Protected By Tyrant Softwares

Hash Cracker

Real dictionary attack with rule-based mutations and brute-force — see exactly how passwords get cracked

How it works: pick an attack mode, paste a hash you own, and start the session to watch real cracking techniques run at speed. Try it with a weak password and a long random one to see the difference. Want to understand what salting and slow hashes change? Read the hashing guide.
Educational tool. Only crack hashes you own or have permission to test. Uses your browser's CPU — no data leaves your device.
Dictionary (10k words)
Dictionary + Rules
Brute Force (1-4 chars)
Full Attack (all)

Just tries the 10,000 most common passwords as-is. Fast but only catches weak passwords.

Cracking... 0%

What You Just Saw

The tool tried real password cracking techniques against your hash:

Dictionary attack: Hashes each word from a list of 10,000 common passwords and compares it to the target. Catches passwords like "password", "qwerty", "monkey".

Rule-based mutations: Takes each dictionary word and generates variations — capitalizing, appending numbers, leetspeak, reversing, doubling. This catches "Password1", "p@ssw0rd", "monkey123" even though they're not in the original list.

Brute force: Tries every possible combination of characters up to a certain length. Catches short passwords like "ab", "x9", "test" regardless of whether they're in any dictionary. Gets exponentially slower with each additional character.

Time to Crack vs Password Length

Estimated time for a modern GPU (10 billion hashes/sec):

Why This Matters

MD5 and SHA1 have known collision attacks — they should NEVER be used for password storage. Use bcrypt, scrypt, or Argon2 instead. A salt (random data per password) prevents rainbow table attacks. But even with a salt, a weak password will still be cracked — the salt doesn't slow down dictionary or brute-force attacks.

Protect Yourself