Hash Recovery by Dictionary Attack

Recover the input of a hash by testing a list of common words and their variants, on your own hashes or in an authorized context. Everything is local.

Only use this on your own hashes or in an authorized context. A hash cannot be “decrypted”: candidates are tested and compared.

Rules

    100% local processing, nothing is uploaded

    How does it work?

    Paste one or more hashes, choose the algorithm, then a word list: your own and/or the provided list of the most common passwords. The tool computes the hash of each word (with optional rules: capitalization, appended digits, “leet” substitutions) and compares it with the targets. The work is spread across several cores, in workers: the interface never freezes.

    It is by far the most effective method in practice, because most compromised passwords are common words or simple variants. A known salt is supported. Nothing is uploaded: words, hashes and results stay on your device.

    Examples

    A common password

    The MD5 hash e10adc3949ba59abbe56e057f20f883e matches “123456”, which is in the provided list: it is found almost instantly among the ~160 words tested.

    A variant found with a rule

    With the “+ two digits” rule, the word “sunshine” generates “sunshine00” to “sunshine99” (101 candidates). “sunshine42” is found even though it is not in the list as is.

    Frequently asked questions

    Does this “decrypt” the hash?
    No, and that is impossible: a hash is one-way. The tool computes the hash of candidates (words from a list, or combinations) and compares it with the target. If none matches, nothing is found.
    Am I allowed to use this tool?
    Only on your own hashes, or in an explicitly authorized context (security audit, penetration test with written consent). Trying to recover someone else’s password without authorization is illegal. Everything happens locally: nothing is sent or stored.
    Is my data sent anywhere?
    No. All the computation happens in your browser, in JavaScript and WebAssembly. Your text, your files and your hashes never leave your device: no network request is made during hashing, and nothing is stored on a server.