MD5 (Message-Digest Algorithm 5) is a cryptographic hash function that produces a 128-bit (16-byte) digest, conventionally shown as 32 hexadecimal characters. Designed by Ronald Rivest in 1991 and specified in RFC 1321, it was once the most widely used hash on the web before being thoroughly broken as a security tool.
MD5 processes input in 512-bit blocks and always produces the same 16-byte digest regardless of input length, in principle behaving like any other one-way hash function: deterministic output, and (originally) computational infeasibility of finding two inputs that hash to the same value.
Example:
MD5("abc") = 900150983cd24fb0d6963f7d28e17f72
That collision resistance is exactly what failed. In 2004, Wang, Feng, Lai, and Yu published a practical method for generating MD5 collisions, and by 2007–2008 researchers demonstrated chosen-prefix collisions — crafting two files with attacker-chosen, meaningfully different content that still hash identically. This was later used to forge a rogue certificate authority certificate (2008) and, notoriously, by the Flame malware (2012) to forge a Microsoft code-signing certificate. MD5 has not been considered safe for any security-relevant use since.