Parallel brute-force against live login forms โ SSH, FTP, RDP, web panels. In labs it ends logins in seconds; in the real world it also ends lockout policies, which is the point of the lesson.
Follow the steps โ click any step card to replay the terminal demo from that point. Everything runs in a lab you control.
-l one user, -L list of users, -P password list.
Inspect the form + failure message (Burp!) to fill the template.
-V shows each attempt (great demo), -f stops at first success.
Real services lock accounts; practice stealth-respecting speed.
Each protocol has flags; hydra -h lists all 50+ modules.
| -l / -L | user / user list |
| -p / -P | password / list |
| -t N | parallel tasks |
| -W sec | delay between attempts |
| -f | stop at first success |
| -V | verbose attempts |
| http-post-form | web form module syntax |
Password spraying (1โ2 passwords ร many users) dodges lockouts โ try it in labs.
Always pair with failure-message recon: the F= string must match.
Medusa is the backup when a Hydra module misbehaves.
Never on systems you don't own โ it's loud, illegal and obvious.
Use Hydra only on systems you own or have written permission to test. Your lab: Kali + Metasploitable2, DVWA, TryHackMe & HackTheBox โ plenty of legal targets, zero risk.