Tooleux

Compute the MD4 (RFC 1320) hash of any input.

Runs in your browser. Nothing leaves your device.
Calculate MD4 hashes of text in your browser. Legacy compatibility only. Free, offline, runs entirely client-side. Read more Show less

What is MD4?

MD4 (Message Digest 4) is a cryptographic hash function designed by Ron Rivest in 1990 for 32-bit machines. It produces a 128-bit (16-byte) digest. It is defined in RFC 1320.

MD4 is cryptographically broken. Collisions can be computed in milliseconds on a modern laptop. It survives because a few legacy systems still reference it - NTLM password hashing, some old PKI signatures, and rsync's --checksum option by default. Never use it for new systems; use SHA-256 or BLAKE3 instead.

How to compute MD4

Type or paste your input. Choose the input encoding (UTF-8, hex, or Base64). For example, the UTF-8 string abc produces:

a448017aaf21d8525fc10ae87aa6729d

A bit about the algorithm

MD4 operates on a 128-bit state (four 32-bit words) initialized to fixed constants. The message is padded with a single 0x80 byte, zeros, and a 64-bit length, to a multiple of 64 bytes. Each 64-byte block is processed in three rounds of 16 operations each, using bitwise operations that were chosen to run fast on 32-bit CPUs (the design predates widespread 64-bit computing).

MD5 was designed as MD4 with an additional fourth round and slightly different constants, in response to early cryptanalytic progress. That extra round was not enough - MD5 is also broken.

FAQ

Where is MD4 still used?

Three places keep it alive: NTLM (Windows LAN Manager authentication - used for compatibility with very old systems), some PKCS#1 v1.5 RSA signatures in legacy certificates, and rsync's default checksum algorithm (which is not really about security, only about detecting accidental corruption). Modern rsync uses xxHash.

Is MD4 faster than SHA-256?

Yes, significantly. On a 32-bit CPU, MD4 was faster than any hash of its era. It is still fast on modern hardware. That speed is precisely why it is unsafe - an attacker can test billions of candidate inputs per second.

Can I reverse MD4?

No. Like all hashes, MD4 is one-way. You can only compute the hash of an input; you cannot recover the input from the hash. Collision attacks let you find two different inputs with the same hash - a different problem from recovering a specific input.

MD4 vs MD5

MD5 is MD4 with a fourth round and slightly different constants. Both are broken. MD5 has been more widely deployed and is therefore more visible in legacy systems. Neither should be used for new work.

Why does my hash not match another tool?

Check input encoding (UTF-8 vs hex vs Base64), trailing whitespace or a newline at the end of the input, and whether the other tool is applying a different algorithm. A single character difference changes the entire digest.

Command line equivalent
# Python
python3 -c 'import hashlib; print(hashlib.new("md4", b"abc").hexdigest())'
# (may need: pip install hashlib-md4 or use passlib)

# OpenSSL (in the "legacy" provider on OpenSSL 3+)
openssl dgst -md4 file.txt
# OpenSSL 3.0+: openssl dgst -provider legacy -md4 file.txt

# Node with js-md4
npm i js-md4
node -e 'const md4 = require("js-md4"); console.log(md4("abc"))'

# hash-wasm (in this project)
node --input-type=module -e 'import { md4 } from "hash-wasm"; console.log(await md4("abc"))'
Loads a test value into the form
Input
MD4