Lesson 1 of 1 in hydra
Loud, Slow, and in the Log
Online brute force runs at the speed the server answers, and every guess is recorded. It is the weakest attack in this course, and worth knowing for exactly that reason.
2 min read
Not yet reviewed
Everything so far has been offline: an attacker with a stolen hash, guessing at a hundred billion a second, invisible to you. hydra is the online version — guessing against a live login screen — and almost everything that makes offline cracking dangerous is reversed.
Offline (hashcat, john)
Speed: 100,000,000,000 / second
Visible: no - the victim has no idea
Stopped by: a slow hashOnline (hydra)
Speed: a few / second, at best
Visible: every attempt is in the auth log
Stopped by: a rate limit, a lockout, a second factorThe speed difference alone is ten orders of magnitude. Online you are limited by the network round trip and by whatever the server does to slow you down — and the server is watching.
Trying it
login.internal runs SSH with an account deploy. Its password is in common.txt. Use hydra to find it — and read what it tells you about the cost.
Why it mostly does not work
Online brute force succeeds in exactly one situation: a weak password, no rate limit, no lockout, no second factor, and nobody reading the logs. Every one of those is a defence the defender controls, and any single one of them is usually enough.
Take care
Where online brute force *does* still work is credential stuffing — not guessing a password, but replaying one that already leaked from somewhere else. That is a different attack with a different defence, and it is the reason a rate limit has to count by address as well as by account. The next module is about exactly that.
Why is online brute force so much weaker than offline cracking?
Tip
If you see a burst of failed logins for one account from one address, that is hydra or something like it — and it is the easy case, because it is loud. The attack to worry about is the quiet one in the next module.