How the Reverse Name Feature in CUPP Generates Password Variations

The reverse name feature in CUPP creates password candidates by mirroring the victim's first name, nickname, and family members' names using Python's [::-1] slice notation, then combines these reversed strings with years, birthdays, and numeric suffixes to catch mirror-written passwords.

The Common User Passwords Profiler (CUPP) is an open-source wordlist generator maintained in the Mebus/cupp repository. It constructs personalized password dictionaries from victim profiling data. The reverse name feature specifically targets the common user habit of writing names backwards or appending personal data to reversed strings.

How the Reverse Name Algorithm Works

The reverse name logic lives inside cupp.py within the generate_wordlist_from_profile function. It processes personal identifiers through three distinct stages: creating mirrored strings, assembling them into a token pool, and combining them with date and number patterns.

Creating Reversed String Variations

CUPP generates reversed versions of multiple identifiers to maximize coverage. For each name field, it creates both a lowercase and title-cased reversal:

rev_name   = profile["name"][::-1]       # lower-case name reversed

rev_nameup = nameup[::-1]               # title-cased name reversed

rev_nick   = profile["nick"][::-1]
rev_nickup = nickup[::-1]
rev_wife   = profile["wife"][::-1]
rev_wifeup = wifeup[::-1]
rev_kid    = profile["kid"][::-1]
rev_kidup  = kidup[::-1]

The slice [::-1] reads the string backward, producing the exact mirror of the original text. Both case variants are preserved because password combinations later in the pipeline may require either format.

Assembling the Reverse Token Pool

Once generated, these mirrored strings are collected into a dedicated list called reverse (lines 447-456 in cupp.py):

reverse = [
    rev_name, rev_nameup,
    rev_nick, rev_nickup,
    rev_wife, rev_wifeup,
    rev_kid,  rev_kidup,
]

This centralized list acts as a feedstock for the combination engine, ensuring that every reversed variant gets processed alongside years, birthdays, and user-defined number ranges.

Combining Reversed Names with Contextual Data

CUPP feeds the reverse list into several permutation functions. The komb helper handles concatenation, while concats appends numeric ranges. According to the source code at lines 517-527, reversed tokens are merged with:

  • Years: Common year strings from the configuration (e.g., "2020", "1999")
  • Birthday fragments: Short date patterns like YY, YYYY, DDMM
  • Random numbers: Ranges specified by the user (e.g., 0-99)
kombi[17] = list(komb(reverse, years))
kombi[17] += list(komb(reverse, years, "_"))

kombi[20] = list(komb(reverse, bdss))
kombi[20] += list(komb(reverse, bdss, "_"))

if profile["randnum"] == "y":
    kombi[21] = list(concats(reverse, numfrom, numto))

These combinations produce candidates like ecilA2021 (reversed title-case name + year) or ecila_1999 (reversed lowercase name + underscore separator + year).

Source Code Implementation Details

The reverse name feature relies on specific sections within cupp.py. The token creation occurs at lines 438-440, while the final merging and deduplication happens at lines 578-595.

The algorithm specifically handles these profile fields:

  • name: The victim's first name
  • nick: The victim's nickname
  • wife: Spouse or partner's name
  • kid: Child's name

Each field undergoes the same [::-1] transformation to ensure comprehensive coverage of familial password patterns.

Practical Examples of Reverse Name Passwords

Based on a victim profile where name is "alice" and nick is "ali", CUPP generates the following reversed base strings:


# Original profile data

profile['name'] = 'alice'
profile['nick'] = 'ali'
nameup = 'Alice'
nickup = 'Ali'

# Generated reversals

rev_name   = 'ecila'    # 'alice'[::-1]

rev_nameup = 'ecilA'    # 'Alice'[::-1]

rev_nick   = 'ila'      # 'ali'[::-1]

rev_nickup = 'ilA'      # 'Ali'[::-1]

When combined with the year "2022" and birthday fragment "1990", the algorithm produces:


# Year combinations

'ecila2022', 'ecilA2022', 'ila2022', 'ilA2022'

# Birthday combinations  

'ecila1990', 'ecilA1990', 'ecila_1990', 'ecilA_1990'

# Numeric suffixes (0-99 sample)

'ecila0', 'ecila1', ... 'ecila99'

These patterns account for passwords where users write their names backwards or append significant dates to reversed identifiers.

Summary

  • The reverse name feature in CUPP uses Python's [::-1] slice notation to mirror strings in cupp.py.
  • It processes the victim's name, nickname, spouse's name, and child's name, generating both lowercase and title-cased reversals.
  • Reversed tokens are stored in the reverse list and combined with years, birthday fragments, and numeric ranges via the komb and concats functions.
  • This technique targets mirror-written passwords like ecilA2021 or ila_1999, significantly expanding the wordlist's coverage of common user behaviors.

Frequently Asked Questions

What file contains the reverse name logic in CUPP?

The reverse name logic is implemented in cupp.py within the generate_wordlist_from_profile function. Specific line ranges include 438-440 for token creation, 447-456 for list assembly, and 517-527 for combining reversed strings with dates and numbers.

Does CUPP reverse only the first name or other identifiers too?

CUPP reverses multiple identifiers: the victim's name and nick, plus the wife and kid fields if provided. Each identifier generates both a lowercase reversal (e.g., rev_name) and a title-cased reversal (e.g., rev_nameup), ensuring case variations are covered.

How does CUPP combine reversed names with numeric suffixes?

When the user enables random numbers (-r flag), CUPP passes the reverse list to the concats function along with numfrom and numto parameters. This generates every combination of reversed strings appended with numbers in the specified range, such as ecila0 through ecila99.

Are reversed names in CUPP case-sensitive?

Yes. The algorithm maintains separate variables for lowercase and title-cased reversals. For example, rev_name contains the fully lowercase reversal (ecila), while rev_nameup contains the title-cased reversal (ecilA). Both variants enter the combination pool, capturing passwords regardless of which character the user capitalized.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →