How the Reverse Name Feature in CUPP Generates Password Variations
The reverse name feature in CUPP creates password candidates by mirroring the victim's first name, nickname, and family members' names using Python's [::-1] slice notation, then combines these reversed strings with years, birthdays, and numeric suffixes to catch mirror-written passwords.
The Common User Passwords Profiler (CUPP) is an open-source wordlist generator maintained in the Mebus/cupp repository. It constructs personalized password dictionaries from victim profiling data. The reverse name feature specifically targets the common user habit of writing names backwards or appending personal data to reversed strings.
How the Reverse Name Algorithm Works
The reverse name logic lives inside cupp.py within the generate_wordlist_from_profile function. It processes personal identifiers through three distinct stages: creating mirrored strings, assembling them into a token pool, and combining them with date and number patterns.
Creating Reversed String Variations
CUPP generates reversed versions of multiple identifiers to maximize coverage. For each name field, it creates both a lowercase and title-cased reversal:
rev_name = profile["name"][::-1] # lower-case name reversed
rev_nameup = nameup[::-1] # title-cased name reversed
rev_nick = profile["nick"][::-1]
rev_nickup = nickup[::-1]
rev_wife = profile["wife"][::-1]
rev_wifeup = wifeup[::-1]
rev_kid = profile["kid"][::-1]
rev_kidup = kidup[::-1]
The slice [::-1] reads the string backward, producing the exact mirror of the original text. Both case variants are preserved because password combinations later in the pipeline may require either format.
Assembling the Reverse Token Pool
Once generated, these mirrored strings are collected into a dedicated list called reverse (lines 447-456 in cupp.py):
reverse = [
rev_name, rev_nameup,
rev_nick, rev_nickup,
rev_wife, rev_wifeup,
rev_kid, rev_kidup,
]
This centralized list acts as a feedstock for the combination engine, ensuring that every reversed variant gets processed alongside years, birthdays, and user-defined number ranges.
Combining Reversed Names with Contextual Data
CUPP feeds the reverse list into several permutation functions. The komb helper handles concatenation, while concats appends numeric ranges. According to the source code at lines 517-527, reversed tokens are merged with:
- Years: Common year strings from the configuration (e.g., "2020", "1999")
- Birthday fragments: Short date patterns like YY, YYYY, DDMM
- Random numbers: Ranges specified by the user (e.g., 0-99)
kombi[17] = list(komb(reverse, years))
kombi[17] += list(komb(reverse, years, "_"))
kombi[20] = list(komb(reverse, bdss))
kombi[20] += list(komb(reverse, bdss, "_"))
if profile["randnum"] == "y":
kombi[21] = list(concats(reverse, numfrom, numto))
These combinations produce candidates like ecilA2021 (reversed title-case name + year) or ecila_1999 (reversed lowercase name + underscore separator + year).
Source Code Implementation Details
The reverse name feature relies on specific sections within cupp.py. The token creation occurs at lines 438-440, while the final merging and deduplication happens at lines 578-595.
The algorithm specifically handles these profile fields:
- name: The victim's first name
- nick: The victim's nickname
- wife: Spouse or partner's name
- kid: Child's name
Each field undergoes the same [::-1] transformation to ensure comprehensive coverage of familial password patterns.
Practical Examples of Reverse Name Passwords
Based on a victim profile where name is "alice" and nick is "ali", CUPP generates the following reversed base strings:
# Original profile data
profile['name'] = 'alice'
profile['nick'] = 'ali'
nameup = 'Alice'
nickup = 'Ali'
# Generated reversals
rev_name = 'ecila' # 'alice'[::-1]
rev_nameup = 'ecilA' # 'Alice'[::-1]
rev_nick = 'ila' # 'ali'[::-1]
rev_nickup = 'ilA' # 'Ali'[::-1]
When combined with the year "2022" and birthday fragment "1990", the algorithm produces:
# Year combinations
'ecila2022', 'ecilA2022', 'ila2022', 'ilA2022'
# Birthday combinations
'ecila1990', 'ecilA1990', 'ecila_1990', 'ecilA_1990'
# Numeric suffixes (0-99 sample)
'ecila0', 'ecila1', ... 'ecila99'
These patterns account for passwords where users write their names backwards or append significant dates to reversed identifiers.
Summary
- The reverse name feature in CUPP uses Python's
[::-1]slice notation to mirror strings incupp.py. - It processes the victim's name, nickname, spouse's name, and child's name, generating both lowercase and title-cased reversals.
- Reversed tokens are stored in the
reverselist and combined with years, birthday fragments, and numeric ranges via thekombandconcatsfunctions. - This technique targets mirror-written passwords like
ecilA2021orila_1999, significantly expanding the wordlist's coverage of common user behaviors.
Frequently Asked Questions
What file contains the reverse name logic in CUPP?
The reverse name logic is implemented in cupp.py within the generate_wordlist_from_profile function. Specific line ranges include 438-440 for token creation, 447-456 for list assembly, and 517-527 for combining reversed strings with dates and numbers.
Does CUPP reverse only the first name or other identifiers too?
CUPP reverses multiple identifiers: the victim's name and nick, plus the wife and kid fields if provided. Each identifier generates both a lowercase reversal (e.g., rev_name) and a title-cased reversal (e.g., rev_nameup), ensuring case variations are covered.
How does CUPP combine reversed names with numeric suffixes?
When the user enables random numbers (-r flag), CUPP passes the reverse list to the concats function along with numfrom and numto parameters. This generates every combination of reversed strings appended with numbers in the specified range, such as ecila0 through ecila99.
Are reversed names in CUPP case-sensitive?
Yes. The algorithm maintains separate variables for lowercase and title-cased reversals. For example, rev_name contains the fully lowercase reversal (ecila), while rev_nameup contains the title-cased reversal (ecilA). Both variants enter the combination pool, capturing passwords regardless of which character the user capitalized.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →