{% extends "base.html" %} {% block content %}

Free Password Hash Cracker

Enter up to 20 non-salted hashes, one per line:

Supports: LM, NTLM, md2, md4, md5, md5(md5_hex), md5-half, sha1, sha224, sha256, sha384, sha512, ripeMD160, whirlpool, MySQL 4.1+ (sha1(sha1_bin)), QubesV3.1BackupDefaults

{% if let Some(error) = error %}

{{ error }}

{% endif %} {% endblock %} {% block wide %} {% if let Some(results) = results %} {% let summary = crate::cracking::ResultSummary::of(results) %}
{% for result in results %} {% if result.format_error %} {% else if result.matches.is_empty() %} {% else %} {% for m in result.matches %} {% if m.is_full_match() %} {% else %} {% endif %} {% endfor %} {% if result.is_truncated() %} {% endif %} {% endif %} {% endfor %}
hashes: {{ summary.hashes }} cracked: {{ summary.cracked }} partial: {{ summary.partial }} not found: {{ summary.not_found }} invalid: {{ summary.invalid }}
HashTypeResult
{{ result.hash }}UnknownUnrecognized hash format.
{{ result.hash }}UnknownNot found.
{{ result.hash }}{{ m.algorithm_name }}{{ m.plaintext_html()|safe }}
{{ m.matched_prefix() }}{{ m.unmatched_rest() }}{{ m.algorithm_name }}{{ m.plaintext_html()|safe }}
{{ result.hash }} {{ result.hidden_matches_grouped() }} more not shown (of {{ result.total_matches_grouped() }} total).
{% endif %} {% endblock %} {% block tail %}
{% if self.results.is_some() %}

Color Codes: Green: Exact match, Yellow: Partial match — the hash column shows what that word really hashes to, with the part yours matched highlighted, Red: Not found.

{% endif %}
Download CrackStation's Wordlist 1,493,677,782 words · 15 GB · torrent or HTTP Command-Line Tool for Local Index Generation & Lookup $ cargo install preimage

How CrackStation Works

CrackStation uses massive pre-computed lookup tables to crack password hashes. These tables store a mapping between the hash of a password, and the correct password for that hash. The hash values are indexed so that it is possible to quickly search the database for a given hash. If the hash is present in the database, the password can be recovered in a fraction of a second. This only works for "unsalted" hashes. For information on password hashing systems that are not vulnerable to pre-computed lookup tables, see our hashing security page.

Crackstation's lookup tables were created by extracting every word from the Wikipedia databases and adding every password list we could find. We also applied intelligent word mangling (brute force hybrid) to our wordlists to make them much more effective. For MD5 and SHA1 hashes, we have a 190GB, 15-billion-entry lookup table, and for other hashes, we have a 19GB 1.5-billion-entry lookup table.

You can download CrackStation's dictionaries here, the lookup table implementation (PHP and C) is available here, and a modern Rust implementation that can be used as either a library or a command-line tool is available here.

{% endblock %}