Passwords are often the weakest link in a system, and for this reason we continue our tour of tools that belong to the category of password crackers. This time we will study the Medusa password cracker, a fairly well-known open source tool.

This is a tool that can work very quickly as a brute-forcer of login credentials in a system. As we have explained in previous articles, brute force (or brute force attack) is the exhaustive testing of possible keys that produce a ciphertext in order to reveal the original message. The purpose of Medusa is to support as many protocols and services as possible that support remote authentication (e.g. ssh). Some of the advantages of this application are summarized below:
- Parallel use: Brute forcing can be performed against multiple hosts, users, or passwords simultaneously.
- Flexibility:Target information (host/user/password) can be specified in different ways.
- Multiple protocol support: Medusa can support different services and protocols (e.g. SMP, HTTP, POP3, MS-SQL, SSHv2, etc.)
How to install it
Medusa is available for Linux, Windows , and MacOS. In the well-known operating system version for penetration testers, Kali Linux, you will find Medusa pre-installed.
Linux
First you need to update your repositories and install the required dependencies:
| sudo apt-get update && sudo apt-get install unrar-free git-core openssl mediainfo |
Next, you will need to install Python (required from Medusa version v0.3.0 onwards) using the appropriate commands depending on your operating system version.
Next, create a group and a user named medusa. This is needed to ensure that the tool will not affect the security of our computer and will run in isolation:
| sudo addgroup –system medusa sudo adduser –disabled-password –system –home /var/lib/medusa –gecos “Medusa” –ingroup medusa medusa |
Then clone the Git repo for Medusa:
| sudo mkdir /opt/medusa && sudo chown medusa:medusa /opt/medusa sudo git clone https://github.com/pymedusa/Medusa.git /opt/medusa sudo chown -R medusa:medusa /opt/medusa |
For SysVinit, you will need to copy the init.d service:
For Ubuntu:
| sudo cp -v /opt/medusa/runscripts/init.ubuntu /etc/init.d/medusa |
For Debian:
| sudo cp -v /opt/medusa/runscripts/init.debian /etc/init.d/medusa |
Make sure the new service has the appropriate permissions:
| sudo chown root:root /etc/init.d/medusa sudo chmod 644 /etc/init.d/medusa |
Refresh and start the new service:
| sudo update-rc.d medusa defaults sudo service medusa start |
systems Upstart, you will need to copy the init.d service:
| sudo cp -v /opt/medusa/runscripts/init.upstart /etc/init/medusa.conf |
Make sure the new service has the appropriate permissions:
| sudo chown root:root /etc/init/medusa.conf sudo chmod 644 /etc/init/medusa.conf |
Refresh and start the new service:
| sudo service medusa start |
For Systemd, you will need to copy the init.d service:
| sudo cp -v /opt/medusa/runscripts/init.systemd /etc/systemd/system/medusa.service |
Make sure the new service has the appropriate permissions:
| sudo chown root:root /etc/systemd/system/medusa.service sudo chmod 644 /etc/systemd/system/medusa.service |
Start and check the status of the new service:
| sudo systemctl enable medusa sudo systemctl start medusa sudo systemctl status medusa |
Make Medusa run at startup (optional):
| sudo systemctl enable medusa.service |
To make sure everything went well, check if Medusa is accessible at: http://localhost:8081
Windows
Because installing the tool on a Windows environment can be quite complicated for many users, the creators of Medusa have created a Windows installer that can download all the necessary files and proceed with their installation. It can also create a service so that Medusa starts automatically when Windows.
First, you should visit the official Github page and download the latest available version.
In the folder you just downloaded, locate the installer and run it. What you will see on your screen looks like the image below.

To proceed with the installation, click Next and then select the installation folder. Click Next to proceed. The next window will ask you if you want to create a shortcut for the tool in the start menu.
The next window will ask you for the port you want Medusa to run on. It is recommended to leave the default value as is and proceed with the installation by clicking the Next button.
In the next window you will be asked if you wish to create a shortcut to the tool on your desktop.
The penultimate installation window will show you a summary of the settings you have selected and the dependencies that are going to be installed along with Medusa. If you select the Install button, the necessary files will start downloading and then the installation will be completed after you click the Finish button .

If everything went well, you can open any browser and visit the Medusa web interface at the address: https://localhost:8081.
How to use it
To see all the available tool options and their corresponding description, open a terminal and type Medusa.
root@kali-:~# medusa Medusa v2.2 [https://www.foofus.net] (C) JoMo-Kun / Foofus Networks<jmk@foofus.net> Syntax: Medusa [-h host|-H file] [-u username|-U file] [-p password|-P file] [-C file] -M module [OPT] -h [TEXT] : Target hostname or IP address -H [FILE] : File containing target hostnames or IP addresses -u [TEXT] : Username to test -U [FILE] : File containing usernames to test -p [TEXT] : Password to test -P [FILE] : File containing passwords to test -C [FILE] : File containing combo entries. See README for more information. -O [FILE] : File to append log information to -e [n/s/ns] : Additional password checks ([n] No Password, [s] Password = Username) -M [TEXT] : Name of the module to execute (without the .mod extension) -m [TEXT] : Parameter to pass to the module. This can be passed multiple times with a different parameter each time and they will all be sent to the module (ie -m Param1 -m Param2, etc.) -d : Dump all known modules -n [NUM] : Use for non-default TCP port number -s : Enable SSL -g [NUM] : Give up after trying to connect for NUM seconds (default 3) -r [NUM] : Sleep NUM seconds between retry attempts (default 3) -R [NUM] : Attempt NUM retries before giving up. The total number of attempts will be NUM + 1. -c [NUM] : Time to wait in usec to verify socket is available (default 500 usec). -t [NUM] : Total number of logins to be tested concurrently -T [NUM] : Total number of hosts to be tested concurrently -L : Parallelize logins using one username per thread. The default is to process the entire username before proceeding. -f : Stop scanning host after first valid username/password found. -F : Stop audit after first valid username/password found on any host. -b : Suppress startup banner -q : Display module's usage information -v [NUM] : Verbose level [0 - 6 (more)] -w [NUM] : Error debug level [0 - 10 (more)] -V : Display version -Z [TEXT] : Resume scan based on map of previous scan
Examples of the different commands you can run, depending on the attack protocol, can be found below:
Find password for a specific username
As we have already mentioned, Medusa is a very fast tool, capable of working with different protocols.
For example, if you want to crack the ssh password for a specific username, you can use the dictionary attack technique.The -u is used to specify a specific username and the -P is used to specify the dictionary file:
| medusa -h 192.168.1.108 -u stormi -P pass.txt -M ssh |
Find username for a specific password
In the opposite case, where you have the password in your possession and you want to check which username (for the ssh service or another) it corresponds to, you can use the same technique – dictionary attack:
| medusa -h 192.168.1.108 -U user.txt -p 123 -M ssh |
Find username and corresponding password
In combination, if you want to find username and password (for the ssh service or another) you can run the following, again using the dictionary attack technique. The -U activates dictionary mode for possible usernames and -P for possible passwords.
| medusa -h 192.168.1.108 -U user.txt -P pass.txt -M ssh |
Save result to disk
For maintenance and better readability purposes, you can write the results of Medusa commands to a file. To do this, use the -O and then the desired file title:
| medusa -h 192.168.1.108 -U user.txt -P pass.txt -M ssh -O log.txt |
Continuing the attack
Many times an attack may stop or be canceled by mistake, so using the -Z you can continue the attack by running the last failed command instead of starting from the beginning:
| medusa -h 192.168.1.108 -U user.txt -P pass.txt -M ssh -Z h1u2u3. |
Attack on a specific door
Network admins often change the port number of one service to another. In the previous cases, where we examined the ssh service, Medusa ran the attack on port 22, the default ssh port.
However, using the -n you can run the attack by selecting the port number you want to check, rather than the default service.
So let's say that by scanning a specific network we found that the port on which ssh runs is 2222 and not 22. For this reason we should run the following command
What did you think of Medusa? Would you prefer it?
