It's worth noting that crypt-ed MD5 (which appears to be what's in use here) is fairly weak on modern hardware when compared to an alternative like BCrypt. There's some basic information available on Wikipedia: http://en.wikipedia.org/w/index.php?title=Crypt_%28Unix%29...
" Graphics processors can speed up password cracking by a factor of 50 to 100 over general purpose computers. As of 2011, commercial products are available that claim the ability to test up to 2,800,000,000 passwords a second on a standard desktop computer using a high-end graphics processor. [3] Such a device can crack a 10 letter single-case password in one day. Note that the work can be distributed over many computers for an additional speedup proportional to the number of available computers with comparable GPUs."
For the other hashes, the fact that there's no nonce or other value stored alongside them was a strong hint (although it doesn't rule out a site-wide nonce). However, I confirmed my suspicion by Googling one of the hashes: it was on a list of unsalted hashes that had been brute forced (unrelated to this, the password was fairly common).
CRYPT_MD5 - MD5 hashing with a twelve character salt starting with $1$
So the hashes you see beginning with $1$ are probably salted.
The $1 is for MD5, the salt includes that $1 and the last $, so to crypt the text in php you do crypt($password, '$1$salt$'). Use single quotes to prevent $ from turning into variables. $password in this case (according to mtgox) was md5('password string').
http://codahale.com/how-to-safely-store-a-password/
[Edit: I meant your typical web application mucking about with salts, not their use within properly thought out things like bcrypt]
Salts will prevent the typical rainbow table attack where you have precomputed hashes for a large number of attempts. Salts won't prevent brute force, but bcrypt will make it so that brute force takes too long for a single given user.