Dictionary Hash Cracker
Recover plaintexts by hashing each word in a wordlist and comparing against your target — supports MD5, NTLM, SHA-1 and SHA-256. Runs entirely in your browser on your own wordlist.
Runs locally: each word is hashed and compared against your target. Only for recovering hashes you own or are authorized to test. Larger wordlists (e.g. rockyou.txt) work — the browser just gets slower.
Crack an MD5 hash
Crack the MD5 hash of “password” against the small built-in wordlist and reveal the plaintext.
The MD5 of “password” is 5f4dcc3b5aa765d61d8327deb882cf99, which is in the default wordlist — so the example succeeds immediately.
FAQ
Is it legal to use this?
Only use it on hashes you own or are explicitly authorized to test. Cracking someone else’s credentials without permission is illegal, so restrict this to your own systems or staged challenges.
Why sometimes does it find nothing?
A dictionary attack only succeeds if the plaintext is actually in your wordlist. Hashes with random salt, strong unique passwords, or slow KDFs like bcrypt/Argon2 won’t be cracked this way.
Which algorithms can it handle?
MD5, NTLM, SHA-1 and SHA-256. For others, use the Hash Identifier to inspect the algorithm, then a dedicated tool like hashcat.
Is my hash sent anywhere?
No. Every word is hashed and compared locally in your browser. Larger lists like rockyou.txt simply make the browser work harder.