Skip to content

Crack Station

Online hash cracking service with a large precomputed wordlist database for recovering plaintext passwords.

Not yet verified
Demo online
MIT

Open the official app on crackstation.net

This tool is hosted by its maintainers. Click below to open crackstation.net in a new tab — it's their official demo.

Browse security tools →

What's next with Crack Station?

Choose how you want to get started.

Use it free

Open the official tool or demo — no account needed.

Free

Self-host it

Run the open-source version on your own infrastructure.

Open

What is Crack Station?

CrackStation is a password hash cracking tool designed to recover plaintext passwords from unsalted cryptographic hashes using precomputed rainbow tables. It supports algorithms like MD5, SHA1, Linux hashes, and others, enabling users to identify weak or compromised passwords. Security professionals, developers, and penetration testers use it to assess password security, audit systems, and test the resilience of password storage mechanisms. The tool addresses the problem of recovering passwords from hashes that lack cryptographic salts, which are vulnerable to precomputed lookup attacks. By leveraging massive databases of hashed passwords and wordlists, CrackStation provides a resource-efficient method for cracking hashes without requiring brute-force computation.

How it works

CrackStation is an online service that cracks password hashes by matching them against precomputed rainbow tables. These tables map cryptographic hashes to their corresponding plaintext passwords, allowing instant recovery when a hash exists in the database. The tool's primary purpose is to demonstrate the vulnerabilities of unsalted password hashing and assist in security audits. It is not intended for malicious use but serves as an educational resource for understanding password security risks. CrackStation supports a wide range of hash types, including MD5, SHA1, Linux hashes, and variations like md5(md5_hex) and sha1(sha1_bin). It also processes hashes from databases such as Wikipedia and integrates wordlists with intelligent mangling to enhance cracking effectiveness.

How to use it

  1. 1Visit CrackStation's website and navigate to the hash cracking interface. 2. Paste up to 20 unsalted hashes into the input area, ensuring each hash is on a separate line. 3. Select the hash type from the provided options (e.g., MD5, SHA1). 4. Submit the hashes and wait for the tool to match them against its database. 5. Retrieve the plaintext passwords from the results section. Practical tips: Verify hash formats match supported types, avoid submitting salted hashes, and use the downloadable wordlist for offline analysis if required.

What it can do

  • online hash cracker

Use cases

Assumptions and limitations

Assumptions

  • source: https://crackstation.net/
  • license: Proprietary — free to use
  • privacy: Opens an external demo

Limitations

  • Dual-use tool — use only with explicit authorization on systems you own or have permission to test.
  • Cannot crack salted hashes or modern cryptographic algorithms like bcrypt, scrypt, or Argon2.
  • Requires precomputed tables for specific hash types, limiting support for niche or custom algorithms.
  • Dependent on the completeness of its rainbow tables, which may not cover all possible password combinations.
  • Limited to 20 hashes per session, requiring batch processing for large datasets.

Understanding the result

Online hash cracking service with a large precomputed wordlist database for recovering plaintext passwords.

Tool details

  • Clearly flagged when a network request is needed.
  • No account, no sign-up, and no tracking of your content.
  • Powered by (MIT).
Built with
(https://crackstation.net/)
License
MIT
Runs locally
No — requires a network request
Verification
Not yet verified
Input
Query
Output
Text
Open-source source & license

Built with https://crackstation.net/. OpenToolVault provides the discovery and browser interface while crediting the original project maintainers.

Built with
License
MIT
View source on GitHub

Open-source project

OpenToolVault is an independent directory. We are not affiliated with or endorsed by this project.

References

Frequently asked

What types of hashes does CrackStation support?

CrackStation supports a variety of hash algorithms, including MD5, SHA1, Linux hashes, MySQL 4.1+, and variants like md5(md5_hex) and sha1(sha1_bin). It also processes hashes from databases such as Wikipedia and integrates with wordlists for hybrid attacks.

How does CrackStation perform hash cracking?

CrackStation uses precomputed rainbow tables that map cryptographic hashes to their plaintext counterparts. When a user submits a hash, the tool searches its database for a matching entry. If found, the plaintext password is returned instantly. This method relies on the existence of the hash in the precomputed tables, making it efficient for unsalted hashes but ineffective against salted or modern cryptographic hashes.

How do I submit hashes to CrackStation?

Navigate to CrackStation's hash cracking interface, paste your hashes into the input area (one per line), select the appropriate hash type from the dropdown menu, and click 'Submit.' The tool will then search its database for matching plaintext passwords and display the results.

How does CrackStation compare to tools like Hashcat or John the Ripper?

CrackStation relies on precomputed rainbow tables, while tools like Hashcat and John the Ripper use brute-force or dictionary-based methods. CrackStation is optimized for unsalted hashes and requires existing tables, whereas Hashcat and John the Ripper can generate or compute hashes on-the-fly. CrackStation is best suited for educational purposes or legacy hash types, while Hashcat and John the Ripper offer greater flexibility for diverse password cracking scenarios.

What should I do if CrackStation cannot find a match for my hash?

If CrackStation fails to find a match, consider the following: 1. Verify the hash format and ensure it matches supported types. 2. Check if the hash is salted or uses a modern algorithm like bcrypt, which CrackStation cannot crack. 3. Use the downloadable wordlist for offline analysis or try alternative tools like Hashcat. 4. If the hash is from a custom system, you may need to generate your own rainbow tables or use a different cracking method.

Spotted something wrong with Crack Station, or want to maintain it? See how to help.