Skip to content

John the Ripper

Fast password cracking tool for recovering weak passwords from hashes.

Self-hostedNot yet verified
Report issueDemo online
MIT★ 12000

Open the official app on www.openwall.com

This tool is hosted by its maintainers. Click below to open www.openwall.com in a new tab — it's their official demo.

Browse security tools →

What's next with John the Ripper?

Choose how you want to get started.

Use it free

Open the official tool or demo — no account needed.

Free

Self-host it

Run the open-source version on your own infrastructure.

Open

What is John the Ripper?

John the Ripper is an open-source password cracking tool designed for security auditing and password recovery. It enables users to test the strength of passwords by cracking hashes derived from user credentials, network traffic, or encrypted files. The tool is widely used by cybersecurity professionals, penetration testers, and system administrators to identify vulnerabilities in password policies and ensure compliance with security standards. By simulating attacks like dictionary attacks, brute-force methods, and rule-based guessing, John the Ripper helps organizations assess the risk of weak or compromised passwords. Its primary purpose is to strengthen security by exposing weak passwords before they are exploited by malicious actors.

How it works

John the Ripper is a GPLv2-licensed password cracking tool developed by Openwall. It supports over 200 hash and cipher types, including Unix, Windows, and database credentials. The tool is primarily used to audit password security by cracking hashes from files like /etc/shadow or network captures. Its purpose is to evaluate the effectiveness of password policies and recover lost credentials. By testing systems against common attack vectors, it helps organizations preemptively identify and mitigate security risks. John the Ripper can crack hashes from Unix/Linux systems (e.g., Linux, BSD, Solaris), Windows, and web applications like WordPress. It also supports network protocols (e.g., WiFi WPA-PSK) and encrypted keys (SSH, GnuPG). The tool leverages GPU acceleration for faster cracking and includes built-in wordlists for dictionary attacks.

How to use it

  1. 1Clone the repository from GitHub (openwall/john) and install dependencies like OpenSSL and CUDA libraries. 2. Prepare hash files (e.g., /etc/shadow) or capture network traffic in formats like pcap. 3. Run the tool using command-line options, specifying the hash type (e.g., --format=raw-md5). 4. Use wordlists or custom rules to guide the cracking process. Practical tips: Prioritize hash types with known weaknesses, leverage GPU acceleration for speed, and ensure compliance with legal frameworks when testing systems.

What it can do

  • password cracking

Use cases

Assumptions and limitations

Assumptions

  • source: https://github.com/openwall/john
  • license: GPL-2.0 — free to use
  • privacy: Self-hosted — you control your data

Limitations

  • Dual-use tool — use only with explicit authorization on systems you own or have permission to test.
  • Requires direct access to hash files or encrypted data, which may not be available in real-world scenarios
  • Cracking time increases exponentially with password complexity and entropy
  • Limited support for newer cryptographic algorithms compared to tools like Hashcat
  • Depends on precomputed wordlists, which may not cover obscure or custom passwords

Understanding the result

Fast password cracking tool for recovering weak passwords from hashes.

Tool details

  • Clearly flagged when a network request is needed.
  • No account, no sign-up, and no tracking of your content.
  • Powered by (MIT).
Built with
(openwall/john)
License
MIT
Runs locally
No — requires a network request
Verification
Not yet verified
Input
Query
Output
Text
Open-source source & license

Built with openwall/john. OpenToolVault provides the discovery and browser interface while crediting the original project maintainers.

Built with
License
MIT
View source on GitHub

Open-source project

OpenToolVault is an independent directory. We are not affiliated with or endorsed by this project.

References

Frequently asked

What is John the Ripper used for?

John the Ripper is used for password auditing and recovery. It tests the strength of passwords by cracking hashes from files like /etc/shadow, network captures, or encrypted credentials. It helps organizations identify weak passwords and improve security policies before breaches occur.

How does John the Ripper crack passwords?

The tool uses dictionary attacks (matching hashes to precomputed wordlists), brute-force methods (trying all character combinations), and rule-based mutations (applying transformations to dictionary words). It supports GPU acceleration for faster processing and can handle modern cryptographic functions like yescrypt and yespower.

How do I run John the Ripper on a Linux system?

Clone the repository from GitHub (git clone https://github.com/openwall/john), install dependencies like OpenSSL and CUDA, then execute the tool with commands like john --format=raw-md5 hashes.txt. Use --help for format-specific options and ensure hash files are properly formatted.

How does John the Ripper compare to Hashcat?

John the Ripper focuses on traditional hash types (e.g., MD5, SHA-1) and integrates with Unix tools, while Hashcat excels at modern cryptographic functions (e.g., bcrypt, SHA-256) and offers more advanced GPU acceleration. John the Ripper is better for system-level audits, whereas Hashcat is optimized for cracking encrypted files and network protocols.

How do I troubleshoot hash format errors?

Verify the hash format matches the target system (e.g., --format=ldap for Active Directory). Check for typos in hash files and ensure compatibility with the tool's supported types. Use john --list=formats to list valid formats and adjust parameters accordingly.

Spotted something wrong with John the Ripper, or want to maintain it? See how to help.