Terminal Dojo
Help العربية Sign inGet started

Command library / hydra

hydra

BashDraft — pending expert review4 practice missions

Online password-guessing tool for authorised tests

Hydra tries many logins and passwords against a network service such as SSH, FTP or HTTP forms. Lowercase options take ONE value (-l login, -p password); capital options take a FILE (-L logins, -P passwords). One account with many passwords is a dictionary/brute-force attack; one password across many accounts is password spraying.

Practice hydra

Usage

hydra [-l LOGIN | -L FILE] [-p PASS | -P FILE] [options] service://server
Scope: Only against systems you are explicitly authorised to test (your own lab, CTF ranges). Online guessing is noisy: it triggers account lockouts and security alerts.

Options and flags

Examples

Common mistakes

hydra -l admin -p wordlist.txt ssh://10.10.10.5 hydra -l admin -P wordlist.txt ssh://10.10.10.5

Lowercase -p is ONE password (here the literal text 'wordlist.txt'); capital -P reads passwords from a file.

Related commands

nmap