Real dictionary attack with rule-based mutations and brute-force — see exactly how passwords get cracked
Just tries the 10,000 most common passwords as-is. Fast but only catches weak passwords.
The tool tried real password cracking techniques against your hash:
Dictionary attack: Hashes each word from a list of 10,000 common passwords and compares it to the target. Catches passwords like "password", "qwerty", "monkey".
Rule-based mutations: Takes each dictionary word and generates variations — capitalizing, appending numbers, leetspeak, reversing, doubling. This catches "Password1", "p@ssw0rd", "monkey123" even though they're not in the original list.
Brute force: Tries every possible combination of characters up to a certain length. Catches short passwords like "ab", "x9", "test" regardless of whether they're in any dictionary. Gets exponentially slower with each additional character.
Estimated time for a modern GPU (10 billion hashes/sec):
MD5 and SHA1 have known collision attacks — they should NEVER be used for password storage. Use bcrypt, scrypt, or Argon2 instead. A salt (random data per password) prevents rainbow table attacks. But even with a salt, a weak password will still be cracked — the salt doesn't slow down dictionary or brute-force attacks.