Crack the leaked password DB — before a salt and a slow KDF close the door

You have a stolen copy of two password stores for the same users — one unsalted MD5, one salted with a real (if simplified) iterated KDF. Same 101-word dictionary, same real MD5 running underneath both. Watch what actually changes.

Store A — unsalted MD5

Store B — salted + iterated KDF

What actually ran (every candidate really hashed, no shortcuts):

Recovered

Store A — unsalted, fast

Store B — salted, iterated