# How CUPP Handles Name Reversal for Password Variations

> Discover how CUPP efficiently handles name reversal for password variations, generating extensive candidate lists by reversing strings and combining them with numbers and characters.

- Repository: [Mebus/cupp](https://github.com/Mebus/cupp)
- Tags: internals
- Published: 2026-07-03

---

**CUPP automatically reverses user names, nicknames, and family members' names using Python slice notation `[::-1]`, then combines these reversed strings with years, special characters, and random numbers to generate extensive password candidate lists.**

CUPP (Common User Passwords Profiler) is an open-source password dictionary generator maintained in the Mebus/cupp repository that creates targeted wordlists from personal information gathered via interactive prompts or profile files. One of its most effective techniques for expanding candidate coverage is **name reversal**, which transforms strings like "alice" into "ecila" and mixes these reversed tokens with dates and symbols to capture common user behaviors.

## How Name Reversal Works in cupp.py

### Generating Reversed Strings at Lines 336‑343

The reversal logic executes immediately after CUPP collects profile data. The tool applies Python's slice notation `[::-1]` to flip each name field character-by-character, preserving both lowercase and title-case variants:

```python

# cupp.py – lines 336‑343

rev_name   = profile["name"][::-1]      # e.g., "alice" → "ecila"

rev_nameup = nameup[::-1]               # capitalised version

rev_nick   = profile["nick"][::-1]
rev_nickup = nickup[::-1]
rev_wife   = profile["wife"][::-1]
rev_wifeup = wifeup[::-1]
rev_kid    = profile["kid"][::-1]
rev_kidup  = kidup[::-1]

```

This generates eight distinct reversed strings covering the victim's name, nickname, spouse's name, and child's name in both casing formats.

### Storing Reversed Variants at Lines 364‑366

These reversed values are collected into a dedicated list named `reverse` for later permutation:

```python

# cupp.py – lines 364‑366

reverse = [
    rev_name, rev_nameup, rev_nick, rev_nickup,
    rev_wife, rev_wifeup, rev_kid, rev_kidup,
]

```

## Combining Reversed Names with Password Patterns

CUPP feeds the `reverse` list into its generic combination engine (`komb`) alongside years and special characters. At lines 618‑623, the tool generates permutations such as reversed-name + year (e.g., `ecila1999`) and reversed-name + underscore + year:

```python

# cupp.py – lines 618‑623

kombi[17] = list(komb(reverse, years))
kombi[17] += list(komb(reverse, years, "_"))
if profile["randnum"] == "y":
    kombi[21] = list(concats(reverse, numfrom, numto))

```

When the `-r`/`--randnum` flag is enabled, `kombi[21]` appends numeric suffixes ranging from `numfrom` to `numto` to each reversed string, producing candidates like `ecila123`.

## Practical Usage Examples

You can observe name reversal in action using interactive mode or programmatically via the Python API.

To generate a wordlist interactively:

```bash

# Interactive mode – answer the prompts

$ python3 cupp.py -i
First Name: alice
Nickname: al
Spouse name: bob
Child's name: carl
... (other prompts)

# The generated file (alice.txt) will contain entries such as:

# ecila          (reversed first name)

# Ecila1999      (reversed first name + year)

# ecila!         (reversed first name + special character)

# ecila123       (reversed first name + random number)

# 321carl        (reversed child name + random number)

```

To use the reversal logic programmatically:

```python

# Programmatic use – reuse the core function

from cupp import read_config, generate_wordlist_from_profile

# Load configuration

read_config("cupp.cfg")

# Build a profile dictionary

profile = {
    "name": "alice",
    "nick": "al",
    "wife": "bob",
    "kid": "carl",
    "surname": "", "wifen": "", "kidn": "", "pet": "", "company": "",
    "spechars1": "n", "randnum": "y", "leetmode": "n",
    "birthdate": "01021990", "wifeb": "", "kidb": ""
}
generate_wordlist_from_profile(profile)

# → creates “alice.txt” with reversed‑name variations included

```

## Summary

CUPP implements name reversal as a systematic expansion technique for password profiling:

- **String reversal** uses Python's `[::-1]` slice on name, nickname, spouse, and child fields at lines 336‑343 of [`cupp.py`](https://github.com/Mebus/cupp/blob/main/cupp.py)
- **Case preservation** generates both lowercase and title-case variants (e.g., `ecila` and `Ecila`)
- **List aggregation** stores all reversed variants in the `reverse` list at lines 364‑366
- **Pattern combination** merges reversed strings with years, underscores, and random numbers via the `komb()` function at lines 618‑623
- **Output integration** includes reversed-name candidates in the final deduplicated wordlist written to disk

## Frequently Asked Questions

### Does CUPP reverse every name field provided in the profile?

Yes, according to the source code in [`cupp.py`](https://github.com/Mebus/cupp/blob/main/cupp.py), CUPP reverses the victim's name, nickname, spouse's name, and child's name. It processes both the original casing and title-case versions, creating eight reversed base strings total that serve as seeds for further permutation.

### What Python technique does CUPP use to reverse strings?

CUPP utilizes Python's extended slice notation `[::-1]` to reverse strings in-place. This idiomatic approach appears at lines 336‑343 where fields like `profile["name"][::-1]` produce backward character sequences without requiring additional imports or loops.

### How does CUPP combine reversed names with other personal data?

The tool passes the `reverse` list to the `komb()` combination engine, which concatenates these strings with years, special characters, and separators. For example, lines 618‑623 generate entries like `ecila1999` (reversed name + birth year) and `ecila_2024` (reversed name + underscore + year).

### Can I disable name reversal when generating wordlists?

No, the current implementation in Mebus/cupp does not provide a configuration flag to disable name reversal specifically. The reversal logic at lines 336‑366 executes automatically for all profiles, though you can manually filter the output file if specific patterns are not required.