Welcome back, my budding hackers!
Password Cracker THC Hydra. Hydra is a parallelized password cracker which supports numerous protocols to attack. It is very fast and flexible, and new modules are easy to add. This tool makes it possible for researchers and security consultants to show how easy it would be to gain unauthorized access to a system remotely. THC-HYDRA UPDATED - A FASTER 8.1 VERSION RELEASED! THC Hydra is often a tool of choice when you aim to crack a remote authentication service. Rapid dictionary attacks to brute force crack the security holes: the security passwords is what Hydra is known to endeavor. Now, that too with fast and easy to inculcate modules provided in a new version: version 8.1.
'How to hack online passwords' such as email, social media, authentication forms, etc. is one the budding hackers' most frequent questions. Although it has become much more difficult in recent years, it is still possible. Here we will use two essential hacking tools to demonstrate how to hack online passwords, THC-Hydra and Burp Suite.
Step 1: Open THC-Hydra
So, let's get started. Fire up Kali and open THC-Hydra from Applications -> Kali Linux -> Password Attacks -> Online Attacks -> hydra.
Step 2: Get the Web Form Parameters
To be able to hack web form usernames and passwords, we need to determine the parameters of the web form login page as well as how the form responds to bad/failed logins. The key parameters we must identify are the:
We can identify each of these using a proxy such as Tamper Data or Burp Suite.
How much you improve depends on how much effort you put into it. It may seem a bit confusing to use the Japanese only textbook then have a translation book plus a workbook, but it works. For one month I went through an entire entire book which is one semester worth of material and was able to go from B class to D level class which is an int I started out with another popular Japanese language series Genki, but when I went to study in Japan we used Minna no Nihongo and now I swear by this series. For one month I went through an entire entire book which is one semester worth of material and was able to go from B class to D level class which is an intermediate level class much to my surprise. I always recommend this series to people who want to learn Japanese. Minna no nihongo textbook pdf.
Step 3: Using Burp Suite
Although we can use any proxy to do the job, including Tamper Data, in this post we will use Burp Suite. You can open Burp Suite by going to Applications -> Kali Linux -> Web Applications -> Web Application Proxies -> burpsuite. When you do, you should see the opening screen like below.
Next, we will be attempting to crack the password on the Damn Vulnerable Web Application (DVWA). You can run it from the Metasploitable operating system (available at Rapid7 or SourceForge) and then connecting to its login page, as I have here.
We need to enable the Proxy and Intercept on the Burp Suite like I have below. Make sure to click on the Proxy tab at the top and then Intercept on the second row of tabs. Make certain that the 'Intercept is on.'
Last, we need to configure our IceWeasel or FireFox web browser to use a proxy. We can go to Edit -> Preferences -> Advanced -> Network -> Settings to open the Connection Settings, as seen below. There, configure IceWeasel to use 127.0.0.1 port 8080 as a proxy by typing in 127.0.0.1 in the HTTP Proxy field, 8080 in the Port field and delete any information in the No Proxy for field at the bottom. Also, select the 'Use this proxy server for all protocols' button.
Step 4: Get the Bad Login Response
Now, let's try to log in with my username OTW and password OTW. When I do so, the BurpSuite intercepts the request and shows us the key fields we need for a THC-Hydra web form crack.
After collecting this information, I then forward the request from Burp Suite by hitting the 'Forward' button to the far left . The DVWA returns a message that the 'Login failed.' Now, I have all the information I need to configure THC-Hydra to crack this web app!
Getting the failure message is key to getting THC-Hydra to work on web forms. In this case, it is a text-based message, but it won't always be. At times it may be a cookie, but the critical part is finding out how the application communicates a failed login. In this way, we can tell THC-Hydra to keep trying different passwords; only when that message does NOT appear, have we succeeded.
Step 5: Place the Parameters into Your THC Hydra Command
Now, that we have the parameters, we can place them into the THC-Hydra command. The syntax looks like this:
kali > hydra -L <username list> -p <password list> <IP Address> <form parameters><failed login message>
So, based on the information we have gathered from Burp Suite, our command should look something like this:
kali >hydra -L <wordlist> -P<password list>192.168.1.101 http-post-form '/dvwa/login.php:username=^USER^&password=^PASS^&Login=Login:Login failed'
A few things to note. First, you use the upper case 'L' if you are using a username list and a lower case 'l' if you are trying to crack one username that you supply there. In this case, I will be using the lower case 'l ' as I will only be trying to crack the 'admin' password.
After the address of the login form (/dvwa/login.php), the next field is the name of the field that takes the username. In our case, it is 'username,' but on some forms it might be something different, such as 'login.'
Now, let's put together a command that will crack this web form login.
Step 6: Choose a Wordlist
Now, we need to chose a wordlist. As with any dictionary attack, the wordlist is key. You can use a custom one made with Crunch or CeWL, but Kali has numerous wordlists built right in. To see them all, simply type:
kali > locate wordlist
In addition, there are numerous online sites with wordlists that can be up to 100 GB! Choose wisely, my budding hacker. In this case for the sake of brevity, I will be using a built-in wordlist with less than 1,000 words at:
Thc Hydra Software Download Free
/usr/share/dirb/wordlists/short.txt
Step 7: Build the Command
Now, let's build our command with all of these elements, as seen below.
kali > hydra -l admin -P /usr/share/dirb/wordlists/small.txt 192.168.1.101 http-post-form '/dvwa/login.php:username=^USER^&password=^PASS^&Login=Login:Login failed' -V
Where:
Step 8: Let Her Fly!
Now, let her fly! Since we used the -V switch, THC-Hydra will show us every attempt.
Thc Hydra Free Download For Windows
After a few minutes, Hydra returns with the password for our web application. Success!
Thc Hydra Software Free Download
Final Thoughts
Although THC-Hydra is an effective and excellent tool for online password cracking, when using it in web forms, it takes a bit of practice. The key to successfully using it in web forms is determining how the form responds differently to a failed login versus a successful login. In the example above, we identified the failed login message, but we could have identified the successful message and used that instead. To use the successful message, we would replace the failed login message with 'S=successful message' such as this:
kali > hydra -l admin -P /usr/share/dirb/wordlists/small.txt 192.168.1.101 http-post-form '/dvwa/login.php:username=^USER^&password=^PASS^&S=success message' -V
Also, some web servers will notice many rapid failed attempts at logging in and lock you out. In this case, you will want to use the wait function in THC-Hydra. This will add a wait between attempts so as not to trigger the lockout. You can use this functionality with the -w switch, so we revise our command to wait 10 seconds between attempts by writing it:
kali > hydra -l admin -P /usr/share/dirb/wordlists/small.txt 192.168.1.101 http-post-form '/dvwa/login.php:username=^USER^&password=^PASS^&Login=Login:Login failed' -w 10 -V
I recommend that you practice the use of THC-Hydra on forms where you know the username and password before using it out 'in the wild.'
Comments are closed.
|
Details
AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |