22 February 2010 | 20,099 views

Medusa 2.0 Released – Parallel Network Login Brute Forcing Tool

Acunetix Web Application Security

After what feels like an eternity (one year to the date since Medusa version 1.5), Medusa 2.0 is now available for public download.

What is Medusa? Medusa is a speedy, massively parallel, modular, login brute-forcer for network services created by the geeks at Foofus.net.

It currently has modules for the following services: AFP, CVS, FTP, HTTP, IMAP, MS-SQL, MySQL, NCP (NetWare), NNTP, PcAnywhere, POP3, PostgreSQL, rexec, rlogin, rsh, SMB, SMTP (AUTH/VRFY), SNMP, SSHv2, SVN, Telnet, VmAuthd, VNC. It also includes a basic web form module and a generic wrapper module for external scripts.

Features

  • Thread-based parallel testing. Brute-force testing can be performed against multiple hosts, users or passwords concurrently.
  • Flexible user input. Target information (host/user/password) can be specified in a variety of ways. For example, each item can be either a single entry or a file containing multiple entries. Additionally, a combination file format allows the user to refine their target listing.
  • Modular design. Each service module exists as an independent .mod file. This means that no modifications are necessary to the core application in order to extend the supported list of services for brute-forcing.

This release contains the most significant changes to the core of Medusa since its original release in 2005. We’ve moved to a “real” thread pool and modified how credential sets are selected. For a more detailed list of changes check the ChangeLog here.

While Medusa was designed to serve the same purpose as THC-Hydra, there are several significant differences. For a brief comparison see Medusa Compare.

You can download Medusa 2.0 here:

medusa-2.0.tar.gz

Or read more here.





                

Recent in Hacking Tools:
- EyeWitness – A Rapid Web Application Triage Tool
- wig – WebApp Information Gatherer – Identify CMS
- Capstone – Multi-platform, Multi-architecture Disassembly Framework

Related Posts:
- Medusa v1.5 Released – Parallel, Modular Login Brute Forcing Tool
- Medusa Fast Parallel Password Cracker 1.3 Released
- Medusa 1.4 – Parallel Password Cracker Released for Download

Most Read in Hacking Tools:
- Top 15 Security/Hacking Tools & Utilities - 1,844,704 views
- Brutus Password Cracker – Download brutus-aet2.zip AET2 - 1,030,169 views
- wwwhack 1.9 – Download wwwhack19.zip Web Hacking Tool - 613,217 views

Low-cost VPS Hosting

Comments are closed.