Skip to content

Hydra

Parallelised login attempt tester for authorized audits

Needs reviewPentesting· Credential & Hash AuditingIntermediateOpen sourceEntry revised 19 Dec 2025
  • Linux
  • macOS
  • Windows
  • Kali
  • Parrot
  • Arch
  • Fedora
  • Source

Needs review. May lag the current upstream release. Verify before relying on it. Cross-check against the upstream documentation before relying on a command.

This entry is thinner than the rest of the directory — missing sections are shown as such rather than filled with filler.Improve this pageContribute

Overview

4 commands documented

Hydra automates credential testing against many service types (SSH, FTP, HTTP form, RDP, SMB, SMTP auth) so an organisation can measure whether weak or default passwords are actually in use on its own systems.

This is the category of tool that most easily crosses a legal line. Run it only with written authorization, inside an agreed window, against test or clearly identified accounts, with lockout policy understood in advance.

Supported platforms

8

Documented install or usage guidance

Learning curve

intermediate

Difficulty of becoming productive, not of the underlying theory

Tags

authentication, audit, policy, lockout

Dataset entry

hydra.ts

Reviewed 2025-12-19

Installation

Grouped by platform. Elevation requirements are marked per method.

Homebrew

RecommendedHomebrew
brew install hydra

Package availability follows your distribution and enabled repositories. Entry revised 19 Dec 2025 — confirm the current release on the project's own download page.

Commands

4 entries

Every command carries its purpose, an example where useful, and the limitations that change how you should read the output.

01Test a known account against an HTTP login form

bash

Uses a POST template with the username and password placeholders that Hydra substitutes.

hydra -l testuser -P lab-wordlist.txt 192.0.2.20 http-post-form '/login:user=^USER^&pass=^PASS^:F=invalid'
  • Repeated failed logins will lock accounts and page the SOC. Agree the account, window and rate with the system owner first.

Notes

  • `F=` marks the failure string; without a precise failure condition results are meaningless.

02SSH policy check with a tiny list

bash

Measures whether an SSH account accepts a password from a short list of known-weak candidates.

hydra -l svc_backup -P weak-own-lab.txt ssh://192.0.2.30 -t 4 -f

Notes

  • `-f` stops at the first success; `-t` is tasks in parallel. Keep it at 4 or below against anything real.

03Resume an interrupted run

bash

Writes a restore file so a long audit can continue after a restart.

hydra -R /tmp/lab.restore

Notes

  • Restore files contain target, list paths and progress. Treat them as engagement material.

04List supported service modules

bash

Service syntax differs per module; the usage dump is the reference for your build.

hydra -h | less

Common errors

Symptoms you will actually hit, with the cause and the legitimate fix.

"[ERROR] Module not found" or confusing usage outputCause 1/3

Possible causes

  • Module names differ between releases and some builds omit optional modules (RDP, Oracle, SAP).

Usual fix

Check the module list in `hydra -h`, and re-configure the build with the needed libraries if you must have them.

Every attempt reported as 'correct login'Cause 2/3

Possible causes

  • The failure string does not match what the application returns.

Usual fix

Send one bad login manually, copy the exact error text, and use it as `F=` — or invert with `S=` on a success string.

Accounts locked, helpdesk tickets, incident openedCause 3/3

Possible causes

  • Lockout policy is stricter than the run assumed.

Usual fix

Stop immediately, notify the system owner, and record the impact. Future runs need an agreed rate and a service account that is exempt from lockout.

Tips

  • Prefer an offline hash test with hashcat over online guessing where you have that option: it does not touch the identity provider.
  • Keep the list small and targeted; a 300-line 'company + season + year' list beats a million-line dump for policy evidence.
  • Log start/end times and the exact command for the engagement record.

Alternatives & comparisons

Not documented yet: medusa. Request an entry and it will link up automatically.Request a tool

Side-by-side

References

Where to verify anything on this page. External links open in a new tab.

Found something wrong?Suggest an editMore in Pentesting

Looking for alternatives?

Hashcat cover adjacent parts of the same job.

Compare side by side