# How the CUPP Interactive Mode (-i) Gathers Victim Information

> Discover how CUPP's interactive mode (-i) gathers victim information through a guided questionnaire to build custom password wordlists for enhanced security testing. Learn more now.

- Repository: [Mebus/cupp](https://github.com/Mebus/cupp)
- Tags: how-to-guide
- Published: 2026-07-03

---

**When executed with the `-i` flag, CUPP launches an interactive questionnaire that collects personal details about the target into a Python dictionary named `profile`, which is then processed by combinatorial algorithms to generate a customized password wordlist.**

CUPP (Common User Passwords Profiler) is an open-source tool designed to create personalized password dictionaries for security testing. According to the Mebus/cupp source code, the interactive mode operates entirely through local prompts defined in [`cupp.py`](https://github.com/Mebus/cupp/blob/main/cupp.py), requiring no network connectivity during the data collection phase.

## Entry Point and CLI Parsing

The interactive workflow begins when the user passes the `-i` or `--interactive` argument. In [`cupp.py`](https://github.com/Mebus/cupp/blob/main/cupp.py), the argument parser registers this flag, and the `main()` function subsequently routes execution to the `interactive()` function when the flag is present. This architecture ensures that the tool remains in a strict input-collection state until all victim data is gathered.

## The Data Collection Flow

The `interactive()` function (lines 299-336 in [`cupp.py`](https://github.com/Mebus/cupp/blob/main/cupp.py)) drives the entire data gathering process through a series of `input()` prompts that build the `profile` dictionary.

### Mandatory and Optional Fields

The function enforces only one mandatory field: **first name**. If the user presses Enter without providing a value, the prompt repeats until valid input is received. All other fields accept blank responses:

- **Surname** and **nickname**
- **Birthdate** (expected format: DDMMYYYY)
- **Partner information**: name, nickname, and birthdate
- **Child information**: name, nickname, and birthdate
- **Pet's name** and **company name**

### Profile Dictionary Assembly

All collected responses are stored in a Python dictionary called `profile` with specific keys mapping to the victim's data:

- `name`: First name (converted to lowercase)
- `surname`: Family name
- `nick`: Nickname
- `birthdate`: Full birthdate string
- `wife`: Partner's name
- `wifen`: Partner's nickname
- `wifeb`: Partner's birthdate
- `kid`: Child's name
- `kidn`: Child's nickname
- `kidb`: Child's birthdate
- `pet`: Pet name
- `company`: Company name
- `words`: List of additional keywords (split from comma-separated input)
- `spechars1`: Flag for special character appending ("y" or "n")
- `randnum`: Flag for random number appending ("y" or "n")
- `leetmode`: Flag for leet-speak conversion ("y" or "n")

## From Profile to Password Candidates

Once the `profile` dictionary is populated, it is passed to `generate_wordlist_from_profile()` (lines 371-406 in [`cupp.py`](https://github.com/Mebus/cupp/blob/main/cupp.py)). This function transforms the personal data into thousands of password candidates through several processing stages.

### Birthday Fragment Extraction

The function parses birthdates to extract multiple numerical fragments (lines 945-998). For the victim, partner, and child, it generates:
- Two-digit year (`YY`)
- Three-digit year (`YYY`)
- Four-digit year (`YYYY`)
- Day and month components
- Various combinations of these elements

### String Permutations and Combinations

The generator creates permutations using several helper utilities (lines 1017-1085):

- **`komb()`**: Concatenates two sequences with optional separators
- **`concats()`**: Appends numeric ranges to strings
- **Reversal operations**: Creates reversed versions of names and words
- **Capitalization**: Generates title-case variants using Python's `title()` method

These utilities combine names, surnames, birth years, and keywords with the fragments extracted earlier, producing a matrix of potential passwords.

### Leet Speak and Special Characters

If the user enabled leet mode (`leetmode: "y"`), each candidate passes through `make_leet()`, which applies character substitutions defined in [`cupp.cfg`](https://github.com/Mebus/cupp/blob/main/cupp.cfg) (such as `a` → `4`, `e` → `3`, `t` → `7`). When special characters are enabled, the generator appends symbols like `!`, `@`, `#`, and `$` to word endings.

## Output Generation

The final stage deduplicates the candidate list using `dict.fromkeys()`, filters entries by the length constraints specified in [`cupp.cfg`](https://github.com/Mebus/cupp/blob/main/cupp.cfg) (`wcfrom` and `wcto`), and writes the results to `<first-name>.txt` via `print_to_file()`. The function also reports the output file size and optionally prints the entire dictionary if the user selects the "Hyperspeed Print" option.

## Practical Example

Running CUPP in interactive mode from the command line:

```bash
python3 cupp.py -i

```

The tool displays the banner and prompts for input:

```text
[+] Insert the information about the victim to make a dictionary
[+] If you don't know all the info, just hit enter when asked! ;)

> First Name: alice
> Surname: smith
> Nickname: ali
> Birthdate (DDMMYYYY): 15081990
> Partners) name: bob
> Partners) nickname: bobby
> Partners) birthdate (DDMMYYYY): 23071985
> Child's name: carol
> Child's nickname: car
> Child's birthdate (DDMMYYYY): 01012010
> Pet's name: rex
> Company name: acme

> Do you want to add some key words about the victim? Y/[N]: y
> Please enter the words, separated by comma. [i.e. hacker,juice,black], spaces will be removed: red,admin

> Do you want to add special chars at the end of words? Y/[N]: y
> Do you want to add some random numbers at the end of words? Y/[N]: y
> Leet mode? (i.e. leet = 1337) Y/[N]: n

```

This generates [`alice.txt`](https://github.com/Mebus/cupp/blob/main/alice.txt) containing combinations such as:

```text
alice1990
Alice1990
alice1990!
alice1990admin
alice1990admin!

```

## Summary

- CUPP's interactive mode (`-i`) uses the `interactive()` function in [`cupp.py`](https://github.com/Mebus/cupp/blob/main/cupp.py) to collect victim data through local command-line prompts.
- Data is stored in a `profile` dictionary with keys for names, birthdates, relationships, pets, companies, and processing flags.
- The `generate_wordlist_from_profile()` function parses dates, reverses strings, and applies combinatorial logic using `komb()` and `concats()` helpers.
- Configuration parameters from [`cupp.cfg`](https://github.com/Mebus/cupp/blob/main/cupp.cfg) control word length limits, leet mappings, and character sets.
- Final output is written to `<first-name>.txt` after deduplication and length filtering.

## Frequently Asked Questions

### What happens if I don't know some of the victim's information?

The interactive mode accepts blank responses for all fields except the first name. Simply press Enter to skip optional questions; the wordlist generator will work with whatever data is provided.

### Where does CUPP store the collected victim information?

The data exists only in memory within the `profile` dictionary during execution. It is not stored in a database or transmitted over the network. The only persistent output is the generated password file (e.g., [`alice.txt`](https://github.com/Mebus/cupp/blob/main/alice.txt)).

### How does CUPP generate so many passwords from a few pieces of information?

The tool uses combinatorial algorithms defined in lines 1017-1085 of [`cupp.py`](https://github.com/Mebus/cupp/blob/main/cupp.py) to mix names with birthdate fragments (YY, YYYY, day, month), reverse strings, append years from [`cupp.cfg`](https://github.com/Mebus/cupp/blob/main/cupp.cfg), and combine elements with special characters and user-defined keywords.

### Can I customize the leet-speak conversions or special characters?

Yes. These mappings are defined in [`cupp.cfg`](https://github.com/Mebus/cupp/blob/main/cupp.cfg), which specifies character substitutions (e.g., `a:4`, `e:3`) and the sets of special characters and numbers to append when those options are enabled.