GO KALI FREE

Ncrack

Password Attacks

Intermediatehigh risk

Ncrack is a high-speed network authentication cracking tool built by the Nmap team. It supports RDP, SSH, HTTP, SMB, FTP, and more protocols.

Installation

sudo apt install ncrack

Basic Syntax

ncrack [options] <target>

Quick Facts

Full Name
Ncrack
License
GPLv2
Author
Nmap Project (Fyodor)
Written In
C++
Platforms
Linux, Windows, macOS
Category
Network Authentication Cracking
Protocols Supported
12+
Key Feature
Nmap XML integration

Tool Overview

Ncrack is a high-speed network authentication cracking tool built by the Nmap team. It specializes in cracking credentials for connection-oriented protocols like RDP, SSH, SMB, and FTP, with native integration with Nmap scan results.

Created in 2008 as part of the Nmap ecosystem, Ncrack's key advantage is its ability to import targets directly from Nmap XML output. After discovering services with Nmap, you can feed the results directly into Ncrack for credential testing without manual target configuration.

Ncrack supports over 12 protocols and provides precise timing control for stealthy operations. It's designed for speed and efficiency, making it ideal for penetration testing workflows that start with Nmap reconnaissance.

Common Commands

ncrack -hDisplay the help summary with all options and supported modules
ncrack --versionPrint the Ncrack version number and exit
ncrack ssh://10.10.10.10Crack SSH on a host using Ncrack's built-in default credential lists
ncrack -p 22 10.10.10.10Attack a host on a specific port, auto-detecting the SSH service
ncrack -p ssh,rdp,ftp 10.10.10.10Attack multiple services on a host by service name
ncrack -U users.txt -P pass.txt ssh://10.10.10.10Use username and password wordlists against SSH
ncrack --user root,admin ssh://10.10.10.10Supply usernames inline as a comma-separated list
ncrack --pass password123,letmein ftp://10.10.10.10Supply passwords inline as a comma-separated list
ncrack -iL target.txt -p sshRead a list of target hosts from a file and attack SSH
ncrack -p rdp 192.168.1.0/24Attack the RDP service across an entire CIDR subnet
ncrack -f -U users.txt -P pass.txt ssh://10.10.10.10Stop attacking each host as soon as one valid credential is found
ncrack -T4 ssh://10.10.10.10Apply the aggressive timing template for faster attacks
ncrack -g cl=3,cr=2,to=1h ssh://10.10.10.10Set global timing options: concurrent logins, retries, and timeout
ncrack "ssh://10.10.10.10,CL=4,at=6"Set per-service options appended after the service specification
ncrack -oN results.txt ssh://10.10.10.10Write results to a file in normal human-readable format

Step-by-Step Guide

  1. 1Pinpoint the services you intend to evaluate
  2. 2Gather your dictionaries and target accounts
  3. 3Launch the application against the specified host
  4. 4Observe the terminal for successfully recovered passwords
  5. 5Record all validated findings for your audit report

Warnings

Use Cases

Nmap Integration

Import Nmap XML scan results directly for credential testing of discovered services.

RDP Brute Force

Test Windows Remote Desktop services for weak administrative passwords.

SSH Credential Testing

Brute-force SSH services across multiple hosts with Nmap-discovered targets.

SMB Authentication

Test Windows SMB shares for default or weak credentials.

Multi-Protocol Testing

Test multiple protocols simultaneously with a single Ncrack command.

Key Features

People Also Ask

Is it legal to use Ncrack?

Ncrack is a legitimate network-authentication auditing tool from the Nmap project, but it may only be used against hosts and accounts you own or have explicit written authorization to test. Unauthorized brute-forcing of remote services is illegal and can cause lockouts and service disruption. Keep your engagement's scope and permission documented.

Is Ncrack pre-installed in Kali Linux?

Yes, Ncrack ships with the standard Kali Linux distribution. On a minimal image you can install it with `sudo apt install ncrack`. Check it is ready with `ncrack --version`.

What is the difference between Ncrack and Medusa?

Both are high-speed parallel login auditors. Ncrack is developed by the Nmap team and shares Nmap's timing model and output style, making it a natural fit alongside Nmap scans. Medusa is an independent tool with its own module set; many testers choose based on protocol support and which output format suits their workflow.

How do I resume a stopped Ncrack session?

If an Ncrack run is interrupted, it writes a restore file and prints the exact `ncrack --resume <file>` command to continue. Running that command resumes from where it stopped rather than restarting the entire credential space. This is helpful during long authorized tests that must be paused.

What username and password list options does Ncrack support?

Provide a single user with `--user` or a list with `-U users.txt`, and likewise `--pass` or `-P passwords.txt` for passwords. You can also supply combined `user:pass` pairs with `-C combo.txt`. Credentials can be set inline per service, e.g. `ncrack -U users.txt -P passwords.txt ssh://10.10.10.10`.

How do I brute-force an SSH service with Ncrack?

Against an authorized target, run `ncrack -U users.txt -P passwords.txt ssh://10.10.10.10`. Ncrack also accepts Nmap-style port syntax, so `ncrack -p 22 10.10.10.10` targets SSH by port. Use the `-T` timing options responsibly to avoid overwhelming production systems you are permitted to test.

Related Tools

Nmap

Information Gathering

Network scanner that discovers services for Ncrack credential testing.

THC Hydra

Password Attacks

More flexible brute-forcer with additional protocols and HTTP form support.

Medusa

Password Attacks

Multi-host brute-forcer for network-wide credential testing campaigns.

Hashcat

Password Attacks

GPU-accelerated offline cracker for hashes extracted from Ncrack-discovered services.

Medusa

Password Attacks

Multi-host parallel scanner for expanding credential testing beyond Ncrack's scope.

Frequently Asked Questions

What is Ncrack?

Ncrack is a high-speed network authentication cracking tool built by the Nmap team. It specializes in cracking credentials for connection-oriented protocols like RDP, SSH, SMB, and FTP, with native integration with Nmap scan results.

How do I use Ncrack with Nmap?

Save Nmap results in XML format with -oX, then import into Ncrack: ncrack -iX nmap_output.xml -p ssh,rdp,ftp. Ncrack will automatically target all discovered services.

What protocols does Ncrack support?

Ncrack supports 12+ protocols including SSH, RDP, SMB, FTP, HTTP(S), Telnet, VNC, MySQL, PostgreSQL, and more. Check the full list in the Ncrack documentation.

What is the difference between Ncrack and Hydra?

Ncrack excels at Nmap integration and connection-oriented protocols. Hydra supports more protocols (50+) and has HTTP form attack capabilities. Ncrack is better for Nmap-centric workflows; Hydra for flexibility and web form attacks.

How do I set connection timeouts in Ncrack?

Use the -g flag with timeout options: -g CL:100 (connect timeout 100ms), -g TO:5000 (overall timeout 5 seconds). Adjust timeouts based on network latency and target response times.

Can Ncrack test for default credentials?

Yes, create username and password lists with common defaults (admin:admin, root:password, etc.) and use them with -U and -P flags. Ncrack will test all combinations across discovered services.

How do I save Ncrack results?

Use -oX for XML output, -oN for normal format, or -oG for grepable format. XML output is recommended for importing into reporting tools and for Nmap compatibility.

What is the advantage of Ncrack over manual testing?

Ncrack automates parallel credential testing across multiple protocols and hosts simultaneously. It handles connection management, retries, and timeout detection that would be tedious and error-prone to do manually.

How do I handle Ncrack account lockouts?

Use -g with lower connection rates and higher timeouts. Add -sS for SYN stealth mode or -T3 for slower timing. Monitor for failed login patterns and adjust accordingly.

Can Ncrack test VPN credentials?

Ncrack supports SSH, RDP, SMB, FTP, and other connection-oriented protocols. For VPN-specific protocols like IPSec or PPTP, use specialized tools like Hydra or custom scripts.

How do I use Ncrack for RDP brute-forcing?

Use: ncrack -p rdp 192.168.1.1 -U users.txt -P passwords.txt. Ncrack tests each username/password combination against the RDP service, reporting successful logins. Use --connection-limit to control concurrent connections.

Can Ncrack test MySQL database credentials?

Yes, use the mysql protocol: ncrack -p 3306 192.168.1.1 -U users.txt -P passwords.txt --mysql. Ncrack connects to the MySQL service and tests credentials using the MySQL authentication protocol.

How do I increase Ncrack speed?

Use --connection-limit to increase concurrent connections: ncrack -p ssh 192.168.1.1 -U users.txt -P passwords.txt --connection-limit 50. Higher values test more credentials simultaneously but increase network load and lockout risk.

Can Ncrack use pass-the-hash authentication?

Ncrack focuses on credential brute-forcing with plaintext passwords. For pass-the-hash attacks, use tools like CrackMapExec (now NetExec) or smbclient which support NTLM hash authentication directly.

How do I interpret Ncrack output?

Ncrack outputs each tested credential with success/failure status. Successful logins show 'Discovered credential' with the username:password pair. Failed attempts show 'Authentication failed' with timing information.

Can Ncrack test VNC credentials?

Yes, Ncrack supports VNC authentication: ncrack -p 5900 192.168.1.1 -P passwords.txt --vnc. VNC uses a challenge-response authentication mechanism that Ncrack can test against password lists.

How do I handle Ncrack connection timeouts?

Use -g with timeout options: -g CL:200 (connect timeout 200ms), -g TO:10000 (overall timeout 10 seconds). Increase timeouts for slow networks or targets with high latency connections.

Can Ncrack test FTP credentials on non-standard ports?

Yes, specify the port directly: ncrack -p 2121 192.168.1.1 -U users.txt -P passwords.txt --ftp. Use -p to target any port running an FTP service, regardless of the standard port assignment.

How do I install Ncrack on different Linux distributions?

Install with: sudo apt install ncrack (Debian/Ubuntu/Kali), sudo yum install ncrack (CentOS/RHEL), or compile from source: git clone https://github.com/nmap/ncrack.git && cd ncrack && ./configure && make.

Tags

#password-attacks

Output Explanation

Presents successfully validated credentials alongside the relevant IP address and service name.

Ethical Usage Notice

This tool is designed for authorized security testing, educational purposes, and legitimate network administration only. Unauthorized access to computer systems is illegal.