> For the complete documentation index, see [llms.txt](https://kaelenvs-cybersecurity-notes.gitbook.io/kaelens-tryhackme-experience/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://kaelenvs-cybersecurity-notes.gitbook.io/kaelens-tryhackme-experience/learning-paths/comptia-pentest+/penetration-testing-tools/hydra/using-hydra.md).

# Using Hydra

The first command given to break down was "hydra -l \<username> -p \<full path to pass> MACHINE\_IP -t 4 ssh"

The following table shows which option does what.&#x20;

| option | description                    |
| ------ | ------------------------------ |
| -l     | username                       |
| -p     | list of passwords              |
| -t     | specifies the numer of threads |

The next command, "hydra -l \<username> -P \<wordlist> MACHINE\_IP http-post-form "/:username=^USER^password=^PASS^:F=incorrect" -V

The following table breaks each part in this command down.&#x20;

| option         | description                              |
| -------------- | ---------------------------------------- |
| -l             | single username                          |
| -p             | indicator to use the password list       |
| http-post-form | indicates the type of form               |
| /login url     | login page url                           |
| :username      | form field to enter the username         |
| ^USER^         | tells hydra to use the username          |
| password       | form field where the password is entered |
| ^PASS^         | uses password list supplied prior        |
| Login          | login failed message indicator           |
| Login failed   | login failure message                    |
| F=incorrect    | if it appears on the page, its incorrect |
| -V             | verborse output                          |

Using the commands we learned, we are instructed to use Hydra to find Molly's passwords.&#x20;

The first thing I did was go through my usr/share/wordlists folder to find my available wordlists that were already preinstalled. The one I ended up using for this exercise was rockyou.txt.

<figure><img src="https://618011075-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F9sSHX9Ko3IU7Hcot2eC8%2Fuploads%2FKo0rotkYrxIBrxopZnzJ%2F11.PNG?alt=media&amp;token=00bc5ac4-f4aa-4531-aebf-01a6e0eaef65" alt=""><figcaption><p>Hydra's output finding Molly's password.</p></figcaption></figure>

Using the command, "hydra -l molly -P /usr/share/wordlists/rockyou.txt 10.10.100.155 http-post-form "/login:username=^USER^password=^PASS^:incorrect" -V" I used Hydra to brute force molly's password.&#x20;

Going back to the web server available on this IP, I used the credentials given to login and capture the first flag.&#x20;

To find Molly's ssh password, I used the command, "hydra -l molly -P /usr/share/wordlists/rockyou.txt".

<figure><img src="https://618011075-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F9sSHX9Ko3IU7Hcot2eC8%2Fuploads%2FdBRFrbuiCHCV7fLbfTmB%2F12.PNG?alt=media&amp;token=f1795d7c-0321-4b4f-945f-cb47e55e3e5d" alt=""><figcaption><p>The results from cracking Molly's ssh password.</p></figcaption></figure>

Using these credentials, I was able to login to molly's system.

<figure><img src="https://618011075-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F9sSHX9Ko3IU7Hcot2eC8%2Fuploads%2FACY3JVpIt0lgOe9Er9d8%2F13.PNG?alt=media&amp;token=86a881b8-5478-46a9-988d-f7517cf2b639" alt=""><figcaption><p>Logging into Molly's system with the newfound credentials. </p></figcaption></figure>

From here, I was able to search around the directories to find the flag.&#x20;

<figure><img src="https://618011075-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F9sSHX9Ko3IU7Hcot2eC8%2Fuploads%2Fv2msYb49JTvvyZ94JKDd%2F14.PNG?alt=media&amp;token=920ca231-0d89-43eb-bfdc-5b7d52a09320" alt=""><figcaption><p>The flag I found by looking around Molly's system. </p></figcaption></figure>

Using "ls" to list the files in the current directory and then using "cat" to read the file found,  I was able to find the second flag.&#x20;
