How To Use Hydra

Поделиться
HTML-код
  • Опубликовано: 18 окт 2024
  • Learn how to use hydra in kali linux to brute force web page login forms as well as brute force ssh.
    #kalilinux #hydra #ethicalhacking #bruteforce #linux
    Disclaimer: This video is for educational purposes only. It is meant to teach Ethical Hacking Techniques and not to promote or condone any illegal activities. Use these techniques at your own risk

Комментарии • 38

  • @fsocietyhacker
    @fsocietyhacker 22 дня назад +4

    How do i bypass false positives?

    • @MattMiles1986
      @MattMiles1986  22 дня назад

      This usually occurs because your response for a failed attempt is wrong or mistyped. That or you could be using the wrong http method such as using get instead of post. In this situation I would suggest using burp suite to see for sure what the http method is, and to see what the failed response is. That and also to see what they are calling the username and password. I have seen before that they use username=user and password=secret instead of password or pass.

    • @fsocietyhacker
      @fsocietyhacker 22 дня назад +1

      @@MattMiles1986 thank you

    • @MattMiles1986
      @MattMiles1986  22 дня назад

      You’re welcome!

  • @Fod1m76
    @Fod1m76 3 месяца назад +2

    i am trying to test using hydra on kali linux in smartphone but most of the result is showing " command not found " so can you give me your successful hydra command line ??

    • @MattMiles1986
      @MattMiles1986  3 месяца назад +1

      I’ve not personally used hydra on a phone but given that it is saying command not found I’m thinking either it’s a typo such as using a capital letter when it should be lower case or using a lower case letter when it should be a capital letter. Check your syntax very closely and see if maybe you mistyped something. That or something is not installed such as a dependency. To my knowledge hydra is built in for the nethunter application for a phone but you could run sudo apt install hydra to make sure hydra is installed. I hope this helps.

  • @Nejtak853
    @Nejtak853 5 месяцев назад +3

    You just gained a sub

  • @jaiwanth5866
    @jaiwanth5866 5 месяцев назад +2

    The video's great
    But where can I learn hacking from total basics......I don't know anything about it

    • @MattMiles1986
      @MattMiles1986  5 месяцев назад +1

      My first suggestion is to start with the basics of learning Linux and networking. There are several resources out there such as RUclips, Udemy courses, TCM Security, tryhackme, hack the box, and several others. I’m going to be working on a couple of videos about getting started with Linux in the near future as well.

    • @jaiwanth5866
      @jaiwanth5866 5 месяцев назад +1

      @@MattMiles1986 Thanks man...waiting for it

    • @MattMiles1986
      @MattMiles1986  5 месяцев назад +1

      You’re welcome!

  • @offecncivesec
    @offecncivesec 5 месяцев назад +2

    keep going bro

    • @MattMiles1986
      @MattMiles1986  4 месяца назад

      Thank you, I definitely plan on it.

  • @ZAKIE-gi8jl
    @ZAKIE-gi8jl 4 месяца назад +1

    hi man , thanks for this video, I'm asking
    Have you tried Hydra on a login page without a username?
    In front of me is a router login page with a field to enter the password without the username
    hydra it is not work with that i tried a lot it didn't work ...
    .
    Can you make another video of Hydra?
    Explain to us the various possibilities, for example if you use it without the Internet.?
    If you use it for services http and how to write the code with the error message correctly

    • @MattMiles1986
      @MattMiles1986  4 месяца назад

      Thanks for the comment. In this situation I would use burp suite or zap proxy to proxy the request and use a password wordlist to brute force the password.
      Just have to have to watch for lockouts on the router as some routers do this to prevent brute forcing.

  • @izumi8170
    @izumi8170 5 месяцев назад +1

    Great video! Looking forward to more related videos, just had a quick question, how did u create the password.txt file?

    • @MattMiles1986
      @MattMiles1986  5 месяцев назад +1

      I used nano and copied some passwords from the seclist and pasted them into a file I named passwords.txt. That and I added a couple of more to it. If you would like I can make a video on this sometime this week because there are several ways to go about it. Just let me know.

    • @izumi8170
      @izumi8170 5 месяцев назад +1

      ​@@MattMiles1986 Oh thanks that'll be great

    • @MattMiles1986
      @MattMiles1986  4 месяца назад +1

      Here is the video on how to make a custom wordlist.
      ruclips.net/video/onhQ4OTZM6A/видео.htmlsi=4WT5gt5ZHesm4BlE

  • @Padmesh848
    @Padmesh848 2 месяца назад +1

    is there a website that we could just use what we learnt?

    • @MattMiles1986
      @MattMiles1986  2 месяца назад

      Two great resources online are tryhackme or hack the box. If you want to save some money though you can download DVWA which is a vulnerable web app for free and you can run all kinds of tests against it. Legally you can only use hydra against machines/web applications you own yourself or that you have permission. Also you can run it on the websites I mentioned above on their machines. Here is a link with info on how to download DVWA, install it, and get it running. www.kali.org/tools/dvwa/

  • @mentalboy2415
    @mentalboy2415 5 месяцев назад +1

    ♥️

  • @esa979
    @esa979 3 месяца назад +1

    hi sir you just uploaded 1 month ago can i just tried to day sir

    • @MattMiles1986
      @MattMiles1986  3 месяца назад +1

      Thanks for watching. Be sure to subscribe so that you’ll get notified when I post new videos.

  • @AliHussain-mt9vn
    @AliHussain-mt9vn 5 месяцев назад +2

    Great!!!

  • @handsomepotato5207
    @handsomepotato5207 16 дней назад +1

    Can you maybe show the code for your website

    • @MattMiles1986
      @MattMiles1986  16 дней назад

      Which website are you talking about?
      The website I used in the video for demonstration is through tryhackme.com

  • @ManSpider-m9m
    @ManSpider-m9m 2 месяца назад

    Can you speak Chinese?I am a Chinese,I can only a little English,I cannot understand your mean,thanks.

  • @eitelngolle1886
    @eitelngolle1886 2 месяца назад +1

    Are you Okay man ? You sound like you lose your voice

    • @MattMiles1986
      @MattMiles1986  2 месяца назад

      I’m good. Thank you for checking on me though. I think I was battling a cold when I filmed that video.

    • @eitelngolle1886
      @eitelngolle1886 2 месяца назад +1

      Ahh Okay I was kind of worried for you

    • @MattMiles1986
      @MattMiles1986  2 месяца назад

      @eitelngolle1886 I appreciate it. I’m all good though. I’ve been working on some new content and another certification. I just passed the PJPT test offered by TCM-Security on Thursday.