DES Decrypt
Decrypt a Base64 ciphertext produced by DES Encrypt.
Decrypt DES or Triple DES ciphertext in your browser. Legacy compatibility only. Read more Show less
What is DES Decrypt?
This tool reverses the encryption performed by DES Encrypt. It reads a Base64 string containing the salt, IV, and ciphertext, derives the key from your password using PBKDF2-SHA-256, and decrypts with DES or Triple DES in CBC mode with PKCS#7 padding.
How to use
Paste the Base64 ciphertext, enter the same password, choose the matching variant, press Decrypt.
If the ciphertext has been corrupted or the password is wrong, decryption will fail or produce garbage. Unlike AEAD ciphers (AES-GCM, ChaCha20-Poly1305), DES-CBC has no authentication tag, so the tool cannot tell you whether the output is genuine - only whether the padding is valid. Treat any decrypted output as untrusted.
Why does decryption produce garbage?
DES-CBC has no integrity check. A wrong password produces a full-length output of random bytes, which the tool will decode as text with replacement characters. If you see mojibake, the password is wrong.
If you see a padding error, either the password is wrong, the variant (DES vs Triple DES) is wrong, or the ciphertext was truncated or modified.
FAQ
Can I verify a password before decrypting?
Not with CBC alone. If you need verifiable decryption, use AES-GCM or ChaCha20-Poly1305 - those ciphers include an authentication tag.
Can I decrypt OpenSSL output?
Only if it uses the same format. OpenSSL's default password mode uses EVP_BytesToKey with MD5, which is different from PBKDF2. If you have OpenSSL ciphertext, use openssl enc -d -des-ede3-cbc directly.
Is the decrypted output safe to trust?
Only if you trust the sender, the password, and the transport that delivered the ciphertext. DES-CBC does not protect against tampering.
Command line equivalent
# OpenSSL 3.x
echo "U2FsdGVkX1..." | openssl enc -d -des-ede3-cbc -k "password" -pbkdf2 -iter 100000 -base64
# Node with crypto-js
node -e 'const C = require("crypto-js");
const bytes = C.TripleDES.decrypt(ciphertext, "password");
console.log(bytes.toString(C.enc.Utf8));'