THC-HYDRA是一个支持多种网络服务的非常快速的网络登陆破解工具。这个工具是一个验证性质的工具,它被设计的主要目的是为研究人员和安全从业人员展示远程获取一个系统的认证权限是比较容易的。THC-HYDRA支持 Linux, Windows/Cygwin, Solaris, FreeBSD和OSX。工具特点:

  • Added a patch by Jan Dlabal which adds password generation bruteforcing (no more password files  )
  • New module: XMPP with TLS negotiation and LOGIN, PLAIN, CRAM-MD5, DIGEST-MD5, SCRAM-SHA1 support
  • New module: IRC is not dead ! use to find general server password and /oper credential
  • Added man pages from debian maintainers
  • Add support for new syntax: ://[:][/]
  • Add TLS support for SIP
  • Add SCRAM-SHA1 auth to IMAP module
  • Add module usage help (-U)
  • Add support for RFC 4013: Internationalized Strings in SASL (“SASLPrep”)
  • Add SASL + TLS support for NNTP
  • Add support for CRAM-MD5 and DIGEST-MD5 auth to ldap module
  • Add support for SCRAM-SHA1 (RFC 5802), first auth cracker to support it, yeah
  • Add TLS negotiation support for smtp-auth, pop3, imap, ftp and ldap
  • Rename smtpauth module to smtp
  • Forgot to rename ssh2 to ssh in xhydra, fixed
  • Fix SASL PLAIN auth method issue
  • Bugfix SASL DIGEST-MD5, response could be wrong on 64bits systems
  • Bugfix rlogin and rsh module, some auth failure could not be detected accurately
  • Add SSL support for VMware Authentication Daemon module
  • Bugfix CVS module, working now
  • Bugfix for Telnet module when line mode is not available

工具更多信息及下载:http://freeworld.thc.org/releases/hydra-6.2-src.tar.gz
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    THC-HYDRA is a very fast network logon cracker which support many different services. This tool is a proof of concept code, to give researchers and security consultants the possibility to show how easy it would be to gain unauthorized access from remote to a system. It was tested to compile cleanly on Linux, Windows/Cygwin, Solaris, FreeBSD and OSX.