Skip to content

Glossary

Brute-force attack

A brute-force attack tries every possible password in a keyspace, one by one, until it finds a match — guaranteed to work eventually, but only fast when the keyspace is small.

A brute-force attack systematically tries every possible candidate password against a hash, rather than guessing from a list. Given enough time it is guaranteed to find the password, because it eventually covers the entire keyspace — but "enough time" is the catch. A short, all-lowercase password falls in seconds; add uppercase, digits and length, and the same exhaustive search can outlast the hardware running it.

In practice, tools rarely brute-force blindly. A mask attack narrows the search to a known structure (say, four digits followed by four letters), which is still brute force but over a far smaller keyspace than "anything up to 12 characters." A wordlist attack skips brute force almost entirely, testing real-world passwords instead of every combination.

How fast a brute-force attack runs depends entirely on the hash: raw MD5 or NTLM crack at billions of guesses per second on a GPU, while a deliberately slow hash like bcrypt or sha512crypt can drop that to a few thousand — see why fast hashes are dangerous for why that difference matters so much.