Password Attacks
Medusa is a speedy, parallel, and modular login brute-forcer. It supports many protocols including HTTP, FTP, SSH, SMB, MySQL, and more.
sudo apt install medusa
medusa -h <host> -u <user> -P <wordlist> -M <module>
Medusa is a speedy, parallel, and modular login brute-forcer. It supports over 20 network protocols through its modular architecture, allowing it to test authentication on SSH, FTP, HTTP, SMB, MySQL, PostgreSQL, and many more services.
Created in 2001 by Foofus, Medusa's key advantage is its multi-host scanning capability. Unlike single-target tools, Medusa can brute-force credentials across multiple hosts simultaneously, making it ideal for network-wide credential auditing.
Medusa's modular design makes it easy to add support for new protocols. It includes resume functionality for interrupted sessions and can operate in non-intrusive mode for testing without triggering lockouts.
medusa -dDump the list of all installed/available authentication modulesmedusa -M ssh -qShow module-specific usage and options for the ssh modulemedusa -h 10.10.10.10 -u <USER> -p <PASS> -M sshTest a single username/password pair against SSH on one hostmedusa -h 10.10.10.10 -u <USER> -P /path/to/file -M sshTry a password list against one fixed username over SSHmedusa -h 10.10.10.10 -U target.txt -P /path/to/file -M sshTest every username and password combination from two filesmedusa -H target.txt -u <USER> -P /path/to/file -M sshAttack multiple hosts read from a file with one usernamemedusa -h 10.10.10.10 -C combo.txt -M sshUse a combo file of host:user:password entriesmedusa -h 10.10.10.10 -u <USER> -P /path/to/file -M ssh -e nsAlso test a null password and password equal to the usernamemedusa -h 10.10.10.10 -u <USER> -P /path/to/file -M ftp -fStop scanning a host after the first valid credential is foundmedusa -H target.txt -U target.txt -P /path/to/file -M ssh -FStop the whole audit after the first success on any hostmedusa -h 10.10.10.10 -u <USER> -P /path/to/file -M ssh -t 4Run 4 concurrent login attempts per hostmedusa -H target.txt -U target.txt -P /path/to/file -M ssh -T 5Test 5 hosts concurrentlymedusa -h 10.10.10.10 -U target.txt -P /path/to/file -M ssh -LParallelize using one username per thread instead of finishing each user firstmedusa -h 10.10.10.10 -u <USER> -P /path/to/file -M ftp -n 2121Target a service on a non-default TCP portmedusa -h 10.10.10.10 -u <USER> -P /path/to/file -M ftp -sEnable SSL for the connectionBrute-force credentials across multiple hosts simultaneously for network-wide auditing.
Test SSH and FTP services across entire server fleets for weak passwords.
Audit MySQL, PostgreSQL, and MSSQL database credentials across multiple servers.
Test SMB authentication across Windows networks for default or weak credentials.
Comprehensive credential testing across all network services in large environments.
Medusa is a legitimate credential-auditing tool, but brute-forcing logins is only lawful against systems and accounts you own or have explicit written permission to test, such as a scoped penetration-testing engagement. Testing third-party services without authorization is illegal and can also trigger account lockouts and alerts. Always confirm your scope in writing first.
Yes, Medusa is part of the default Kali Linux tool set. If it is absent on a minimal install, run `sudo apt install medusa`. Confirm it is available with `medusa -h`.
Against a host you are authorized to test, the syntax is `medusa -h 10.10.10.10 -U users.txt -P passwords.txt -M ssh`. Here `-h` sets the target, `-U` and `-P` supply the username and password lists, and `-M ssh` selects the SSH module. Add `-f` to stop after the first valid credential is found.
Medusa prints a resume map when interrupted, and you can restart from it using the `-Z` flag with that value. This avoids re-testing combinations already checked. Logging the session to a file with `-O medusa.log` makes it easy to recover the resume string later.
Connection errors usually mean the service is filtered by a firewall, the port is closed, or the target is rate-limiting or blocking repeated attempts. Verify the port is open first (for example with Nmap) and reduce concurrency using `-t` for authorized tests. Some services also drop connections after several failed logins.
All three are parallel network login auditors. Medusa emphasizes stable, modular parallelism; Hydra supports the widest range of protocols; and Ncrack is built by the Nmap team and integrates cleanly with Nmap output. Choosing among them usually comes down to which protocols you need and personal workflow preference.
Password Attacks
Faster single-target brute-forcer with more protocols and HTTP form support.
Information Gathering
Network scanner for discovering login services before brute-forcing them.
Password Attacks
Offline password cracker for hashes extracted from compromised systems.
Password Attacks
GPU-accelerated offline cracker for large hash sets discovered during Medusa scans.
Information Gathering
Network scanner for discovering additional services beyond Medusa's initial targets.
The interface lists each authentication attempt, clearly marking valid combinations with a noticeable tag.
This tool is designed for authorized security testing, educational purposes, and legitimate network administration only. Unauthorized access to computer systems is illegal.