Hydra
Parallelized login cracker supporting 50+ protocols to audit password security.
External Tool
This open-source tool is maintained externally. View the source on GitHub to learn more or run it yourself.
Browse network tools →What's next with Hydra?
Choose how you want to get started.
Use it free
Open the official tool or demo — no account needed.
Self-host it
Run the open-source version on your own infrastructure.
What is Hydra?
Hydra is an open-source network authentication cracking tool designed to test the security of passwords by systematically attempting to guess credentials across various protocols. Developed under the AGPL-3.0 license, it is widely used by cybersecurity professionals, penetration testers, and ethical hackers to identify weak or compromised passwords in systems. The tool addresses the problem of password security vulnerabilities by simulating brute-force attacks against services like FTP, SSH, HTTP, and others. Its modular architecture allows for rapid adaptation to new protocols, making it a critical component in security assessments. Hydra’s popularity stems from its efficiency, flexibility, and extensive community support, with over 12,000 stars on GitHub reflecting its adoption in both academic and professional environments.
How it works
Hydra is a password-cracking tool that automates the process of testing authentication credentials against network services. It supports over 50 protocols, including FTP, Telnet, and SMB, enabling users to evaluate the strength of passwords in target systems. The tool is primarily used for penetration testing and security research to uncover misconfigured or weakly protected accounts. Its open-source nature allows customization for specific use cases, such as testing corporate networks or identifying vulnerabilities in legacy systems. Hydra can perform dictionary attacks, brute-force attacks, and combination attacks using custom wordlists. For example, it can test SSH credentials by iterating through a list of potential passwords, or exploit HTTP Basic Auth by guessing username-password pairs.
How to use it
- 1Install Hydra via package managers (e.g., `apt-get install hydra`) or compile from source using the provided Makefile. 2. Prepare a wordlist of potential passwords (e.g., `rockyou.txt`) and a target server list (e.g., `targets.txt`). 3. Run Hydra with the command `hydra -l username -p password_list target_protocol://target_ip`, specifying parameters like login credentials and protocol type. 4. Monitor the output for successful authentication attempts or errors. Practical tips: Use `-t` to limit simultaneous threads, `-u` to bypass username checks, and `-s` to specify a port. Always operate within legal boundaries and obtain explicit authorization before testing systems.
What it can do
- password brute force
Use cases
Assumptions and limitations
Assumptions
- source: https://github.com/vanhauser-thc/thc-hydra
- license: AGPL-3.0 — free to use
- privacy: Self-hosted — you control your data
Limitations
- Offensive tool — authorized penetration testing and lab use only; unauthorized use is illegal.
- Requires legal authorization to avoid violating laws like the Computer Fraud and Abuse Act
- High resource consumption for large-scale brute-force operations
- Limited support for modern encryption protocols like TLS 1.3
- Dependent on the quality and relevance of provided wordlists
Understanding the result
Parallelized login cracker supporting 50+ protocols to audit password security.
Tool details
- Clearly flagged when a network request is needed.
- No account, no sign-up, and no tracking of your content.
- Powered by (MIT).
- Built with
- (vanhauser-thc/thc-hydra)
- License
- MIT
- Runs locally
- No — requires a network request
- Verification
- Not yet verified
- Input
- Query
- Output
- Text
Built with vanhauser-thc/thc-hydra. OpenToolVault provides the discovery and browser interface while crediting the original project maintainers.
- Built with
- License
- MIT
Open-source project
OpenToolVault is an independent directory. We are not affiliated with or endorsed by this project.
References
- / — GitHub Repository
Upstream project · GitHub
- AGPL-3.0 License
Upstream project
Frequently asked
What protocols does Hydra support?
Hydra supports over 50 protocols including FTP, HTTP, SMB, Telnet, RDP, and Cisco Enable. It also includes modules for specialized services like Asterisk and VoIP. The tool’s extensibility allows for custom protocol plugins via its modular architecture.
How does Hydra handle distributed attacks?
Hydra’s Distributed (HDD) framework enables parallel attacks by splitting tasks across multiple machines. This is achieved through a master-slave architecture where the master node distributes password guesses to worker nodes, which then report results. This significantly reduces attack time for large password spaces.
How do I test SSH credentials with Hydra?
To test SSH credentials, use the command `hydra -l admin -p password ssh://192.168.1.1`. Replace `admin` with the target username, `password` with a password from your wordlist, and `192.168.1.1` with the SSH server IP. Hydra will attempt to log in using these credentials and report successes.
How does Hydra compare to other password-cracking tools like John the Ripper?
Hydra is network-focused and excels at testing credentials against remote services, while John the Ripper is designed for offline password cracking on stored hashes. Hydra’s modular architecture and support for multiple protocols make it ideal for penetration testing, whereas John the Ripper is better suited for analyzing local password files.
What should I do if Hydra gets blocked by the target server?
If the target server blocks your IP, use the `-S` flag to randomize the order of password attempts and avoid patterns. Additionally, employ proxy servers or rotate IP addresses to bypass rate-limiting mechanisms. Always ensure you have explicit permission to test the target system.