Protected By Tyrant Softwares
OverviewThe Common AlgorithmsHow Passwords Get CrackedUsing the EDX Hash CrackerSalting and Slow HashesToolsDisclaimer

Hashing Algorithms

Overview

A hash function takes any input, a password, a file, a message, and produces a fixed-length fingerprint that is practically impossible to reverse. Change one character of the input and the hash changes completely. That combination, easy to compute one way, infeasible to undo, is what makes hashing useful for storing passwords, checking file integrity, and signing data.

Hashing is not encryption. Encryption is designed to be reversed with a key. A hash is a one-way fingerprint: there is no key and no undo, only guessing inputs until one produces the same hash.

The Common Algorithms

MD5: fast, old, and broken for security purposes. Collisions, two different inputs with the same hash, can be produced cheaply. It remains common for non-security checksums and in older breached databases.

SHA-1: also collision-broken. It should no longer be used for signatures or certificates.

SHA-256 and SHA-512: the SHA-2 family, and the current general-purpose standard. They are still considered collision-resistant. Their weakness for passwords is speed: because they are fast to compute, an attacker can guess billions of candidates per second on a GPU.

Password hashes (bcrypt, scrypt, Argon2): deliberately slow, usually by design requiring memory as well as CPU time. They are built for one job, storing passwords, and anything serious should use them for it.

The key idea: an algorithm being unbroken is not the same as it being right for the job. SHA-256 is excellent for file integrity and poor for password storage, purely because it is too fast.

How Passwords Get Cracked

When a database is breached, the attacker usually holds a list of hashes, not passwords. Cracking means running guesses through the same hash function and looking for matches. Three techniques do almost all the work:

Dictionary attacks: try a list of likely passwords, real words, leaked passwords from other breaches, keyboard patterns. This succeeds because people reuse memorable passwords.

Rule-based mutations: apply transformations to dictionary words, capitalise the first letter, append a number, swap a for 4. Password1 becomes password1 then Password1 then Password123 within seconds of guessing.

Brute force: try every combination up to a length. It is guaranteed against short passwords and hopeless against long random ones, which is exactly why length matters more than clever substitution.

Using the EDX Hash Cracker

The Hash Cracker page on EDX runs a real cracking session in your browser. Choose an attack mode, dictionary, rules, or full dictionary plus rules plus brute force, paste a hash, and start. The tool shows candidates per second, which guesses were tried, and how long the attack took.

The point of the tool is the lesson, not the result: watching a seven-character password fall in seconds, and seeing a long random one survive everything, teaches more about password strength than any checklist. Everything runs on your device, and nothing is sent anywhere.

Try it with your own hashes. Generate one from a weak password you have used before, and one from a long passphrase, and compare how each fares.

Salting and Slow Hashes

A salt is random data added to each password before hashing and stored alongside the hash. It does not make a single password harder to guess, but it defeats precomputed tables and makes attackers crack every account individually instead of the whole database at once.

Slow hashes go further. bcrypt, scrypt, and Argon2 are tuned to cost real time and memory per guess, cutting billions of guesses per second down to thousands or fewer. Combined with a unique salt, this is the correct modern recipe for storing passwords. If a service can send you your password back in plain text, it never hashed it at all, and that tells you everything about how it stores your data.

Tools

The following tools are commonly associated with this topic for research, testing, and defense:

Hash Cracker

Live dictionary, rule, and brute-force demo, available on the Hash Demo page.

Hash Generators

MD5, SHA-1, SHA-256, SHA-512, and Base64 generators in the EDX toolkit.

Related Reading

See the Cryptography guide for the wider picture of encryption and key exchange.

Disclaimer

This guide is for educational purposes only. Only crack hashes you own or have permission to test. Do not use this knowledge for malicious activities. Always follow the law and ethical guidelines.