How to Use SecLists with Hydra: A Complete Guide to Brute-Force Testing

Use Hydra's -L flag to specify username lists and the -P flag to specify password lists from the danielmiessler/SecLists repository, then target specific network services like SSH, FTP, or HTTP with parallelized login attempts.

SecLists is a curated collection of wordlists maintained by Daniel Miessler that contains millions of passwords, usernames, and payloads organized by attack type. When paired with Hydra (thc-hydra), a fast parallelized login cracker, these lists become powerful tools for authorized penetration testing and security assessments.

Understanding the SecLists Directory Structure

The danielmiessler/SecLists repository organizes wordlists into logical categories that map directly to Hydra use cases. Knowing where specific files live ensures you select the right list for your target service.

For username enumeration, the repository provides options ranging from quick tests to comprehensive spraying campaigns:

For password attacks, SecLists offers both generic and targeted collections:

Essential Hydra Flags for Wordlist Integration

Hydra consumes SecLists through specific command-line flags that define the attack parameters:

  • -L <file> — Loads a file containing usernames (one per line). Point this to SecLists/Usernames/ files.
  • -P <file> — Loads a file containing passwords (one per line). Point this to SecLists/Passwords/ files.
  • -t <num> — Sets the number of parallel connections. Increase for speed on robust networks, decrease if targeting rate-limited services.
  • -w <sec> — Defines the connection timeout in seconds.
  • -s <port> — Specifies a non-standard service port.
  • -e ns — Enables additional checks: n tries null passwords, s tries the username as the password.

Practical Examples for Common Services

SSH Brute Force on Default Port 22

This command uses a short username list with a comprehensive password list against standard SSH:

hydra -L /opt/SecLists/Usernames/top-usernames-shortlist.txt \
      -P /opt/SecLists/Passwords/openwall.net-all.txt \
      -t 64 -w 10 \
      ssh://target.example.com

The -t 64 flag creates 64 parallel threads, maximizing throughput on stable networks. Reduce this value if the target exhibits throttling behavior.

FTP with Custom Port Configuration

When targeting FTP services running on non-standard ports, use the -s flag:

hydra -L /opt/SecLists/Usernames/top-usernames-shortlist.txt \
      -P /opt/SecLists/Passwords/openwall.net-all.txt \
      -s 2121 -t 32 -w 5 \
      ftp://target.example.com

This example targets port 2121 instead of the default 21, using 32 threads and a 5-second timeout.

HTTP Form-Based Authentication

For web login forms, Hydra requires the form field names and failure identifiers. Assuming a POST to login.php with fields username and password:

hydra -L /opt/SecLists/Usernames/top-usernames-shortlist.txt \
      -P /opt/SecLists/Passwords/openwall.net-all.txt \
      -t 50 -w 10 -f -V \
      https-post-form "https://target.example.com/login.php:username=^USER^&password=^PASS^:F=incorrect"

The ^USER^ and ^PASS^ placeholders are mandatory markers that Hydra replaces with entries from your SecLists files. The F=incorrect string tells Hydra to treat any response containing "incorrect" as a failed attempt.

RDP (Remote Desktop Protocol) Attacks

Remote Desktop requires slower thread counts due to protocol overhead:

hydra -L /opt/SecLists/Usernames/top-usernames-shortlist.txt \
      -P /opt/SecLists/Passwords/openwall.net-all.txt \
      -t 16 -w 10 \
      rdp://target.example.com

Using -t 16 prevents overwhelming Windows systems that may lock accounts or drop connections under heavy load.

Credential Spraying with Massive Username Lists

When testing a single common password against many usernames (credential spraying), combine the extensive xato-net-10-million-usernames.txt with the null/same-as-username checks:

hydra -L /opt/SecLists/Usernames/xato-net-10-million-usernames.txt \
      -P /opt/SecLists/Passwords/Default-Credentials/default-passwords.txt \
      -e ns -t 128 -w 15 \
      ssh://target.example.com

The -e ns flag adds two attempts per username: one with a blank password and one where the password equals the username, often catching misconfigured accounts before the main wordlist iteration begins.

Selecting Optimal Wordlists for Specific Targets

Different attack scenarios demand specific SecLists files:

Summary

  • Clone the danielmiessler/SecLists repository to /opt/SecLists or your preferred directory to maintain consistent file paths in your commands.
  • Use -L for username files from SecLists/Usernames/ and -P for password files from SecLists/Passwords/.
  • Adjust thread counts (-t) based on protocol resilience—higher for SSH (64+), lower for RDP (16).
  • Leverage -e ns to automatically test null passwords and username-as-password combinations before iterating through full wordlists.
  • Reference Passwords/Default-Credentials/ when targeting hardware devices that likely retained factory settings.

Frequently Asked Questions

Where should I clone SecLists to use with Hydra?

Clone the repository to any persistent directory such as /opt/SecLists or ~/tools/SecLists. The path you choose becomes the base reference for all -L and -P flags. For example: git clone https://github.com/danielmiessler/SecLists.git /opt/SecLists.

Which SecLists file is best for a quick SSH password audit?

Use Usernames/top-usernames-shortlist.txt for usernames and Passwords/openwall.net-all.txt for passwords. This combination covers the most common credentials without the time investment required for massive lists like xato-net-10-million-usernames.txt.

How do I prevent Hydra from locking accounts during testing?

Reduce the thread count using -t 4 or -t 8, increase the wait time with -w 30, and avoid massive username lists unless performing credential spraying with a single password. Always verify account lockout policies before running brute-force attacks.

Can I use SecLists with Hydra for web services that use tokens or headers?

Yes, though you may need protocol-specific modules. For HTTP headers or API tokens, use the http-get or http-post modules with ^USER^ and ^PASS^ placeholders in the header strings. The Discovery/Web-Content/ directory contains lists useful for identifying valid API endpoints before attempting authentication.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →