Command library / hydra
hydra
Online password-guessing tool for authorised tests
Hydra tries many logins and passwords against a network service such as SSH, FTP or HTTP forms. Lowercase options take ONE value (-l login, -p password); capital options take a FILE (-L logins, -P passwords). One account with many passwords is a dictionary/brute-force attack; one password across many accounts is password spraying.
Practice hydraUsage
Options and flags
service://targetprotocol and host to attack, e.g. ssh://10.10.10.5
-lLOGINa single username
-LFILEa file of usernames
-pPASSa single password
-PFILEa file of passwords (the password list)
-tTASKSnumber of parallel connections (default 16)
-sPORTnon-default service port
-fstop as soon as one valid login is found
-Vverbose: show every attempt
-oFILEwrite the found credentials to a file
Examples
hydra -l admin -P wordlist.txt ssh://10.10.10.5One account, many passwords (dictionary attack) against SSH.
hydra -L users.txt -p Winter2026 ssh://10.10.10.5One password across many accounts: password spraying.
hydra -l admin -P wordlist.txt -t 4 ssh://10.10.10.5Four parallel tasks — gentler on a fragile lab host.
hydra -l admin -P wordlist.txt -f ssh://10.10.10.5Stop at the first valid pair.
Common mistakes
Lowercase -p is ONE password (here the literal text 'wordlist.txt'); capital -P reads passwords from a file.