How CUPP Handles Partner and Child Information in Password Generation

CUPP collects partner and child details—names, nicknames, and birthdates—during interactive profiling, then slices these values into fragments and combines them with the victim's data using the komb() function to generate family-based password candidates.

The Common User Passwords Profiler (CUPP) is an open-source tool in the Mebus/cupp repository designed to create targeted wordlists for password security auditing. When operating in interactive mode, CUPP explicitly requests information about the victim's partner and children to enhance prediction accuracy. Understanding how CUPP handles partner and child information in password generation reveals why family-based passwords like alice1992 or john_jr08 appear frequently in generated dictionaries.

Collecting Partner and Child Data in Interactive Mode

CUPP's interactive() function in cupp.py (lines 306-338) prompts the user for six specific fields related to family members. These inputs are normalized to lowercase and stored directly in the profile dictionary alongside the primary victim's data.

For the partner (spouse), CUPP captures:

profile["wife"]   = input("> Partners) name: ").lower()
profile["wifen"]  = input("> Partners) nickname: ").lower()
profile["wifeb"]  = input("> Partners) birthdate (DDMMYYYY): ")

For children, the pattern follows similarly:

profile["kid"]    = input("> Child's name: ").lower()
profile["kidn"]   = input("> Child's nickname: ").lower()
profile["kidb"]   = input("> Child's birthdate (DDMMYYYY): ")

All six values persist in the same profile dictionary that contains the victim's own biographical data, ensuring seamless integration during the generation phase.

Extracting Date Fragments for Family Members

Inside generate_wordlist_from_profile() (lines 403-424), CUPP processes birthdate strings into multiple numeric fragments. This slicing logic applies identically to the victim, partner, and child dates, creating versatile components for password construction.

For the partner's birthdate stored in profile["wifeb"]:

wifeb_yy   = profile["wifeb"][-2:]   # Last 2 digits (year)

wifeb_yyy  = profile["wifeb"][-3:]   # Last 3 digits

wifeb_yyyy = profile["wifeb"][-4:]   # Full year

The child's birthdate undergoes identical processing:

kidb_yy    = profile["kidb"][-2:]
kidb_yyy   = profile["kidb"][-3:]
kidb_yyyy  = profile["kidb"][-4:]

These fragments populate the wbdss (partner dates) and kbdss (child dates) lists, which later feed into the combination engine alongside month and day extractions.

Building Name Pools with kombinaw and kombinak

Before generating passwords, CUPP constructs specialized name pools for family members (lines 438-452). The system creates title-cased variants alongside the original lowercase values to account for common capitalization patterns.

The partner name pool (kombinaw) includes:

wifeup    = profile["wife"].title()    # "alice" becomes "Alice"

wifenup   = profile["wifen"].title()
surnameup = profile["surname"].title()

kombinaw = [
    profile["wife"],    # lowercase name

    profile["wifen"],   # lowercase nickname

    wifeup,             # title case name

    wifenup,            # title case nickname

    profile["surname"], 
    surnameup,
]

The child name pool (kombinak) follows an identical structure using kid, kidn, and their title-cased variants (kidup, kidnup). These pools ensure that password candidates cover variations like alice92, Alice92, and ALICE92.

Combining Data with the komb() Function

The final password generation occurs in lines 866-894, where CUPP feeds the family name pools into the komb() helper function. This utility concatenates each name element with date fragments, special characters, and numeric suffixes to produce comprehensive candidate lists.

For partner combinations:

kombi[2] = list(komb(kombinaw, wbdss))          # Partner names + partner dates

kombi[2] += list(komb(kombinaw, wbdss, "_"))    # With underscore separator

For child combinations:

kombi[3] = list(komb(kombinak, kbdss))          # Child names + child dates

kombi[3] += list(komb(kombinak, kbdss, "_"))    # With underscore separator

The komb() function systematically joins each element from the name pools (kombinaw or kombinak) with each element from the corresponding date lists (wbdss or kbdss). After generation, CUPP deduplicates the results, applies length constraints, optionally applies leet-speak transformations, and writes the final output to the wordlist file.

Summary

  • CUPP stores family data in the same profile dictionary as the victim's information, using keys wife, wifen, wifeb, kid, kidn, and kidb.
  • Date fragmentation extracts 2-digit, 3-digit, and 4-digit year components from partner and child birthdates to create flexible numeric suffixes.
  • Name pools (kombinaw and kombinak) include both lowercase and title-cased versions of names, nicknames, and surnames to maximize pattern coverage.
  • The komb() function generates final candidates by concatenating family names with their corresponding date fragments, supporting both direct concatenation and underscore-separated formats.
  • Output processing removes duplicates, enforces length limits, and applies optional leet-speak encoding before saving the family-enhanced password list.

Frequently Asked Questions

Does CUPP require partner and child information to generate a wordlist?

No, providing partner and child information is optional during the interactive session. If you skip these fields, CUPP generates passwords based solely on the primary victim's data and generic permutations. However, including family data significantly improves the wordlist's effectiveness against users who incorporate family members' names or birth years into their passwords.

How does CUPP format dates when combining them with names?

CUPP extracts multiple fragments from the DDMMYYYY birthdate format stored in profile["wifeb"] and profile["kidb"]. The code slices strings to isolate the last 2 digits of the year (e.g., "92"), the full 4-digit year ("1992"), and typically the day-month combination ("1508"). These fragments are stored in date lists (wbdss, kbdss) that the komb() function iterates through, creating candidates like alice92, alice1992, and alice1508.

Can CUPP handle multiple children or partners?

The current implementation in cupp.py supports only one partner and one child through the kid and wife profile keys. The interactive mode does not loop to collect additional family members, and the generation logic specifically references these single-instance keys. Users requiring multiple family member profiles would need to manually edit the source code to add additional profile fields and corresponding combination logic.

What password patterns does CUPP create with family information?

CUPP generates several pattern types using the komb() function: direct concatenation of names and years (e.g., alice92), underscore-separated versions (alice_92), capitalized variants (Alice92), and combinations with the victim's surname. These patterns are then mixed with leet-speak substitutions and numeric suffixes, producing realistic family-based passwords like johnjr08, mary_1995, or smithkid22.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →