According to Kali, THC-Hydra Tool is a parallelized login cracker that supports numerous protocols to attack. It is very fast and flexible, and new modules are easy to add.
This Tool makes it possible for researchers and security consultants to show how easy it would be to gain unauthorized access to a system remotely.
It supports: Cisco AAA, Cisco auth, Cisco enable, CVS, FTP, HTTP(S)-FORM-GET, HTTP(S)-FORM-POST, HTTP(S)-GET, HTTP(S)-HEAD, HTTP-Proxy, ICQ, IMAP, IRC, LDAP, MS-SQL, MySQL, NNTP, Oracle Listener, Oracle SID, PC-Anywhere, PC-NFS, POP3, PostgreSQL, RDP, Rexec, Rlogin, Rsh, SIP, SMB(NT), SMTP, SMTP Enum, SNMP v1+v2+v3, SOCKS5, SSH (v1 and v2), SSHKEY, Subversion, Teamspeak (TS2), Telnet, VMware-Auth, VNC and XMPP.Also Read : Offline Password Cracking with John the Ripper – Tutorial
Find the Hydra from Kali by searching xHydra.
Here we are setting our Target IP “192.268.0.103”(set your Remote Target) In the Target area.
we are using SSH authentication for communicating to remote Target “192.268.0.103”
Target: “192.268.0.103” Protocol : SSHBottom of the tool we can see the command line which automatically Create when we set out settings in the GUI of THC-Hydra
we Perform a wordlist attack by using a wordlist containing the most common passwords to break into the root account. you can add an “n” number of passwords to your word list.
In the Passwords area, we set our username as “root” and specified our wordlist.txt location in the password list box(/root/password/txt).
Kali Linux comes with built-in word lists.
Search them using the command: locate *.lst in the terminal.
command: locate *.lst
In the Tuning area, we set the number of tasks that we are going to perform.
I set 1 task for the Attack.
you can set the proxy as No Proxy.
we can go ahead and trigger the start attachment by Clicking the start button.
you can see clearly the terminal command line at the bottom of the tool which is about the target IP, a protocol that we used, and wordlist of dictionary list (password.txt)
Finally, e have got the result about our target system login ID and password
Cybersecurity researcher "0xdf" has cracked the "Ghost" challenge on Hack The Box (HTB), a premier…
Google has unveiled Sec-Gemini v1, an AI model designed to redefine cybersecurity operations by empowering…
The United States has successfully extradited two Kosovo nationals, Ardit Kutleshi, 26, and Jetmir Kutleshi,…
Ivanti has issued an urgent security advisory for CVE-2025-22457, a critical vulnerability impacting Ivanti Connect…
A concerning malware campaign was disclosed by the AhnLab Security Intelligence Center (ASEC), revealing how…
EncryptHub, a rapidly evolving cybercriminal entity, has come under intense scrutiny following revelations of operational…