Hydra
In short: An open-source tool for brute-force and dictionary attacks on login procedures of various protocols (SSH, FTP, HTTP forms and many more) — used in a pentesting context to uncover weak passwords.
In more detail: Hydra systematically tries combinations of user names and passwords (from word lists or generated) against a login service until one works or all combinations are exhausted. Using it against systems without explicit permission is illegal — it’s used legitimately as part of authorised penetration tests to check whether systems are sufficiently protected against brute-force attacks (e.g. through rate limiting or account lockouts).
In Depth
A typical Hydra call against an SSH service (only for test purposes on your own/authorised systems):
hydra -l admin -P rockyou.txt ssh://192.168.1.10
# | | |
# | | +-- target protocol and host
# | +----------------- word list with password candidates
# +--------------------------- fixed user nameHydra supports dozens of protocols via modules (SSH, FTP, HTTP forms, RDP, MySQL, SMB and many more) and can make requests in parallel to speed up the test. There are two basic types of attack: dictionary attacks (try a list of known/common passwords, e.g. from leaked password databases) and pure brute-force attacks (systematically try ALL possible character combinations up to a certain length — takes practically forever with sufficiently long passwords).
From the defender’s point of view, Hydra shows exactly what you need to protect against: rate limiting (forcing a pause after N failed attempts), account lockouts after too many failed attempts, 2FA (even a guessed password is then no longer enough) and generally strong, long passwords that practically can’t be found in a reasonable time even by trying everything.
Legal framework
Using Hydra (like any pentesting tool) against other people’s systems without explicit, written permission is a criminal offence in Germany under § 202c StGB (“preparing to spy on and intercept data”) — this section is sometimes colloquially called the “hacker paragraph” and explicitly also covers merely possessing/distributing such tools for criminal purposes. For legal security research, a written “rules of engagement” contract with the system operator is therefore customary, specifying exactly which systems may be tested in which period with which methods, before any test even begins.
Word lists as the decisive factor
The effectiveness of a dictionary attack depends largely on the word list used. rockyou.txt — one of the best-known publicly available password word lists with over 14 million entries — comes from a real data leak: in 2009, the social gaming platform RockYou was hacked, and the attackers published millions of user passwords stored in plain text (an additional lesson in why passwords should never be stored in plain text, see Hashing). This real collection of passwords shows how predictable human password choice actually is — millions of users chose identical, trivial passwords such as “123456” or “password”.
Limits of brute-force tools in practice
Against well-secured modern systems, simply trying passwords with Hydra is often ineffective: even simple rate limiting (e.g. a maximum of 5 attempts per minute) makes even short word lists impractically slow, and 2FA makes a guessed password worthless on its own. In modern penetration tests, Hydra is therefore used less often against well-protected live systems and more often to explicitly VERIFY that protective measures such as rate limiting actually work as expected — over the years, the actual focus of offensive security research has shifted more towards phishing, social engineering and exploiting software vulnerabilities, because pure password guessing against well-configured systems is rarely the most efficient attack path any more.
See also: Nmap