Dictionary Password Cracking (A THC Hydra starter guide)

Hello! In this tutorial, we will explore how to run a dictionary attack of THC Hydra. Let’s get started. If you are running Kali Linux you will already have a version of Hydra installed. If not you can install it on Linux platforms using the command sudo apt-get install hydra or just download it from the Github Repository https://github.com/vanhauser-thc/thc-hydra. Once you have finished the installation you have a new application called THC-Hydra. It should look like this:

THC Hydra has the option of running a dictionary attack or a brute force attack, however, in this tutorial, we will focus on the Dictionary Attack option. In the THC Hydra folder, you can import wordlists for dictionary attacks. I am getting mine from skullsecurity.org. In this, I am using the Rockyou.txt wordlist. To start the cracking, you would input command like this. hydra -t 4 -V -f -l administrator -P rockyou.txt rdp://Add IP ADRESS HERE. If you did everything correctly it should look like this:

Congratulations! You were able to run a dictionary attack using THC Hydra. I hope this helps you.


1 Like