Skip to contentExploitQuest

Lesson 1 of 1 in hydra

Loud, Slow, and in the Log

Online brute force runs at the speed the server answers, and every guess is recorded. It is the weakest attack in this course, and worth knowing for exactly that reason.

2 min read

Not yet reviewed

Everything so far has been offline: an attacker with a stolen hash, guessing at a hundred billion a second, invisible to you. hydra is the online version — guessing against a live login screen — and almost everything that makes offline cracking dangerous is reversed.

Offline (hashcat, john)

Speed:   100,000,000,000 / second
Visible: no - the victim has no idea
Stopped by: a slow hash

Online (hydra)

Speed:   a few / second, at best
Visible: every attempt is in the auth log
Stopped by: a rate limit, a lockout, a second factor

The speed difference alone is ten orders of magnitude. Online you are limited by the network round trip and by whatever the server does to slow you down — and the server is watching.

Trying it

Your turn

login.internal runs SSH with an account deploy. Its password is in common.txt. Use hydra to find it — and read what it tells you about the cost.

you@practice
Practice shell — nothing here is real. Type 'help' to begin.

Why it mostly does not work

Online brute force succeeds in exactly one situation: a weak password, no rate limit, no lockout, no second factor, and nobody reading the logs. Every one of those is a defence the defender controls, and any single one of them is usually enough.

Take care

Where online brute force *does* still work is credential stuffing — not guessing a password, but replaying one that already leaked from somewhere else. That is a different attack with a different defence, and it is the reason a rate limit has to count by address as well as by account. The next module is about exactly that.

Why is online brute force so much weaker than offline cracking?

Tip

If you see a burst of failed logins for one account from one address, that is hydra or something like it — and it is the easy case, because it is loud. The attack to worry about is the quiet one in the next module.