Skip to main content

April 13, 2026

Hash Cracking for CTF: MD5, SHA-1, SHA-256 and Beyond (picoCTF 2026)

Hash cracking for CTF: identify hash types, run hashcat and John the Ripper, use rainbow tables and online lookups, and solve picoCTF 2026 and 2025 hash challenges.

Assorted shapes funnelled into identical fixed-length bars, with one bar held beside a target bar.

Introduction

Hash cracking is one of the most common skills tested in CTF competitions, appearing in cryptography, forensics, and general skills categories alike. A cryptographic hash function takes an input of any length and produces a fixed-length digest. Hash functions are designed to be one-directional: given a hash, you should not be able to recover the original input through a mathematical shortcut. Cracking means finding that input anyway, by computing hashes of candidate inputs until one matches.

The digest length is what identifies the algorithm, and those lengths are fixed by standards. RFC 1321 defines MD5 at 128 bits, which is 32 hex characters, while FIPS 180-4 specifies the SHA family: SHA-1 at 160 bits (40 hex), SHA-256 at 256 (64 hex), and SHA-512 at 512 (128 hex). Counting characters in the string in front of you is therefore not a heuristic, it is a lookup, and it is the first thing to do before opening any tool.

Hash cracking appears in CTF challenges in several forms:

  • A file or challenge description contains a raw hex digest; you must reverse it to a password or flag.
  • A login form in a web challenge stores passwords as MD5 or SHA-1 hashes; cracking the hash lets you log in.
  • A forensics challenge gives you a shadow file or NTLM dump; cracking it recovers the credential.
  • The flag itself is the cracked plaintext, not the hash.

This guide walks through every tool and technique you need: recognizing hash types by their digest length, using online rainbow tables for quick wins, running hashcat and John the Ripper locally for anything not already in a database, and applying a systematic workflow so you never waste time on the wrong approach.

Related guides on this site

Hashes are often base64- or hex-encoded before being presented in a challenge. The encodings guide covers decoding that outer layer. The RSA guide covers the broader cryptography context where hashing is used for digital signatures.

Hash types and recognition

The fastest way to identify an unknown hash is by its length. Each algorithm always produces a fixed number of hex characters (two hex chars per byte). Here is what to look for:

AlgorithmHex charsBytesExample prefix / pattern
MD53216d41d8cd98f00b204...
SHA-14020da39a3ee5e6b4b0d...
SHA-2245628d14a028c2a3a2bc9...
SHA-2566432e3b0c44298fc1c14...
SHA-384964838b060a751ac9638...
SHA-51212864cf83e1357eefb8bd...
NTLM321631d6cfe0d16ae931... (all lowercase)
bcrypt60N/A$2b$12$... (always starts with $2)
sha512cryptvariableN/A$6$salt$... (Linux /etc/shadow)
MD5cryptvariableN/A$1$salt$... (older Linux shadow)

MD5 and SHA-1: broken for collisions, not for cracking

You will often read that MD5 and SHA-1 are "broken". This refers to collision attacks: a researcher can craft two different inputs that produce the same hash. That does not help you crack a hash in a CTF. For CTF purposes, MD5 and SHA-1 are broken in a different and more practical sense: they are fast to compute, so GPUs can test billions of candidates per second, and most common passwords already appear in public databases like CrackStation.

The collision milestones are worth knowing because they are what pushed these algorithms out of standards, not out of CTF. MD5 collisions became practical after Wang and Yu's 2004 result and now take seconds on a laptop. SHA-1 held out longer: SHAttered, announced in February 2017, produced the first SHA-1 collision at a cost of roughly 263.1 hash computations, which the authors put at about 6,500 CPU-years plus 110 GPU-years. By 2020 a chosen-prefix SHA-1 collision was down to tens of thousands of dollars of rented GPU time. None of that helps you invert a digest, which is why a 2017-broken algorithm is still cracked in 2026 the same way it was in 2007: by guessing.

SHA-256 is not broken in either sense. It has no known collision, and it is fast enough that GPU cracking is still feasible. The difference is purely probabilistic: SHA-256 hashes of common passwords are far less likely to appear in pre-computed databases, so you rely on wordlists and rules rather than simple lookup.

bcrypt: intentionally slow

bcrypt is a password hashing scheme designed to be slow, and deliberately so: Provos and Mazieres published it at USENIX in 1999 under the title "A Future-Adaptable Password Scheme", the point being that the cost parameter can be raised as hardware improves. The $2b$12$ prefix means 212 = 4,096 rounds of the Blowfish key setup; each increment of the cost factor doubles the work, so $2b$14$ is four times slower than $2b$12$. A modern GPU can test roughly 20,000 bcrypt candidates per second (versus billions for MD5). In a CTF, bcrypt challenges are almost always solvable with a short wordlist or a top-10000 password list rather than a brute-force mask attack. Online tools like CrackStation will not help you with bcrypt at all: the cost of pre-computing a bcrypt rainbow table is prohibitive.

NTLM hashes from Windows

NTLM is the hash format Windows uses to store local account passwords. NTLM is MD4 of the UTF-16LE password, with no salt and no iteration count, so two users with the same password produce byte-identical hashes and the entire corpus is rainbow-table friendly. It also produces a 128-bit digest, so NTLM hashes look exactly like MD5 hashes (32 lowercase hex chars). The context gives them away: if you extracted them from a Windows SAM dump, a memory image, or a challenge mentioning Windows credentials, assume NTLM and use -m 1000 in hashcat.

Rainbow tables and salting

A rainbow table is a pre-computed lookup structure that maps hash values back to their plaintexts. Instead of storing every hash-to-plaintext pair (which would require enormous storage), rainbow tables use chains of alternating hash and reduction functions to compress billions of entries into a manageable file.

For a CTF player, the practical upshot is simple: sites like CrackStation have already computed the MD5, SHA-1, and SHA-256 hashes of every word in large password lists and every permutation up to a certain length. If the plaintext is a common word or password, you paste the hash and get the answer in under a second.

Why salted hashes defeat rainbow tables

A salt is a random value prepended or appended to the password before hashing: hash(salt + password). Because each user gets a unique salt, a pre-computed table that maps hash("password123") to its plaintext is useless. You would need a separate table for every possible salt, which is not feasible.

The size of the salt decides how infeasible. NIST SP 800-63B requires a salt of at least 32 bits, which multiplies the storage for any pre-computed table by 4.3 billion; bcrypt uses 128 bits, which ends the conversation. The same publication asks for a minimum of 10,000 PBKDF2 iterations and an 8-character minimum password length. The modern recommendation is Argon2, standardised in RFC 9106, which adds a memory cost on top of the time cost specifically to blunt the GPU and ASIC parallelism that makes MD5 cracking trivial. Seeing Argon2 in a challenge tells you the intended solution is not brute force.

In CTF challenges, you can tell whether a hash is salted by the format:

  • A bare 32-character hex string is almost certainly an unsalted MD5. Try CrackStation immediately.
  • A string starting with $1$, $2b$, $5$, or $6$ is a salted hash in Modular Crypt Format. The salt is embedded in the string itself, so hashcat and John the Ripper can extract it automatically.
  • If the challenge provides both a salt and a hash separately, construct the input yourself: echo -n "salthello" | md5sum.

Hashcat

Hashcat is the fastest GPU-accelerated password cracker available. It supports hundreds of hash types via -m mode numbers and several attack modes. When online lookup fails, hashcat is the next tool to reach for.

Installation

# Ubuntu / Debian
sudo apt install hashcat
# macOS (with Homebrew)
brew install hashcat
# Verify GPU is recognized
hashcat -I

The -m flag: hash type numbers

Every hashcat command requires -m <number> to tell it which algorithm to use. The most common values you will need in picoCTF:

-m valueHash typeNotes
0MD5Most common in CTF, also the fastest
100SHA-140 hex chars; also fast
1400SHA-25664 hex chars; slower than MD5 but still GPU-friendly
1700SHA-512128 hex chars; noticeably slower per-candidate
1000NTLMWindows password hashes; same length as MD5
3200bcryptVery slow; use a small targeted wordlist
1800sha512crypt ($6$)Linux shadow file passwords
500MD5crypt ($1$)Older Linux shadow file passwords
10md5($pass.$salt)Hash the password then append salt
20md5($salt.$pass)Prepend salt then hash

Attack mode 0: wordlist (dictionary) attack

The dictionary attack hashes every line in a wordlist and compares against your target. This is the most effective first attempt for any CTF hash. The rockyou.txt wordlist holds over 14 million real-world passwords recovered from the 2009 RockYou breach, and it cracks the majority of CTF hashes.

Compare that to the search space and the reason it works becomes obvious. A wordlist pass over rockyou is 14 million candidates, finishing in under a second against MD5 on any GPU. An exhaustive eight-character brute force over the 95 printable ASCII characters is 958, roughly 6.6 quadrillion candidates, which is 470 million times more work. That ratio is why the correct order is always wordlist, then rules, then mask, and never mask first. The hashcat mode reference lists an example digest for every one of its several hundred hash modes, which is the fastest way to confirm you picked the right -m.

# Basic wordlist attack on an MD5 hash
hashcat -m 0 -a 0 hash.txt /usr/share/wordlists/rockyou.txt
# SHA-256 with rockyou
hashcat -m 1400 -a 0 hash.txt /usr/share/wordlists/rockyou.txt
# bcrypt with a targeted top-passwords list
hashcat -m 3200 -a 0 hash.txt /usr/share/wordlists/rockyou.txt
# hash.txt contains one hash per line:
# 5f4dcc3b5aa765d61d8327deb882cf99

Rule-based attacks

Rules transform each wordlist entry before hashing: capitalize the first letter, append numbers, substitute letters with symbols, etc. Hashcat ships with several built-in rule files. The best64.rule file applies 64 of the most effective transformations and dramatically increases coverage without needing a larger wordlist.

# Apply best64 rules to rockyou wordlist
hashcat -m 0 -a 0 hash.txt /usr/share/wordlists/rockyou.txt -r /usr/share/hashcat/rules/best64.rule
# Stack multiple rule files
hashcat -m 0 -a 0 hash.txt /usr/share/wordlists/rockyou.txt \
-r /usr/share/hashcat/rules/best64.rule \
-r /usr/share/hashcat/rules/toggles1.rule

Attack mode 3: mask (brute-force) attack

A mask attack generates every combination that fits a pattern. Use this when you know the password format (e.g., the flag format tells you the answer is 8 lowercase letters followed by 2 digits).

# Charset placeholders:
# ?l = lowercase a-z
# ?u = uppercase A-Z
# ?d = digits 0-9
# ?s = special characters
# ?a = all printable ASCII
# Brute-force all 6-character lowercase passwords
hashcat -m 0 -a 3 hash.txt ?l?l?l?l?l?l
# 4 digits (PIN brute-force)
hashcat -m 0 -a 3 hash.txt ?d?d?d?d
# Specific pattern: capital + 5 lowercase + 2 digits
hashcat -m 0 -a 3 hash.txt ?u?l?l?l?l?l?d?d
# Increment length from 1 to 8 chars
hashcat -m 0 -a 3 hash.txt --increment --increment-min=1 ?l?l?l?l?l?l?l?l

Useful hashcat flags

--show # Print previously cracked hashes from the potfile
--potfile-path # Use a custom potfile location
-O # Optimized kernel (faster, but max password length limited to 32)
-w 3 # Workload profile: 1=low, 2=default, 3=high, 4=nightmare
--status # Print progress updates while running
--remove # Remove hashes from the input file once cracked

Wordlists beyond rockyou

The SecLists repository (available on GitHub and pre-installed on Kali/Parrot) contains dozens of specialized wordlists. For CTF challenges that hint at a theme (a challenge named after a movie, a sport, a video game), a domain-specific wordlist can crack the hash in seconds.

# Install SecLists
sudo apt install seclists # Kali and Parrot only
git clone --depth 1 https://github.com/danielmiessler/SecLists # everywhere else
# Common locations after install:
/usr/share/seclists/Passwords/Common-Credentials/10-million-password-list-top-1000000.txt
/usr/share/seclists/Passwords/xato-net-10-million-passwords.txt
/usr/share/seclists/Passwords/Leaked-Databases/rockyou-75.txt

John the Ripper

John the Ripper(usually called just "john") is the other major password cracker. It has a simpler interface than hashcat and automatically detects many hash formats, which makes it a good choice when you are not sure what you are dealing with or when you need a quick first attempt.

Installation

sudo apt install john
# For Jumbo formats (zip2john, bcrypt, and hundreds more, recommended for CTF),
# build John the Ripper jumbo from source:
git clone https://github.com/openwall/john -b bleeding-jumbo
cd john/src && ./configure && make -s

Automatic format detection

John can usually detect the hash type without you specifying it. Just point it at a file containing one hash per line:

# Let john detect the format
john hash.txt
# View what formats john detected
john --show hash.txt
# List all supported formats
john --list=formats

Specifying the format manually

When john guesses wrong, or when it is ambiguous (NTLM and MD5 have the same length), force the format:

john --format=raw-md5 hash.txt
john --format=raw-sha1 hash.txt
john --format=raw-sha256 hash.txt
john --format=raw-sha512 hash.txt
john --format=nt hash.txt # NTLM
john --format=bcrypt hash.txt
john --format=sha512crypt hash.txt # $6$ Linux shadow

Wordlist mode

# Use rockyou wordlist
john --wordlist=/usr/share/wordlists/rockyou.txt hash.txt
# With format specified
john --format=raw-sha256 --wordlist=/usr/share/wordlists/rockyou.txt hash.txt

Rule-based mangling

John has a powerful built-in rule engine. The --rules flag applies word-mangling rules to each wordlist entry before hashing. Rules are defined in john.conf and cover capitalization, number suffixes, leet substitution, and more.

# Apply default rules to rockyou
john --wordlist=/usr/share/wordlists/rockyou.txt --rules hash.txt
# Use a specific rule set (defined in john.conf)
john --wordlist=/usr/share/wordlists/rockyou.txt --rules=Jumbo hash.txt

Incremental (brute-force) mode

When wordlists fail, john can try every combination of characters up to a specified length. This is slow but exhaustive for short passwords:

# Brute-force lowercase alpha up to 6 chars
john --incremental=lower hash.txt
# Brute-force digits only
john --incremental=digits hash.txt
# All printable ASCII (very slow beyond 5-6 chars)
john --incremental hash.txt

Cracking shadow files and zip archives

John ships with helper utilities that convert protected file formats into john-compatible hash files. The archive case has enough of its own detail (which ZIP encryption scheme you are facing, and the known-plaintext shortcut that beats brute force outright) that it gets a guide of its own: archive and ZIP password cracking.

# /etc/shadow (Linux password file)
unshadow /etc/passwd /etc/shadow > combined.txt
john --wordlist=/usr/share/wordlists/rockyou.txt combined.txt
# Protected ZIP file
zip2john protected.zip > zip.hash
john --wordlist=/usr/share/wordlists/rockyou.txt zip.hash
# Password-protected PDF
pdf2john document.pdf > pdf.hash
john --wordlist=/usr/share/wordlists/rockyou.txt pdf.hash

Online lookup tools

For unsalted MD5, SHA-1, and SHA-256 hashes, online tools can return the plaintext instantly if the password is common. Always try these first before spinning up hashcat, since they are zero-effort and cover millions of real-world passwords.

CrackStation

The most comprehensive free lookup database. Contains over 15 billion entries covering MD5, SHA-1, SHA-256, and several others. Handles up to 20 hashes at once. URL: crackstation.net

What it can crack:

  • MD5, SHA-1, SHA-256, SHA-512, LM, NTLM, MySQL4.1
  • Common English words, names, passwords from major leaks (RockYou, LinkedIn, Adobe)
  • Simple variations: password123, P@ssw0rd, etc.

What it cannot crack:

  • bcrypt hashes (computationally infeasible to pre-compute)
  • Any salted hash format ($1$, $2b$, $5$, $6$)
  • Obscure or randomly-generated passwords not in its wordlists
  • MD5 of a custom string like a CTF flag format (picoCTF{...})

hashes.com

A community-driven hash lookup and cracking service. You can submit hashes to their queue and receive email notification when cracked. Also has a free instant lookup that covers MD5 and NTLM. Useful for NTLM hashes from Windows challenges.

MD5Hashing.net / md5decrypt.net

Smaller databases focused on MD5. Good as a second check if CrackStation misses something. They maintain separate databases contributed by their users over the years.

Niph.net / sha1.online

SHA-1 focused lookup databases. Use after CrackStation returns no result.

Identifying the hash type

When you are handed an unknown digest, you need to determine the algorithm before you can crack it. The two main tools for this are hashid and hash-identifier.

hashid (Python-based)

pip install hashid
# Identify a single hash
hashid 5f4dcc3b5aa765d61d8327deb882cf99
# Output:
# Analyzing '5f4dcc3b5aa765d61d8327deb882cf99'
# [+] MD2
# [+] MD5
# [+] MD4
# Use -m to show hashcat mode numbers
hashid -m 5f4dcc3b5aa765d61d8327deb882cf99
# Use -j to show john format names
hashid -j 5f4dcc3b5aa765d61d8327deb882cf99

hash-identifier (Kali built-in)

hash-identifier
# (interactive: paste hash at the prompt)
# Or pipe it in:
echo '5f4dcc3b5aa765d61d8327deb882cf99' | hash-identifier

Browser-based tool on this site

If you prefer not to install anything, this site has a hash identification tool that runs entirely in your browser:

/tools/hash-identifier

Manual identification by length

In practice, counting the hex characters is usually faster than running a tool. Check the quick reference table at the bottom of this page for a one-look guide.

Decision workflow

Follow this numbered sequence every time you encounter a hash in a CTF challenge. It is ordered from fastest to slowest so you do not waste compute time:

  1. 1

    Identify the hash type

    Count the hex characters and check against the reference table. Run hashid -m <hash> to confirm and get the hashcat mode number. Look for dollar-sign prefixes ($2b$, $6$) that immediately reveal the algorithm and salt.

  2. 2

    Check if it is salted

    Bare hex = likely unsalted. Dollar-sign format = salted. If salted, skip step 3 and go straight to hashcat or John (they can read the embedded salt automatically).

  3. 3

    Try online lookup (unsalted only)

    Paste into CrackStation. If it returns a result, you are done. This takes under 10 seconds and works on the majority of CTF hashes. For NTLM, also try hashes.com.

  4. 4

    Run hashcat with rockyou wordlist

    hashcat -m <mode> -a 0 hash.txt /usr/share/wordlists/rockyou.txt. This covers 14 million real passwords and completes in seconds for MD5/SHA-1.

  5. 5

    Add rules to the wordlist attack

    Append -r best64.rule to catch variations like Password1, p@ssword, HELLO123. Then try rockyou-30000.rule for broader coverage.

  6. 6

    Try SecLists specialized wordlists

    Use domain-specific lists if the challenge hints at a theme. A challenge called "Star Wars" probably uses a character name or quote as the password.

  7. 7

    Mask attack if you know the password format

    If the challenge hints at a format (e.g., "the answer is a 4-digit PIN" or the flag format gives you length information), use hashcat -a 3 with the appropriate mask.

  8. 8

    Re-read the challenge for hints

    If nothing has worked, the challenge itself probably contains a hint about the password. Look for names, dates, challenge descriptions, filenames, or any string that could be the answer. Try hashing those strings yourself to verify the algorithm.

picoCTF hash challenges to practise on

These challenges are solved directly with the techniques above. Each writeup walks through the identification, tool selection, and exact commands used. The 2026 set is worth doing first: it is where picoCTF stopped asking you to run hashcat and started asking whether you understood what a hash actually is.

picoCTF 2026

None of these three crack a hash with a wordlist, and that is the point. Every one of them fails if your entire hash playbook is hashcat -m 0 -a 0.

A profile URL ends in 32 hex characters. Identifying it as MD5 takes two seconds and gets you nowhere, because the digest is not a password. It is MD5 of the numeric user ID, so guessing the preimage and hashing it yourself lets you forge any other user URL. The lesson that identification names the algorithm but never the input is the single most useful thing on this page.

Secure Password Database

Secure Password Database (2026)

The binary checks a hash that no identifier will ever recognise: a homebrew polynomial rolling hash, total = total * 33 + byte. No hashcat mode exists for it. You recover the algorithm in Ghidra and then compute the expected value directly. Custom hashes are common in reversing challenges, and the workflow in this post routes you to Ghidra rather than to a wordlist.

Credential Stuffing

Credential Stuffing (2026)

The other side of the rainbow-table story. Here you are handed the breach dump itself and replay the pairs against a login service. It is the practical reason every wordlist in this post starts with rockyou: those are real passwords that real people reused.

picoCTF 2025

The classic wordlist-and-rules progression, in increasing difficulty.

A direct hash cracking challenge where you are given a digest and must recover the plaintext. Demonstrates the full workflow: identify the algorithm by length, check CrackStation, and fall back to hashcat with rockyou if needed. A great introductory challenge for understanding hash cracking mechanics.

An introduction to hashing where you encounter a salted or formatted hash and must determine the correct hashcat mode. Covers recognizing hash format from context and using John with the correct format flag.

The harder follow-up. Requires either a rule-based attack or a mask attack after the basic wordlist fails. The challenge hints in the description narrow down the password structure, making the mask approach viable.

General approach for the 2025 set

# Step 1: identify the hash (count hex chars or use hashid)
hashid -m <paste-hash-here>
# Step 2: try CrackStation (browser) for fast win
# Step 3: hashcat with rockyou if online fails
hashcat -m <mode> -a 0 hash.txt /usr/share/wordlists/rockyou.txt
# Step 4: add rules if plain wordlist fails
hashcat -m <mode> -a 0 hash.txt /usr/share/wordlists/rockyou.txt \
-r /usr/share/hashcat/rules/best64.rule
# Step 5: view cracked result
hashcat -m <mode> hash.txt --show

Quick reference

Hash recognition table

Hash typeHex charsHashcat -mJohn formatCrackable online?
MD5320raw-md5Yes (CrackStation)
SHA-140100raw-sha1Yes (CrackStation)
SHA-224561300raw-sha224Sometimes
SHA-256641400raw-sha256Sometimes
SHA-5121281700raw-sha512Sometimes
NTLM321000ntYes (hashes.com)
bcrypt ($2b$)60 (full string)3200bcryptNo
sha512crypt ($6$)varies (full string)1800sha512cryptNo
MD5crypt ($1$)varies (full string)500md5cryptNo

Essential hashcat commands

GoalCommand
MD5 + rockyou wordlisthashcat -m 0 -a 0 hash.txt rockyou.txt
SHA-256 + rockyou + ruleshashcat -m 1400 -a 0 hash.txt rockyou.txt -r best64.rule
bcrypt + targeted listhashcat -m 3200 -a 0 hash.txt rockyou.txt
4-digit PIN brute-forcehashcat -m 0 -a 3 hash.txt ?d?d?d?d
6 lowercase lettershashcat -m 0 -a 3 hash.txt ?l?l?l?l?l?l
Show cracked resultshashcat -m 0 hash.txt --show
NTLM + rockyouhashcat -m 1000 -a 0 hash.txt rockyou.txt

Essential John commands

GoalCommand
Auto-detect + wordlistjohn --wordlist=rockyou.txt hash.txt
Force MD5 formatjohn --format=raw-md5 --wordlist=rockyou.txt hash.txt
With rulesjohn --wordlist=rockyou.txt --rules hash.txt
Brute-force lowercasejohn --incremental=lower hash.txt
Show cracked passwordsjohn --show hash.txt
Linux shadow fileunshadow passwd shadow > c.txt; john c.txt

All picoCTF hash cracking writeups

Sources and further reading

Digest lengths, salt requirements, and cost parameters are all specified numbers. These are where they come from.

Run it in the browser

Tools on this site that do the work described above. No install, nothing uploaded: they run entirely in your browser.

Try it on these picoCTF challenges

Walkthroughs that put this technique to work, grouped by event.

Keep reading

Guides that build on the same ideas, plus the roadmap this topic sits under.