Skip to main content

weakpass-lookup

A Python script that queries the Weakpass API to attempt cracking various types of password hashes (NTLM, MD5, SHA1, SHA256). This tool is particularly helpful for cracking NTLM hashes obtained via DCSync in a Windows Domain environment, though it supports several other hash types as well.

Features

  • Generic search: No need to specify the hash type (supports NTLM, MD5, SHA1, SHA256).
  • Bulk processing: Reads hashes from a file and checks them concurrently using multiple worker threads.
  • Single hash processing: Checks a single hash without needing a file.
  • Verbose mode: Provides additional debug output to help with troubleshooting.
  • Debug mode: Rich-formatted tracebacks and HTTP details for local/dev troubleshooting.

Installation

It is recommended to install weakpass-lookup using pipx (preferred) or pip.

Using pipx (Recommended)

pipx install weakpass-lookup

Make sure you have pipx installed and set up on your system.

Using pip

pip install weakpass-lookup

Usage

usage: weakpass-lookup [-h] (-f FILE | -H HASH) [-w WORKERS] [-v] [-d]

Searches hashes in the Weakpass API

optional arguments:
  -h, --help            show this help message and exit
  -f FILE, --file FILE  File with list of hashes (one per line)
  -H HASH, --hash HASH  Individual hash to search
  -w WORKERS, --workers WORKERS
                        Number of threads to use (default: 10)
  -v, --verbose         Verbose mode to show more debugging details
  -d, --debug           Debug mode with tracebacks and HTTP details (use only in local/dev)

Examples

  1. Crack a single hash:

    weakpass-lookup --hash <HASH_VALUE>
    
  2. Crack multiple hashes from a file (default 10 threads):

    weakpass-lookup --file /path/to/hashes.txt --workers 10
    
  3. Use verbose mode for debugging:

    weakpass-lookup --file /path/to/hashes.txt --verbose
    
  4. Detailed debug:

    weakpass-lookup --hash <HASH_VALUE> --debug
    

Output

  • When processing a file:

    • <filename>_cracked.txt: Stores all cracked hashes in <hash>:<password> format.
    • <filename>_uncracked.txt: Stores all remaining uncracked hashes.
  • When processing a single hash:

    • Prints the result (cracked or uncracked) directly to the terminal.

Contributing

  1. Fork the project.
  2. Create a new feature branch (git checkout -b feature/my-feature).
  3. Commit your changes (git commit -m 'Add some feature').
  4. Push to the branch (git push origin feature/my-feature).
  5. Open a Pull Request.

License

This project is licensed under the MIT License. Feel free to use, modify, and distribute it as per the terms of the license.


Happy cracking with weakpass-lookup!

Release files for weakpass-lookup 0.1.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for weakpass-lookup 0.1.1
File Size Uploaded
weakpass_lookup-0.1.1.tar.gz 6.2 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for weakpass-lookup 0.1.1
File Interpreter ABI Platform
weakpass_lookup-0.1.1-py3-none-any.whl Python 3 none any Details

Total release size: 13.1 kB

Release files / weakpass_lookup-0.1.1.tar.gz

Download URL weakpass_lookup-0.1.1.tar.gz
Size 6.2 kB
Tags Source
SHA-256 checksum
How to use checksums
0b782fdb553a69cd428c6bf0ecb5ce31a3ac0f3cd0f2c43ddd519d0338065921
BLAKE2b-256 checksum
How to use checksums
4300cd33714023a5324833635ab8eab8e100735e7e4f61d73cbe663cd8aef7b2
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.12.9

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 17, 2025.

Transparency log

Release files / weakpass_lookup-0.1.1-py3-none-any.whl

Download URL weakpass_lookup-0.1.1-py3-none-any.whl
Size 6.9 kB
Tags Python 3
SHA-256 checksum
How to use checksums
5a091c1b5cce37149c50387bb4556f71d10a1d13d5aa1c2cd259cf2d53d00e48
BLAKE2b-256 checksum
How to use checksums
214d8361f55fa5d3f714ce562599e3f514f19adcf229b318ad07b23e741ef6f0
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.12.9

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 17, 2025.

Transparency log

Release history Release notifications | RSS feed

This release

0.1.1 This release

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page