{"id":27392419,"url":"https://github.com/byt3n33dl3/thc-hydra","last_synced_at":"2025-04-13T21:51:47.221Z","repository":{"id":257700653,"uuid":"852144866","full_name":"byt3n33dl3/thc-Hydra","owner":"byt3n33dl3","description":"Enterprise level of Parallelization SSH (Concurrency), Logon Penetration Testing.","archived":false,"fork":false,"pushed_at":"2024-11-22T06:49:51.000Z","size":4119,"stargazers_count":24,"open_issues_count":2,"forks_count":1,"subscribers_count":1,"default_branch":"master","last_synced_at":"2025-04-12T18:17:43.039Z","etag":null,"topics":["brute-force","cracking-password","logon","passwordcracking","session-manager","ssh-client"],"latest_commit_sha":null,"homepage":"https://www.kali.org","language":"C","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"agpl-3.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/byt3n33dl3.png","metadata":{"files":{"readme":"README.md","changelog":"CHANGES","contributing":null,"funding":".github/FUNDING.yml","license":"LICENSE.md","code_of_conduct":"CODE_OF_CONDUCT","threat_model":null,"audit":null,"citation":"CITATION.cff","codeowners":null,"security":"SECURITY.md","support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null},"funding":{"open_collective":"byt3n33dl3","custom":"s.id/byt3n33dl3","patreon":"byt3n33dl3","ko_fi":"byt3n33dl3"}},"created_at":"2024-09-04T09:52:49.000Z","updated_at":"2025-02-05T16:16:02.000Z","dependencies_parsed_at":"2024-09-18T06:33:29.013Z","dependency_job_id":"25c37768-b30f-4fbf-ad53-53652762e0a8","html_url":"https://github.com/byt3n33dl3/thc-Hydra","commit_stats":null,"previous_names":["byt3n33dl3/corphydra","byt3n33dl3/thc-hydra"],"tags_count":15,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/byt3n33dl3%2Fthc-Hydra","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/byt3n33dl3%2Fthc-Hydra/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/byt3n33dl3%2Fthc-Hydra/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/byt3n33dl3%2Fthc-Hydra/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/byt3n33dl3","download_url":"https://codeload.github.com/byt3n33dl3/thc-Hydra/tar.gz/refs/heads/master","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":248788856,"owners_count":21161726,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["brute-force","cracking-password","logon","passwordcracking","session-manager","ssh-client"],"created_at":"2025-04-13T21:51:46.399Z","updated_at":"2025-04-13T21:51:47.213Z","avatar_url":"https://github.com/byt3n33dl3.png","language":"C","funding_links":["https://opencollective.com/byt3n33dl3","s.id/byt3n33dl3","https://patreon.com/byt3n33dl3","https://ko-fi.com/byt3n33dl3"],"categories":[],"sub_categories":[],"readme":"\u003ca href=\"https://github.com/byt3n33dl3/thc-Hydra/\"\u003e\u003cp align=\"center\"\u003e\n\u003cimg width=\"250\" height=\"250\" src=\"/img/hydra-logo.svg\"\u003e\n\u003c/p\u003e\u003c/a\u003e\n\n\u003cdiv align=\"center\"\u003e\n\u003ch2\u003eH Y D R A\u003c/h2\u003e\n\u003cp\u003e\u003c/div\u003e\n\n(c) 2001-2024 by van Hauser / THC \u003cvh@thc.org\u003e \ncontinued by [byt3n33dl3@pm.me](mailto:byt3n33dl3@proton.me)\nmany modules were written by \u003cdavid.maciejak@gmail.com\u003e\nBFG code by Jan Dlabal \u003cdlabaljan@gmail.com\u003e and\nSulaiman Aziz [byt3n33dl3@pm.me](mailto:byt3n33dl3@proton.me)\n\nLicensed under `AGPLv3` and `BSD II` : see LICENSE file\n\nPlease do not use in military or secret service organizations,\nor for illegal purposes.\n(This is the wish of the author and non-binding. Many people working\nin these organizations do not care for laws and ethics anyways.\nYou are not one of the \"good\" ones if you ignore this.)\n\nNOTE: no this is not meant to be a markdown doc! old school!\n\n\nthc-Hydra in the most current github state can be directly downloaded via `Docker`:\n\n```docker\ndocker pull byt3n33dl3/thc-Hydra\n```\n\n\n# INTRODUCTION\n\nNumber one of the biggest security holes are passwords, as every password\nsecurity study shows.\nThis tool is a proof of concept code, to give researchers and security\nconsultants the possibility to show how easy it would be to gain unauthorized\naccess from remote to a system.\n\nTHIS TOOL IS FOR LEGAL PURPOSES ONLY!\n\nThere are already several login hacker tools available, however, none does\neither support more than one protocol to attack or support parallelized\nconnects.\n\nIt was tested to compile cleanly on Linux, Windows/Cygwin, Solaris,\nFreeBSD/OpenBSD, QNX (Blackberry 10) and MacOS.\n\nCurrently this tool supports the following protocols:\nAsterisk, AFP, Cisco AAA, Cisco auth, Cisco enable, CVS, Firebird, FTP,\nHTTP-FORM-GET, HTTP-FORM-POST, HTTP-GET, HTTP-HEAD, HTTP-POST, HTTP-PROXY,\nHTTPs-FORM-GET, HTTPs-FORM-POST, HTTPs-GET, HTTPs-HEAD, HTTPs-POST,\nHTTP-Proxy, ICQ, IMAP, IRC, LDAP, MEMCACHED, MONGODB, MS-SQL, MYSQL, NCP, NNTP, Oracle Listener,\nOracle SID, Oracle, PC-Anywhere, PCNFS, POP3, POSTGRES, Radmin, RDP, Rexec, Rlogin,\nRsh, RTSP, SAP/R3, SIP, SMB, SMTP, SMTP Enum, SNMP v1+v2+v3, SOCKS5,\nSSH (v1 and v2), SSHKEY, Subversion, Teamspeak (TS2), Telnet, VMware-Auth,\nVNC and XMPP.\n\nHowever the module engine for new services is very easy so it won't take a\nlong time until even more services are supported.\nYour help in writing, enhancing or fixing modules is highly appreciated!! :-)\n\n\n# WHERE TO GET\n\nYou can always find the newest release/production version of thc-Hydra at its\nproject page at [release](https://github.com/byt3n33dl3/thc-Hydra/releases)\nIf you are interested in the current development state, the public development\nrepository is at Github:\nsvn co [repo](https://github.com/byt3n33dl3/thc-Hydra)\nor\ngit clone [repo](https://github.com/byt3n33dl3/thc-Hydra)\nUse the development version at your own risk. It contains new features and\nnew bugs. Things might not work!\n\nAlternatively (and easier) to can pull it as a docker container:\n```\ndocker pull byt3n33dl3/thc-Hydra\n```\n\n\n## HOW TO COMPILE\n\nTo configure, compile and install thc-Hydra, just type:\n\n```docker\n./configure\nmake\nmake install\n```\n\nIf you want the ssh module, you have to setup libssh (not libssh2!) on your\nsystem,  get it from [libssh](https://www.libssh.org), for ssh v1 support you also need\nto add \"-DWITH_SSH1=On\" option in the cmake command line.\nIMPORTANT: If you compile on MacOS then you must do this - do not install libssh via brew!\n\nIf you use Ubuntu/Debian, this will install supplementary libraries needed\nfor a few optional modules (note that some might not be available on your distribution):\n\n```docker\napt-get install libssl-dev libssh-dev libidn11-dev libpcre3-dev \\\nlibgtk2.0-dev libmysqlclient-dev libpq-dev libsvn-dev \\\nfirebird-dev libmemcached-dev libgpg-error-dev \\\nlibgcrypt11-dev libgcrypt20-dev\n```\n\nThis enables all optional modules and features with the exception of Oracle,\nSAP R/3, NCP and the apple filing protocol - which you will need to download and\ninstall from the vendor's web sites.\n\nFor all other Linux derivates and BSD based systems, use the system\nsoftware installer and look for similarly named libraries like in the\ncommand above. In all other cases, you have to download all source libraries\nand compile them manually.\n\n\n\n## SUPPORTED \n\n- All UNIX platforms (Linux, BSD, Solaris, etc.)\n- MacOS (basically a BSD clone)\n- Windows with Cygwin (both IPv4 and IPv6)\n- Mobile systems based on Linux, MacOS or QNX (e.g. Android, iPhone, Blackberry 10, Zaurus, iPaq)\n\n```sh\n  _    ___     _______  _____            \n | |  | \\ \\   / /  __ \\|  __ \\     /\\    \n | |__| |\\ \\_/ /| |  | | |__) |   /  \\   \n |  __  | \\   / | |  | |  _  /   / /\\ \\  \n | |  | |  | |  | |__| | | \\ \\  / ____ \\ \n |_|  |_|  |_|  |_____/|_|  \\_\\/_/    \\_\\\n \n        L O G O N F O R C E R\n```\n\n## HOW TO `USE`\n\nIf you just enter `Hydra`, you will see a short summary of the important\noptions available.\nType `./Hydra -h` to see all available command line options.\n\nNote that NO login/password file is included. Generate them yourself.\nA default password list is however present, use \"dpl4Hydra.sh\" to generate\na list.\n\nFor Linux users, a GTK GUI is available, try `./xHydra`\n\nFor the command line usage, the syntax is as follows:\nFor attacking one target or a network, you can use the new \"://\" style:\nHydra [some command line options] PROTOCOL://TARGET:PORT/MODULE-OPTIONS\nThe old mode can be used for these too, and additionally if you want to\nspecify your targets from a text file, you *must* use this one:\n\n```\nHydra [some command line options] [-s PORT] TARGET PROTOCOL [MODULE-OPTIONS]\n```\n\nVia the command line options you specify which logins to try, which passwords,\nif SSL should be used, how many parallel tasks to use for attacking, etc.\n\nPROTOCOL is the protocol you want to use for attacking, e.g. ftp, smtp,\nhttp-get or many others are available\nTARGET is the target you want to attack\nMODULE-OPTIONS are optional values which are special per PROTOCOL module\n\nFIRST - select your target\nyou have three options on how to specify the target you want to attack:\n1. a single target on the command line: just put the IP or DNS address in\n2. a network range on the command line: CIDR specification like \"192.168.0.0/24\"\n3. a list of hosts in a text file: one line per entry (see below)\n\nSECOND - select your protocol\nTry to avoid telnet, as it is unreliable to detect a correct or false login attempt.\nUse a port scanner to see which protocols are enabled on the target.\n\nTHIRD - check if the module has optional parameters\nthc-Hydra -U PROTOCOL\ne.g. thc-Hydra -U smtp\n\nFOURTH - the destination port\nthis is optional, if no port is supplied the default common port for the\nPROTOCOL is used.\nIf you specify SSL to use (\"-S\" option), the SSL common port is used by default.\n\n\nIf you use \"://\" notation, you must use \"[\" \"]\" brackets if you want to supply\nIPv6 addresses or CIDR (\"192.168.0.0/24\") notations to attack:\nthc-Hydra [some command line options] ftp://[192.168.0.0/24]\nthc-Hydra [some command line options] -6 smtps://[2001:db8::1]/NTLM\n\nNote that everything thc-Hydra does is IPv4 only!\nIf you want to attack IPv6 addresses, you must add the \"-6\" command line option.\nAll attacks are then IPv6 only!\n\nIf you want to supply your targets via a text file, you can not use the ://\nnotation but use the old style and just supply the protocol (and module options):\nthc-Hydra [some command line options] -M targets.txt ftp\nYou can also supply the port for each target entry by adding \":\u003cport\u003e\" after a\ntarget entry in the file, e.g.:\n\n```\nfoo.bar.com\ntarget.com:21\nunusual.port.com:2121\ndefault.used.here.com\n127.0.0.1\n127.0.0.1:2121\n```\n\nNote that if you want to attach IPv6 targets, you must supply the -6 option\nand *must* put IPv6 addresses in brackets in the file(!) like this:\n\n```\nfoo.bar.com\ntarget.com:21\n[fe80::1%eth0]\n[2001::1]\n[2002::2]:8080\n[2a01:24a:133:0:00:123:ff:1a]\n```\n\n## LOGINS AND `PASSWORDS`\n\nYou have many options on how to attack with logins and passwords\nWith -l for login and -p for password you tell thc-Hydra that this is the only\nlogin and/or password to try.\nWith -L for logins and -P for passwords you supply text files with entries.\ne.g.:\n\n```\nHydra -l admin -p password ftp://localhost/\nHydra -L default_logins.txt -p test ftp://localhost/\nHydra -l admin -P common_passwords.txt ftp://localhost/\nHydra -L logins.txt -P passwords.txt ftp://localhost/\n```\n\nAdditionally, you can try passwords based on the login via the \"-e\" option.\nThe \"-e\" option has three parameters:\n\n```\ns - try the login as password\nn - try an empty password\nr - reverse the login and try it as password\n```\n\nIf you want to, e.g. try \"try login as password and \"empty password\", you \nspecify \"-e sn\" on the command line.\n\nBut there are two more modes for trying passwords than -p/-P:\nYou can use text file which where a login and password pair is separated by a colon,\ne.g.:\n\n```\nadmin:password\ntest:test\nfoo:bar\n```\n\nThis is a common default account style listing, that is also generated by the\ndpl4Hydra.sh default account file generator supplied with thc-Hydra.\nYou use such a text file with the -C option - note that in this mode you\ncan not use -l/-L/-p/-P options (-e nsr however you can).\nExample:\n\n```\nHydra -C default_accounts.txt ftp://localhost\n```\n\nAnd finally, there is a bruteforce mode with the -x option (which you can not\nuse with -p/-P/-C):\n\n```\n-x minimum_length:maximum_length:charset\n```\n\nthe charset definition is `a` for lowercase letters, `A` for uppercase letters,\n`1` for numbers and for anything else you supply it is their real representation.\nExamples:\n\n```\n-x 1:3:a generate passwords from length 1 to 3 with all lowercase letters\n-x 2:5:/ generate passwords from length 2 to 5 containing only slashes\n-x 5:8:A1 generate passwords from length 5 to 8 with uppercase and numbers\n-x '3:3:aA1\u0026~#\\\\ \"\\'\u003c{([-|_^@)]=}\u003e$%*?./§,;:!`' -v generates lenght 3 passwords with all 95 characters, and verbose. \n```\n\n# Example:\n\n```\nHydra -l ftp -x 3:3:a ftp://localhost/target\n```\n\n## OPTIONS FOR `MODULES`\n\nVia the third command line parameter (TARGET SERVICE OPTIONAL) or the -m\ncommand line option, you can pass one option to a module.\nMany modules use this, a few require it!\n\nTo see the special option of a module, type:\n\nHydra -U \u003cmodule\u003e\n\ne.g.\n\n./Hydra -U http-post-form\n\nThe special options can be passed via the -m parameter, as 3rd command line\noption or in the service://target/option format.\n\nExamples (they are all equal):\n\n```\n./Hydra -l test -p test -m PLAIN 127.0.0.1 imap\n./Hydra -l test -p test 127.0.0.1 imap PLAIN\n./Hydra -l test -p test imap://127.0.0.1/PLAIN\n```\n\n# ADDITIONAL HINTS\n\n* sort your password files by likelihood and use the -u option to find\npasswords much faster!\n* uniq your dictionary files! this can save you a lot of time :-)\ncat words.txt | sort | uniq \u003e dictionary.txt\n* if you know that the target is using a password policy (allowing users\nonly to choose a password with a minimum length of 6, containing a least one\nletter and one number, etc. use the tool pw-inspector which comes along\nwith the thc-Hydra package to reduce the password list:\ncat dictionary.txt | pw-inspector -m 6 -c 2 -n \u003e passlist.txt\n\n\n# OUTPUT / `Main`\n\n\nThe results are output to stdio along with the other information.  Via the -o\ncommand line option, the results can also be written to a file.  Using -b,\nthe format of the output can be specified.  Currently, these are supported:\n\n* `text`   - plain text format\n* `jsonv1` - JSON data using version 1.x of the schema (defined below).\n* `json`   - JSON data using the latest version of the schema, currently there\nis only version 1.\n\nIf using JSON output, the results file may not be valid JSON if there are\nserious errors in booting thc-Hydra.\n\n\nJSON Schema\n-----------\nHere is an example of the JSON output.  Notes on some of the fields:\n\n* `errormessages` - an array of zero or more strings that are normally printed\nto stderr at the end of the thc-Hydra's run.  The text is very free form.\n* `success` - indication if thc-Hydra ran correctly without error (**NOT** if\npasswords were detected).  This parameter is either the JSON value `true`\nor `false` depending on completion.  \n* `quantityfound` - How many username+password combinations discovered.\n* `jsonoutputversion` - Version of the schema, 1.00, 1.01, 1.11, 2.00,\n2.03, etc.  thc-Hydra will make second tuple of the version to always be two\ndigits to make it easier for downstream processors (as opposed to v1.1 vs\nv1.10).  The minor-level versions are additive, so 1.02 will contain more\nfields than version 1.00 and will be backward compatible.  Version 2.x will\nbreak something from version 1.x output.  \n\nVersion 1.00 example:\n```\n{\n\"errormessages\": [\n\"[ERROR] Error Message of Something\",\n\"[ERROR] Another Message\",\n\"These are very free form\"\n],\n\"generator\": {\n\"built\": \"2021-03-01 14:44:22\",\n\"commandline\": \"thc-Hydra -b jsonv1 -o results.json ... ...\",\n\"jsonoutputversion\": \"1.00\",\n\"server\": \"127.0.0.1\",\n\"service\": \"http-post-form\",\n\"software\": \"thc-Hydra\",\n\"version\": \"v9.6\"\n},\n\"quantityfound\": 2,\n\"results\": [\n{\n\"host\": \"127.0.0.1\",\n\"login\": \"bill@example.com\",\n\"password\": \"bill\",\n\"port\": 9999,\n\"service\": \"http-post-form\"\n},\n{\n\"host\": \"127.0.0.1\",\n\"login\": \"joe@example.com\",\n\"password\": \"joe\",\n\"port\": 4444,\n\"service\": \"http-post-form\"\n}\n],\n\"success\": false\n}\n```\n\n\n# SPEED\n\nthrough the parallelizing feature, this password cracker tool can be very\nfast, however it depends on the protocol. The fastest are generally POP3\nand FTP.\nExperiment with the task option (-t) to speed things up! The higher - the\nfaster ;-) (but too high - and it disables the service)\n\n\n\n# STATISTICS\n\nRun against a SuSE Linux 7.2 on localhost with a \"-C FILE\" containing\n295 entries (294 tries invalid logins, 1 valid). Every test was run three\ntimes (only for \"1 task\" just once), and the average noted down.\n\n```\nP A R A L L E L    T A S K S\nSERVICE\t1\t4\t8\t16\t32\t50\t64\t100\t128\n------- --------------------------------------------------------------------\ntelnet\t23:20\t5:58\t2:58\t1:34\t1:05\t0:33\t0:45*\t0:25*\t0:55*\nftp\t45:54\t11:51\t5:54\t3:06\t1:25\t0:58\t0:46\t0:29\t0:32\npop3\t92:10\t27:16\t13:56\t6:42\t2:55\t1:57\t1:24\t1:14\t0:50\nimap\t31:05\t7:41\t3:51\t1:58\t1:01\t0:39\t0:32\t0:25\t0:21\n```\n\n(*)\nNote: telnet timings can be VERY different for 64 to 128 tasks! e.g. with\n128 tasks, running four times resulted in timings between 28 and 97 seconds!\nThe reason for this is unknown...\n\nguesses per task (rounded up):\n\n295\t74\t38\t19\t10\t6\t5\t3\t3\n\nguesses possible per connect (depends on the server software and config):\n\ntelnet\t4\nftp\t6\npop3\t1\nimap\t3\n\n\n\n# BUGS \u0026 FEATURES\n\nthc-Hydra:\nEmail me or David or Sulaiman if you find bugs or if you have written a new module.\nvh@thc.org or [byt3n33dl3@pm.me](mailto:byt3n33dl3@proton.me) (and put \"antispam\" in the subject line)\n\n\nYou should use [PGP](https://github.com/byt3n33dl3/thc-Hydra/blob/master/vh-thc-key.md) to encrypt emails to \u003cvh@thc.org\u003e\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fbyt3n33dl3%2Fthc-hydra","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fbyt3n33dl3%2Fthc-hydra","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fbyt3n33dl3%2Fthc-hydra/lists"}