How the CUPP Interactive Mode (-i) Gathers Victim Information
When executed with the -i flag, CUPP launches an interactive questionnaire that collects personal details about the target into a Python dictionary named profile, which is then processed by combinatorial algorithms to generate a customized password wordlist.
CUPP (Common User Passwords Profiler) is an open-source tool designed to create personalized password dictionaries for security testing. According to the Mebus/cupp source code, the interactive mode operates entirely through local prompts defined in cupp.py, requiring no network connectivity during the data collection phase.
Entry Point and CLI Parsing
The interactive workflow begins when the user passes the -i or --interactive argument. In cupp.py, the argument parser registers this flag, and the main() function subsequently routes execution to the interactive() function when the flag is present. This architecture ensures that the tool remains in a strict input-collection state until all victim data is gathered.
The Data Collection Flow
The interactive() function (lines 299-336 in cupp.py) drives the entire data gathering process through a series of input() prompts that build the profile dictionary.
Mandatory and Optional Fields
The function enforces only one mandatory field: first name. If the user presses Enter without providing a value, the prompt repeats until valid input is received. All other fields accept blank responses:
- Surname and nickname
- Birthdate (expected format: DDMMYYYY)
- Partner information: name, nickname, and birthdate
- Child information: name, nickname, and birthdate
- Pet's name and company name
Profile Dictionary Assembly
All collected responses are stored in a Python dictionary called profile with specific keys mapping to the victim's data:
name: First name (converted to lowercase)surname: Family namenick: Nicknamebirthdate: Full birthdate stringwife: Partner's namewifen: Partner's nicknamewifeb: Partner's birthdatekid: Child's namekidn: Child's nicknamekidb: Child's birthdatepet: Pet namecompany: Company namewords: List of additional keywords (split from comma-separated input)spechars1: Flag for special character appending ("y" or "n")randnum: Flag for random number appending ("y" or "n")leetmode: Flag for leet-speak conversion ("y" or "n")
From Profile to Password Candidates
Once the profile dictionary is populated, it is passed to generate_wordlist_from_profile() (lines 371-406 in cupp.py). This function transforms the personal data into thousands of password candidates through several processing stages.
Birthday Fragment Extraction
The function parses birthdates to extract multiple numerical fragments (lines 945-998). For the victim, partner, and child, it generates:
- Two-digit year (
YY) - Three-digit year (
YYY) - Four-digit year (
YYYY) - Day and month components
- Various combinations of these elements
String Permutations and Combinations
The generator creates permutations using several helper utilities (lines 1017-1085):
komb(): Concatenates two sequences with optional separatorsconcats(): Appends numeric ranges to strings- Reversal operations: Creates reversed versions of names and words
- Capitalization: Generates title-case variants using Python's
title()method
These utilities combine names, surnames, birth years, and keywords with the fragments extracted earlier, producing a matrix of potential passwords.
Leet Speak and Special Characters
If the user enabled leet mode (leetmode: "y"), each candidate passes through make_leet(), which applies character substitutions defined in cupp.cfg (such as a → 4, e → 3, t → 7). When special characters are enabled, the generator appends symbols like !, @, #, and $ to word endings.
Output Generation
The final stage deduplicates the candidate list using dict.fromkeys(), filters entries by the length constraints specified in cupp.cfg (wcfrom and wcto), and writes the results to <first-name>.txt via print_to_file(). The function also reports the output file size and optionally prints the entire dictionary if the user selects the "Hyperspeed Print" option.
Practical Example
Running CUPP in interactive mode from the command line:
python3 cupp.py -i
The tool displays the banner and prompts for input:
[+] Insert the information about the victim to make a dictionary
[+] If you don't know all the info, just hit enter when asked! ;)
> First Name: alice
> Surname: smith
> Nickname: ali
> Birthdate (DDMMYYYY): 15081990
> Partners) name: bob
> Partners) nickname: bobby
> Partners) birthdate (DDMMYYYY): 23071985
> Child's name: carol
> Child's nickname: car
> Child's birthdate (DDMMYYYY): 01012010
> Pet's name: rex
> Company name: acme
> Do you want to add some key words about the victim? Y/[N]: y
> Please enter the words, separated by comma. [i.e. hacker,juice,black], spaces will be removed: red,admin
> Do you want to add special chars at the end of words? Y/[N]: y
> Do you want to add some random numbers at the end of words? Y/[N]: y
> Leet mode? (i.e. leet = 1337) Y/[N]: n
This generates alice.txt containing combinations such as:
alice1990
Alice1990
alice1990!
alice1990admin
alice1990admin!
Summary
- CUPP's interactive mode (
-i) uses theinteractive()function incupp.pyto collect victim data through local command-line prompts. - Data is stored in a
profiledictionary with keys for names, birthdates, relationships, pets, companies, and processing flags. - The
generate_wordlist_from_profile()function parses dates, reverses strings, and applies combinatorial logic usingkomb()andconcats()helpers. - Configuration parameters from
cupp.cfgcontrol word length limits, leet mappings, and character sets. - Final output is written to
<first-name>.txtafter deduplication and length filtering.
Frequently Asked Questions
What happens if I don't know some of the victim's information?
The interactive mode accepts blank responses for all fields except the first name. Simply press Enter to skip optional questions; the wordlist generator will work with whatever data is provided.
Where does CUPP store the collected victim information?
The data exists only in memory within the profile dictionary during execution. It is not stored in a database or transmitted over the network. The only persistent output is the generated password file (e.g., alice.txt).
How does CUPP generate so many passwords from a few pieces of information?
The tool uses combinatorial algorithms defined in lines 1017-1085 of cupp.py to mix names with birthdate fragments (YY, YYYY, day, month), reverse strings, append years from cupp.cfg, and combine elements with special characters and user-defined keywords.
Can I customize the leet-speak conversions or special characters?
Yes. These mappings are defined in cupp.cfg, which specifies character substitutions (e.g., a:4, e:3) and the sets of special characters and numbers to append when those options are enabled.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →