password attacks.
CeWL
Custom wordlist generator from target website wording.
Crunch
Wordlist generator for charsets and patterns.