// the find
s0md3v/Hash-Buster
Crack hashes in seconds.
Hash Buster is a single-file Python 3 script that identifies a hash's type from its length and looks it up against third-party online hash databases. It suits people triaging leaked dumps or config files who want quick answers for common unsalted MD5, SHA1, or SHA-2 values, not a local cracker.
Type detection is by hex length, and for this scope that is sound: 32, 40, 64, 96 and 128 hex characters map to MD5, SHA1, SHA256, SHA384 and SHA512 with no overlap, so auto-detection never has to guess between candidates. The file mode does the useful work, pulling hashes out of arbitrary text by pattern, so a hash inside a JSON blob or surrounded by other characters still gets found, which is what you want when sorting through a dump. The whole tool is one hash.py, a makefile and a requirements file, so the full lookup path can be read in a few minutes, which matters for a tool that sends data off the machine.
Every lookup is a network request to a third-party service, so results are only as good as those databases. Anything salted, or never posted to those sites, comes back as a miss, and there is no offline or brute-force fallback. The README's 'under 3 seconds' describes network latency on a good day, not a property of the tool. Privacy is the real bite: the -d and -f modes sweep whatever directory you point them at and send every hash they find to outside APIs, and the README only suggests reading the source if you are paranoid. For a tool that will be aimed at client data or a home directory, that warning should be the first thing a user reads. Maintenance is thin: the last push was December 2024, the visible tree has no test directory, and I saw no caching or rate-limit handling, so a large batch against a throttled API will fail in ways the README does not describe.