Hashes, identification and cracking
Identify a digest by shape, understand why hashing is one-way, and learn where wordlist cracking works and where it is a trap.
Assumes1. Recognising encodings
By the end you can
- Identify a hash from its length and prefix, and name the ambiguities that length alone cannot resolve
- Explain the difference between encoding, encryption, and hashing
- Crack a fast unsalted hash with a wordlist and rule transforms
- Recognise a deliberately slow hash and choose a different approach
- Extend a Merkle-Damgard MAC without knowing the secret, and say which constructions stop that
1. Read
Hash cracking that actually works: identify, wordlist, rules, mask
Cracking is a search problem, and most failed attempts are searches aimed at the wrong space. How to identify a hash from its shape, choose between wordlist, rules, and mask attacks, and recognise the hashes you should not be brute-forcing at all.
Hash length extension: appending to a message you cannot read
Why MD5, SHA-1 and SHA-256 let you forge a valid `H(secret || message || padding || yours)` without ever knowing the secret, how to recognise a vulnerable MAC construction on sight, and which hashes are immune.
2. Use the tools
In the order they come up while solving. Read what each one does, or go straight to the workspace tab that runs it.
- Hash identifier with hashcat mode lookup
Identify a hash from its shape and prefix - MD5, SHA family, bcrypt, NTLM, and the salted formats - and get the hashcat mode number to crack it.
Open it in the workspace - MD5, SHA-1 and SHA-256 hash generator
Compute MD5, SHA-1, SHA-256, SHA-384, and SHA-512 of any text in the browser, using Web Crypto. Nothing is sent anywhere.
Open it in the workspace - In-browser hash cracker with rule transforms
Crack MD5, SHA-1, SHA-256, SHA-384, and SHA-512 against a wordlist in your browser, with leetspeak, case, reversal, and digit-append rules.
Open it in the workspace - SHA-3, BLAKE2, Keccak and RIPEMD calculator
Compute the hash functions outside the standard set - SHA-3, Keccak, BLAKE2, and RIPEMD-160 - when SHA-2 does not match.
Open it in the workspace - Hash length extension attack
Append data to a message and forge a valid MD5, SHA-1, or SHA-256 signature without knowing the secret - the Merkle-Damgard flaw behind `hash(secret || message)`.
Open it in the workspace
3. Try one now
Generated in your browser and checked in your browser. No account, nothing to download, and a fresh one whenever you want another.
4. Practise on the real thing
Real picoCTF challenges that use these techniques, easiest first. 17 match in total - see the full index.
Common mistakes
The wrong turns this topic reliably produces. Written as the mistake rather than the rule, because the rule is easy to agree with and easy to walk straight past.
- Reading 32 hex characters as 'MD5' rather than as 128 bits, which NTLM, MD4 and a truncated digest also produce.
- Cracking a bcrypt or Argon2 hash because the tool accepted it. The cost parameter is in the string, and it is telling you the password is somewhere else in the challenge.
- Forgetting the salt is part of the input. A rule set that cracks the unsalted corpus finds nothing once a per-user salt is in play.
- Running rockyou against a hash whose plaintext is a flag. Flags are not in any wordlist - the route is a mask over the known format, a prefix plus a small varying tail, and a dictionary run only proves the tool works.
- Reading `H(secret || message)` as a signature. Over a Merkle-Damgard hash that construction extends without the secret, which is the whole reason HMAC exists and is the first thing to check before attacking the key.
Checkpoint
Identify an unknown digest, justify the identification, then crack it - or argue from the algorithm why cracking is the wrong path.
Teaching note
The valuable outcome is the negative one: students should leave able to say 'this is bcrypt, so the password is somewhere else in the challenge'. That judgement is worth more than any successful crack.
Go deeper
The lessons above are written to get you through a challenge. These go after the subject instead. Each one opens our notes on that chapter - what it argues, what to take from it and where it stops - so this is somewhere to read now rather than a book to buy first. Nothing here is affiliate-linked or sold by us.
Chapter 5, Cryptography
Designing Secure Software - Loren Kohnfelder
Separates the three properties a hash is asked for - preimage, second preimage, collision - so 'broken' stops being one word.
Chapter 7, Forensic Image Management
Practical Forensic Imaging - Bruce Nikkel
Hashing used for integrity rather than secrecy, which is the other half of what a digest is for and the half CTFs rarely show.
Chapter 13, Network Authentication
Windows Security Internals - James Forshaw
Where the NTLM hashes people crack actually come from, and why a captured challenge-response is not the same object as a stored digest.
Every book the curriculum cites has a page in the library.