SharkBruteforce is a modular, terminal-driven credential auditing engine that weaponizes the legendary THC-Hydra engine along with native PDF-cracking fallbacks. It is built for authorized penetration testers, CTF players, and security students who need a clean, fast, and reliable way to audit weak credentials on:
- ๐ท IP Cameras (HTTP Basic Auth)
- ๐ Web Admin Panels (HTTP Form Auth)
- ๐ Password-Protected PDFs (pdfcrack / John the Ripper / pikepdf)
Every attack runs through multi-backend auto-fallback, so if one cracker is missing, Shark jumps to the next โ zero manual config. ๐ฏ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ $ whoami โ
โ > technicalsuraj2 (Suraj Patel) โ
โ $ id โ
โ > uid=1337 gid=1337 groups=1337(offense) โ
โ $ cat /etc/role โ
โ > Ethical Hacker & Developer โ
โ > Founder @ AGSC Developer โ
โ > Location: India ๐ฎ๐ณ โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
Suraj Patel (technicalsuraj2) is an ethical hacker and Python developer from India who builds cutting-edge offensive security tooling โ engineered for power, built for education. He believes the sharpest defenses come from studying the sharpest offenses. Every tool he ships is designed to teach, expose weak spots, and raise security awareness โ never to harm.
๐ Arsenal so far: Eagle Eyes Pro ยท SharkBruteforce ยท Subfinder ยท Rootlock ยท DarkDomainFinder ยท Wifibruteforce & more.
| Feature | Details |
|---|---|
| ๐ฏ Three attack vectors | IP Camera ยท Web Admin ยท PDF brute force |
| โ๏ธ Hydra-powered | Industry-standard THC-Hydra under the hood |
| ๐ Auto fallback | pdfcrack โ John the Ripper โ pikepdf |
| ๐ฆ Auto dependency install | Hydra auto-installs on Linux |
| ๐ Auto wordlist fetch | Downloads full rockyou.txt (~133 MB) if missing |
| โ Input validation | URL, file-existence & path sanitization |
| โน๏ธ Graceful interrupts | Clean Ctrl+C handling, no half-broken states |
| ๐งต Cross-platform | Kali ยท Ubuntu ยท Debian ยท Windows (WSL2) |
| ๐ฅ๏ธ Professional UI | Red/cyan terminal theming ready for screen-demo |
| Dependency | Purpose | Install |
|---|---|---|
| Python 3.x | Core runtime | Pre-installed on Kali/Ubuntu |
| THC-Hydra | Camera & web brute force | sudo apt install hydra (auto-installs) |
| pdfcrack / john (optional) | PDF cracking backends | sudo apt install john pdfcrack |
| pikepdf (fallback) | Pure-Python PDF cracker | pip install pikepdf |
| rockyou.txt | Default wordlist | Auto-downloaded on first run |
| Network access | Wordlist download / targets | Standard |
sudo apt update && sudo apt install -y python3 python3-pip git hydra john
git clone https://github.com/technicalsuraj2/SharkBruteforce.git
cd SharkBruteforce
pip3 install -r requirements.txt
python3 sharkbruteforce.py# WSL2 (Kali/Ubuntu): same commands as above
# Termux:
pkg update && pkg upgrade
pkg install python git hydra
git clone https://github.com/technicalsuraj2/SharkBruteforce.git
cd SharkBruteforce
pip install -r requirements.txt
python sharkbruteforce.py๐ก On Windows without WSL, install THC-Hydra manually โ PDF cracking still works via
pikepdf.
python3 sharkbruteforce.pyโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ ๐ฆ SELECT ATTACK MODE ๐ฆ โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโค
โ [1] Camera Login Brute Force โ IP Camera URL + lists โ
โ [2] Web Admin Panel Brute Force โ Web URL + lists โ
โ [3] PDF Password Brute Force โ PDF path + wordlist โ
โ [4] Exit โ
โ [5] Go to Author GitHub โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
$ 1
Camera IP URL: http://192.168.1.100:8080
Username wordlist: users.txt
Password wordlist: rockyou.txt
[*] Starting Camera Brute Force on 192.168.1.100:8080
[*] Service: http-get
[โ] Credentials acquired โ admin / admin@123$ 2
Web Admin URL: https://example.com/admin
Username wordlist: users.txt
Password wordlist: rockyou.txt
[*] Starting Web Admin Brute Force on example.com:443
[โ] Credentials acquired โ root / root123$ 3
PDF file path: /home/suraj/encrypted.pdf
Password wordlist: rockyou.txt
[*] Trying pdfcrack โ [fallback] John โ [fallback] pikepdf
[โโโ] PASSWORD FOUND: secret@2024This tool is provided strictly for EDUCATIONAL PURPOSES and AUTHORIZED SECURITY TESTING ONLY.
- โ Use it only on your own systems, lab environments, or targets you have explicit written permission to test.
- โ Unauthorized access to devices, networks, or accounts you do not own is illegal in most jurisdictions.
โ ๏ธ The author takes no responsibility for any misuse of this software. You alone are accountable for how you use it.- ๐ก๏ธ The purpose of this project is to raise awareness and help the security community harden their defenses โ not to break the law.
By downloading/using this tool, you agree to use it ethically and legally. Stay on the right side of the law. ๐ฆ
| Parameter | Mode | Example |
|---|---|---|
Camera IP URL |
1 | http://192.168.1.100:8080 |
Web Admin URL |
2 | https://example.com/admin or /login.php |
PDF file path |
3 | /path/to/encrypted.pdf |
Username wordlist |
1, 2 | /path/users.txt |
Password wordlist |
1, 2, 3 | rockyou.txt (auto) |
SharkBruteforce/
โโโ sharkbruteforce.py # Main tool (single-file, zero bloat)
โโโ requirements.txt # Python dependencies
โโโ LICENSE # MIT license
โโโ README.md # You are here
โโโ .gitignore # Ignores rockyou.txt & caches
โโโ assets/
โโโ demo.gif # Animated demo
- ๐ฆ Camera & web brute force (Hydra)
- ๐ PDF multi-backend cracking
- ๐ Auto
rockyou.txtdownloader - ๐ Full form-field mapper (auto-detect login form)
- ๐ง AI-assisted password candidate generation
- ๐ Session logging & reports (CSV/HTML)
- โก Multi-threaded config tuning presets
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ ๐ FOR ETHICAL SECURITY AND AUTHORSED TESTS ONLY ๐ โ
โ ๐ฆ SHARK BRUTEFORCE 1.0 ๐ฆ โ
โ Built with ๐ by technicalsuraj2 โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โญ Show love โ star the repo, fork, and share responsibly.
Made with โก by technicalsuraj2 ยท AGSC Developer
