- Home
- Security Operations
- Offensive Security
- Hash Extender
Hash Extender
Hash Extender is a command-line tool that automates length extension attacks against various hashing algorithms including MD5, SHA-1, SHA-256, and others.

Hash Extender
Hash Extender is a command-line tool that automates length extension attacks against various hashing algorithms including MD5, SHA-1, SHA-256, and others.
Hash Extender Description
Hash Extender is a command-line tool developed by Ron Bowes that implements length extension attacks against multiple hashing algorithms. The tool supports attacks against MD4, MD5, RIPEMD-160, SHA-0, SHA-1, SHA-256, SHA-512, and WHIRLPOOL hash functions. Length extension attacks exploit a vulnerability in certain hash functions where an attacker can append data to an original message and compute the hash of the extended message without knowing the original message content. Hash Extender simplifies the process of performing these cryptographic attacks by automating the complex mathematical operations required. The tool takes the original hash, known data, and additional data to append as inputs, then generates the extended hash and the complete message that would produce that hash. This functionality makes it useful for penetration testing scenarios where hash length extension vulnerabilities need to be identified and exploited in web applications or other systems that use vulnerable hash functions for authentication or integrity verification.
FEATURED
Password manager with end-to-end encryption and identity protection features
VPN service providing encrypted internet connections and privacy protection
Fractional CISO services for B2B companies to accelerate sales and compliance
Stay Updated with Mandos Brief
Get the latest cybersecurity updates in your inbox
TRENDING CATEGORIES
POPULAR
Security platform that provides protection, monitoring and governance for enterprise generative AI applications and LLMs against various threats including prompt injection and data poisoning.
A threat intelligence aggregation service that consolidates and summarizes security updates from multiple sources to provide comprehensive cybersecurity situational awareness.
Fabric Platform is a cybersecurity reporting solution that automates and standardizes report generation, offering a private-cloud platform, open-source tools, and community-supported templates.
A weekly newsletter providing cybersecurity leadership insights, industry updates, and strategic guidance for security professionals advancing to management positions.