The short answer
- Linux account hashes live in
/etc/shadow, readable by root only. The hash is the second colon-separated field. - The prefix tells you the algorithm:
$1$md5crypt,$5$sha256crypt,$6$sha512crypt,$2b$bcrypt,$y$yescrypt. - Submit only the hash field, not the whole line. OHC detects the format from the prefix.
- md5crypt falls fastest, sha512crypt is much slower, and bcrypt and yescrypt are slower still.
Authorized use only. This guide is for security testing and recovery on systems and data you own or are explicitly authorized to test.
On Linux, local account password hashes are stored in /etc/shadow. This guide shows how to read the right field, identify the algorithm from the hash prefix and submit the hash to OnlineHashCrack for recovery.
Where Linux stores password hashes
Each line of /etc/shadow describes one account. Fields are separated by colons, and the second one is the password hash:
user:$6$salt$hash:19000:0:99999:7:::
Only root can read the file. As an administrator of your own system, print the line of one account:
sudo grep '^username:' /etc/shadow
A hash field that is only ! or * means the account cannot log in with a password, so there is nothing to recover.
Identify the algorithm from the prefix
The characters between the first two dollar signs name the algorithm. Do not assume what your distribution uses: read the prefix.
| Prefix | Algorithm | Hashcat mode |
|---|---|---|
| none (13 chars) | DES crypt | 1500 |
$1$ | md5crypt | 500 |
$5$ | sha256crypt | 7400 |
$6$ | sha512crypt | 1800 |
$2a$, $2b$, $2y$ | bcrypt | 3200 |
$y$ | yescrypt | 36100 |
Older distributions default to md5crypt or sha512crypt. Recent Fedora, Ubuntu and Arch releases default to yescrypt, which is intentionally memory-hard and far slower to attack than the others on this list.
Submit the hash
Copy only the hash field, between the second and third colons, and paste it as-is: OnlineHashCrack reads the prefix and selects the matching hashcat mode automatically. Nothing else from the /etc/shadow line is needed.
Recovery speed differs sharply by algorithm. md5crypt is the fastest to test, sha256crypt and sha512crypt repeat their round many times by design, and bcrypt and yescrypt add a deliberate memory cost on top. A short, predictable password is found quickly whichever algorithm is in use; a long random one may not be recoverable at all against the slower formats.
Hash extracted?Paste the hash and OHC detects md5crypt, sha512crypt, bcrypt or yescrypt and starts the attack on its GPUs.
Linux password hashes: frequently asked questions
Where does Linux store password hashes?
In /etc/shadow, which only root can read. Each line is one account, and the second colon-separated field is the password hash.
How do I know which algorithm a Linux hash uses?
Read its prefix: $1$ is md5crypt, $5$ is sha256crypt, $6$ is sha512crypt, $2a$, $2b$ or $2y$ is bcrypt and $y$ is yescrypt. A 13-character hash with no prefix is the old DES crypt.
Which hashcat mode matches each Linux hash?
Mode 500 for md5crypt, 7400 for sha256crypt, 1800 for sha512crypt, 3200 for bcrypt, 1500 for DES crypt and 36100 for yescrypt in the OHC registry.
What does a ! or * in the hash field mean?
The account has no usable password login, either because it is locked or because it never had a password. There is nothing to recover in that case.
Why are sha512crypt and bcrypt so much slower to crack than md5crypt?
They repeat the hash many more times, or, for bcrypt and yescrypt, need memory and time on purpose. That slows each guess, which is exactly what they are designed to do.
Further reading
Related guides on Online Hash Crack: