Tooleux

DES Decrypt

DES (2)

Decrypt a Base64 ciphertext produced by DES Encrypt.

Runs in your browser. Nothing leaves your device.
Decrypt DES or Triple DES ciphertext in your browser. Legacy compatibility only. Read more Show less
Legacy algorithms. This tool decrypts data produced by DES Encrypt or any tool that follows the same format. For new encryption, use AES-GCM or ChaCha20-Poly1305.

What is DES Decrypt?

This tool reverses the encryption performed by DES Encrypt. It reads a Base64 string containing the salt, IV, and ciphertext, derives the key from your password using PBKDF2-SHA-256, and decrypts with DES or Triple DES in CBC mode with PKCS#7 padding.

How to use

Paste the Base64 ciphertext, enter the same password, choose the matching variant, press Decrypt.

If the ciphertext has been corrupted or the password is wrong, decryption will fail or produce garbage. Unlike AEAD ciphers (AES-GCM, ChaCha20-Poly1305), DES-CBC has no authentication tag, so the tool cannot tell you whether the output is genuine - only whether the padding is valid. Treat any decrypted output as untrusted.

Why does decryption produce garbage?

DES-CBC has no integrity check. A wrong password produces a full-length output of random bytes, which the tool will decode as text with replacement characters. If you see mojibake, the password is wrong.

If you see a padding error, either the password is wrong, the variant (DES vs Triple DES) is wrong, or the ciphertext was truncated or modified.

FAQ

Can I verify a password before decrypting?

Not with CBC alone. If you need verifiable decryption, use AES-GCM or ChaCha20-Poly1305 - those ciphers include an authentication tag.

Can I decrypt OpenSSL output?

Only if it uses the same format. OpenSSL's default password mode uses EVP_BytesToKey with MD5, which is different from PBKDF2. If you have OpenSSL ciphertext, use openssl enc -d -des-ede3-cbc directly.

Is the decrypted output safe to trust?

Only if you trust the sender, the password, and the transport that delivered the ciphertext. DES-CBC does not protect against tampering.

Command line equivalent
# OpenSSL 3.x
echo "U2FsdGVkX1..." | openssl enc -d -des-ede3-cbc -k "password" -pbkdf2 -iter 100000 -base64

# Node with crypto-js
node -e 'const C = require("crypto-js");
const bytes = C.TripleDES.decrypt(ciphertext, "password");
console.log(bytes.toString(C.enc.Utf8));'
Loads a test value into the form
Ciphertext
Plaintext