I'm no expert, but I think it works something like:
A hacker steals hashed passwords from a vulnerable website.
From a list of potential passwords like password, 12345, trustno1, etc, the hacker hashes each of them with hashing methods commonly used by web sites.
If a match is found, the hacker...