GO KALI FREE

Medusa

Password Attacks

Intermediatehigh risk

Medusa is a speedy, parallel, and modular login brute-forcer. It supports many protocols including HTTP, FTP, SSH, SMB, MySQL, and more.

Installation

sudo apt install medusa

Basic Syntax

medusa -h <host> -u <user> -P <wordlist> -M <module>

Quick Facts

Full Name
Medusa
License
GPLv2
Author
Foofus (jmk)
Written In
C
Platforms
Linux, macOS, BSD
Category
Network Brute-Forcer
Protocols Supported
20+
Key Feature
Multi-host parallel scanning

Tool Overview

Medusa is a speedy, parallel, and modular login brute-forcer. It supports over 20 network protocols through its modular architecture, allowing it to test authentication on SSH, FTP, HTTP, SMB, MySQL, PostgreSQL, and many more services.

Created in 2001 by Foofus, Medusa's key advantage is its multi-host scanning capability. Unlike single-target tools, Medusa can brute-force credentials across multiple hosts simultaneously, making it ideal for network-wide credential auditing.

Medusa's modular design makes it easy to add support for new protocols. It includes resume functionality for interrupted sessions and can operate in non-intrusive mode for testing without triggering lockouts.

Common Commands

medusa -dDump the list of all installed/available authentication modules
medusa -M ssh -qShow module-specific usage and options for the ssh module
medusa -h 10.10.10.10 -u <USER> -p <PASS> -M sshTest a single username/password pair against SSH on one host
medusa -h 10.10.10.10 -u <USER> -P /path/to/file -M sshTry a password list against one fixed username over SSH
medusa -h 10.10.10.10 -U target.txt -P /path/to/file -M sshTest every username and password combination from two files
medusa -H target.txt -u <USER> -P /path/to/file -M sshAttack multiple hosts read from a file with one username
medusa -h 10.10.10.10 -C combo.txt -M sshUse a combo file of host:user:password entries
medusa -h 10.10.10.10 -u <USER> -P /path/to/file -M ssh -e nsAlso test a null password and password equal to the username
medusa -h 10.10.10.10 -u <USER> -P /path/to/file -M ftp -fStop scanning a host after the first valid credential is found
medusa -H target.txt -U target.txt -P /path/to/file -M ssh -FStop the whole audit after the first success on any host
medusa -h 10.10.10.10 -u <USER> -P /path/to/file -M ssh -t 4Run 4 concurrent login attempts per host
medusa -H target.txt -U target.txt -P /path/to/file -M ssh -T 5Test 5 hosts concurrently
medusa -h 10.10.10.10 -U target.txt -P /path/to/file -M ssh -LParallelize using one username per thread instead of finishing each user first
medusa -h 10.10.10.10 -u <USER> -P /path/to/file -M ftp -n 2121Target a service on a non-default TCP port
medusa -h 10.10.10.10 -u <USER> -P /path/to/file -M ftp -sEnable SSL for the connection

Step-by-Step Guide

  1. 1Identify the objective server and the listening service
  2. 2Acquire your target usernames and associated dictionary files
  3. 3Assign the correct protocol module using the designated flag
  4. 4Execute the tool against the remote system
  5. 5Scan the output for valid authentication combinations

Warnings

Use Cases

Multi-Host Scanning

Brute-force credentials across multiple hosts simultaneously for network-wide auditing.

SSH/FTP Auditing

Test SSH and FTP services across entire server fleets for weak passwords.

Database Testing

Audit MySQL, PostgreSQL, and MSSQL database credentials across multiple servers.

SMB Share Access

Test SMB authentication across Windows networks for default or weak credentials.

Network-Wide Audits

Comprehensive credential testing across all network services in large environments.

Key Features

People Also Ask

Is it legal to use Medusa?

Medusa is a legitimate credential-auditing tool, but brute-forcing logins is only lawful against systems and accounts you own or have explicit written permission to test, such as a scoped penetration-testing engagement. Testing third-party services without authorization is illegal and can also trigger account lockouts and alerts. Always confirm your scope in writing first.

Is Medusa pre-installed in Kali Linux?

Yes, Medusa is part of the default Kali Linux tool set. If it is absent on a minimal install, run `sudo apt install medusa`. Confirm it is available with `medusa -h`.

How do I brute-force an SSH login with Medusa?

Against a host you are authorized to test, the syntax is `medusa -h 10.10.10.10 -U users.txt -P passwords.txt -M ssh`. Here `-h` sets the target, `-U` and `-P` supply the username and password lists, and `-M ssh` selects the SSH module. Add `-f` to stop after the first valid credential is found.

How do I resume an interrupted Medusa scan?

Medusa prints a resume map when interrupted, and you can restart from it using the `-Z` flag with that value. This avoids re-testing combinations already checked. Logging the session to a file with `-O medusa.log` makes it easy to recover the resume string later.

Why does Medusa show connection errors or timeouts?

Connection errors usually mean the service is filtered by a firewall, the port is closed, or the target is rate-limiting or blocking repeated attempts. Verify the port is open first (for example with Nmap) and reduce concurrency using `-t` for authorized tests. Some services also drop connections after several failed logins.

What is the difference between Medusa, Hydra, and Ncrack?

All three are parallel network login auditors. Medusa emphasizes stable, modular parallelism; Hydra supports the widest range of protocols; and Ncrack is built by the Nmap team and integrates cleanly with Nmap output. Choosing among them usually comes down to which protocols you need and personal workflow preference.

Related Tools

THC Hydra

Password Attacks

Faster single-target brute-forcer with more protocols and HTTP form support.

Nmap

Information Gathering

Network scanner for discovering login services before brute-forcing them.

John the Ripper

Password Attacks

Offline password cracker for hashes extracted from compromised systems.

Hashcat

Password Attacks

GPU-accelerated offline cracker for large hash sets discovered during Medusa scans.

Nmap

Information Gathering

Network scanner for discovering additional services beyond Medusa's initial targets.

Frequently Asked Questions

What is Medusa?

Medusa is a speedy, parallel, and modular login brute-forcer that supports over 20 network protocols. Its key advantage is multi-host scanning capability, allowing it to brute-force credentials across multiple hosts simultaneously for network-wide auditing.

How do I list available Medusa modules?

Run medusa -d to display all available protocol modules. Each module has specific options you can view with medusa -M <module> -m OPT:VALUE.

What is the difference between Medusa and Hydra?

Medusa excels at multi-host parallel scanning and has a modular architecture. Hydra supports more protocols (50+ vs 20+) and has HTTP form attack capabilities. Medusa is better for network-wide scanning; Hydra for single-target deep testing.

How do I brute-force multiple hosts with Medusa?

Create a file with target IPs (one per line) and use the -H flag: medusa -H hosts.txt -u admin -P passwords.txt -M ssh. Medusa will test all hosts simultaneously.

What protocols does Medusa support?

Medusa supports 20+ protocols including SSH, FTP, Telnet, HTTP, HTTPS, SMB, MySQL, PostgreSQL, MSSQL, Oracle, VNC, SNMP, POP3, IMAP, and more. Each protocol has its own module with specific options.

How do I stop Medusa if it's running too long?

Use Ctrl+C to gracefully stop Medusa. It saves partial results to the log file. You can also set timeouts with -T for per-connection timeouts and -f to stop after first successful login per host.

How do I use Medusa with custom username/password lists?

Use -U for username file and -P for password file: medusa -H targets.txt -U users.txt -P passwords.txt -M ssh. Each line in the files is tested as a single credential pair.

Can Medusa test for default credentials?

Yes, create a list of common default credentials (admin:admin, root:root, etc.) and use it with -C for combined credential files. Medusa is commonly used to audit default credentials across server fleets.

How do I check Medusa scan progress?

Medusa outputs results to stdout and optionally to a log file with -O. Use -v for verbose output showing each attempt, or -f for fast mode showing only successful logins.

How do I parallelize Medusa for faster scanning?

Medusa is already multi-threaded. Use -T to set connection timeout and -f for first-success-per-host mode. For maximum speed, reduce timeout values and use -M with the fastest module for the protocol.

How do I use Medusa with a combined credential file?

Use -C for combined username:password files: medusa -H targets.txt -C credentials.txt -M ssh. Each line should contain username:password pairs. This is faster than using separate -U and -P files for credential testing.

Can Medusa brute-force HTTP forms?

Yes, Medusa's HTTP module supports basic authentication and form-based login. Use -m DIR:/login and provide form parameters. For complex forms, tools like Hydra with the http-form module may be more suitable.

How do I set Medusa to stop after first success?

Use the -f flag to stop after the first successful login per host. Without -f, Medusa continues testing all remaining credentials, which wastes time once valid credentials are found.

Can Medusa scan IPv6 hosts?

Medusa primarily supports IPv4 addresses. For IPv6 scanning, use IPv4-mapped addresses or consider Hydra as an alternative that has better IPv6 support for certain protocols.

How do I use Medusa with a custom username list?

Use -U to specify a file containing usernames (one per line): medusa -H target.txt -U users.txt -P passwords.txt -M ssh. Each line in the username file is tested against each password.

What happens when Medusa encounters a locked account?

Medusa continues testing remaining credentials but the locked account will show as a failure. Use -f to stop on first success and -T for timeouts to reduce lockout risk. Monitor target logs for lockout patterns.

Can Medusa test PostgreSQL databases?

Yes, use the postgres module: medusa -h db.server -u postgres -P passwords.txt -M postgres -m PORT:5432. Medusa tests PostgreSQL credentials using the pg_hba.conf authentication method.

How do I log Medusa output to a file?

Use -O to save all output to a log file: medusa -h target.txt -U users.txt -P pass.txt -M ssh -O medusa.log. Use -v for verbose logging showing each attempt, or -f for only successful logins.

Can Medusa test multiple services simultaneously?

Medusa scans multiple hosts in parallel but tests one protocol module per run. To test multiple services, run separate Medusa instances for each protocol (SSH, FTP, etc.) against the same targets.

Tags

#password-attacks

Output Explanation

The interface lists each authentication attempt, clearly marking valid combinations with a noticeable tag.

Ethical Usage Notice

This tool is designed for authorized security testing, educational purposes, and legitimate network administration only. Unauthorized access to computer systems is illegal.