Looking for cloud-based phone profiles? Check out our technical analysis of GeeLark. Discover GeeLark

MD5 Hash Generator

0 of 0 ratings
Everything is calculated in your browser. Your text and files are not uploaded and nothing is stored.
With a key you get HMAC values instead of plain hashes. The key stays in your browser.
Calculate
SHA-384 and SHA-512 are several times slower in a browser. Untick what you do not need for big files.

Hashes

Subresource Integrity (SHA-384)
The button copies the whole attribute for a script or link tag.

Compare with a given hash

Paste the checksum you were given: hex, Base64, or a whole line like “abc123… file.iso”.

Check against common passwords

A hash cannot be decrypted, but weak passwords can be guessed. This compares your hash with the hashes of the 10,000 most common passwords, in your browser.

MD5 Hash Generator and Checker Online

Create the MD5 hash of any text or file, or check whether a file matches the MD5 checksum you were given. The calculation runs in your browser: your text and files are not uploaded anywhere. Besides MD5 the page shows SHA-1, SHA-256, SHA-384 and SHA-512 of the same data.

How to get the MD5 of a text or a file

  1. Type or paste the text: the MD5 appears at once, as 32 hexadecimal characters.
  2. For a file open the File tab and drop the file (up to 2 GB).
  3. To verify a download, paste the MD5 from the vendor’s site into the Compare box: you see a green check mark or a red cross.

Example: the MD5 of hello is 5d41402abc4b2a76b9719d911017c592, the MD5 of an empty text is d41d8cd98f00b204e9800998ecf8427e.

What is MD5?

MD5 (Message-Digest Algorithm 5) was designed by Ronald Rivest in 1991 and described in RFC 1321. It turns data of any size into a 128-bit value, written as 32 hexadecimal characters. The data is padded and split into 512-bit blocks, and every block goes through 64 steps in four rounds of simple operations (additions, rotations, logical functions) that mix it into a four-word state; the final state is the hash. For many years MD5 was the standard way to check file integrity and to store passwords.

Is MD5 secure?

No, not against an attacker. In 2004 researchers found how to create two different messages with the same MD5 (a collision), and the attacks became cheap enough to run on a laptop. In 2008 researchers used MD5 collisions to create a fake certificate authority certificate, and in 2012 the Flame malware used an MD5 collision to forge a Microsoft certificate. Because of this browsers reject certificates signed with MD5, and MD5 must not be used for digital signatures, certificates or any protection against deliberate tampering.

MD5 is still acceptable where nobody attacks it: detecting accidental corruption of a download or a backup, cache keys and ETags, finding duplicates, splitting data between servers. For everything that has to resist an attacker use SHA-256.

MD5 and passwords

Never store passwords as a plain MD5. MD5 is extremely fast, so a single graphics card can test billions of guesses per second, and databases of precomputed MD5 hashes of common passwords are public. Use a slow salted algorithm such as bcrypt or Argon2. If you inherited an MD5 password database, re-hash each password with a modern algorithm when the user next logs in.

MD5 decrypt: can an MD5 hash be reversed?

No. MD5 is a one-way function, not encryption: the original text cannot be calculated from the hash, because a hash of 128 bits holds far less information than the text. Sites that offer “MD5 decryption” only look the hash up in huge tables of hashes that were calculated in advance for common words and passwords, or try guesses. That is why a long random password, or a hash with a unique salt, cannot be “decrypted” this way.

The check against common passwords box on this page does the same thing in its simplest form, locally in your browser: it calculates the MD5 (or SHA-1, SHA-256, ...) of each of the 10,000 most common passwords and tells you if one of them produces your hash. If the hash is not found, it does not mean that it is safe, only that the password is not one of the most common ones.

MD5, MD4, MD2 and the other “MD” algorithms

MD5 has two older relatives. MD2 (1989) was designed for 8-bit computers and is slow and weak; the IETF moved it to Historic status in RFC 6149. MD4 (1990) is the predecessor of MD5. The MD4 algorithm is considered completely obsolete, compromised and insecure. In today’s world its use for any data protection or cryptographic task is strictly unacceptable. The IETF also moved MD4 to Historic status (RFC 6150). It survives only inside legacy systems such as the old Windows NTLM password hash, which is one of the reasons NTLM is considered weak. There is no MD4 or MD2 generator on this site, because there is no good reason to use them. The newer MD6 (2008) was never adopted.

How to check the MD5 of a file

Use the File tab, or the command line:

SystemCommand
Linuxmd5sum file.iso, sha1sum file.iso, sha256sum file.iso
macOSmd5 file.iso, shasum -a 1 file.iso, shasum -a 256 file.iso
Windows PowerShellGet-FileHash file.iso -Algorithm MD5 (or SHA1, SHA256, SHA384, SHA512)
Windows Command Promptcertutil -hashfile file.iso SHA256
Any system with OpenSSLopenssl dgst -sha256 file.iso

Paste the result and the checksum from the vendor’s page into the Compare box to see whether they match. If the MD5 differs, download the file again; if it still differs, do not use it.

MD5 vs SHA-256

MD5 produces 128 bits, SHA-256 produces 256 bits. MD5 is a little faster but has broken collision resistance, SHA-256 has no known practical attack. Publishing a SHA-256 next to a download is the modern standard; MD5 is still published by many vendors for compatibility with old tools, and is fine for catching a damaged download.

Frequently asked questions

How long is an MD5 hash?

Always 32 hexadecimal characters (128 bits), no matter how big the text or file is. In Base64 it is 24 characters ending with ==.

Is MD5 a hash or an encryption?

A hash. Encryption can be reversed with a key, a hash cannot be reversed at all.

Why does my MD5 differ from the one in the terminal?

Usually because of a line break: echo adds one, echo -n does not. Use the switches under the text field to match the terminal. The text is hashed as UTF-8 and exactly as typed.

Is it safe to enter text here?

Yes. Nothing leaves your browser.

Similar tools

Hash Generator: MD5, SHA-1, SHA-256, SHA-512

Free online hash generator: MD5, SHA-1, SHA-256, SHA-384 and SHA-512 of a text or a file up to 2 GB, HMAC, checksum comparison and SRI values. Calculated in your browser, nothing is uploaded.

18
SHA-256 Hash Generator

Free online SHA-256 hash generator: SHA-256 and HMAC-SHA256 of a text or a file up to 2 GB, compare with a given checksum. Calculated in your browser, nothing is uploaded.

13
SHA-1 Hash Generator

Free online SHA-1 hash generator: SHA-1 of a text or a file up to 2 GB, compare with a given checksum. Calculated in your browser, nothing is uploaded.

11

Popular tools