How to Configure Word Length Filtering in cupp.cfg for Password Generation

Set the wcfrom and wcto parameters in the [Word length shaping] section of cupp.cfg to define the minimum and maximum character limits for words used in password generation.

The CUPP (Common User Passwords Profiler) tool, maintained in the Mebus/cupp repository, uses a central configuration file to control how it transforms input words into potential passwords. Configuring word length filtering in cupp.cfg allows you to constrain the generator to words within specific size boundaries, ensuring output passwords meet your target length policies.

Understanding the Word Length Shaping Section

In cupp.cfg, the [Word length shaping] block contains two critical parameters that control which words enter the password generation pipeline. According to the source configuration at lines 49–55, these settings establish a closed interval [wcfrom, wcto] that filters the input wordlist before permutation begins.

  • wcfrom – Defines the minimum word length in characters. Words shorter than this value are excluded from the generation process.
  • wcto – Defines the maximum word length in characters. Words exceeding this length are discarded.

When CUPP executes, it reads these values from cupp.cfg and applies them as a pre-filter in cupp.py before applying mutations and concatenations.

Editing cupp.cfg Parameters

Setting the Minimum Word Length (wcfrom)

Locate the wcfrom entry in the [Word length shaping] section of cupp.cfg. This integer value represents the shortest word length the generator will accept. For security policies requiring passwords of at least 8 characters derived from base words, set this to 8.

Setting the Maximum Word Length (wcto)

Similarly, configure wcto to cap the upper bound of word lengths. This prevents excessively long dictionary entries from creating unwieldy password candidates. A typical enterprise configuration might set this to 16 to balance complexity with memorability.

Practical Configuration Examples

You can modify these parameters using any text editor or automated scripting tools. Here is a shell command that updates both values in place using sed:


# Update cupp.cfg to accept only words between 8 and 16 characters

sed -i \
  -e 's/^wcfrom=.*/wcfrom=8/' \
  -e 's/^wcto=.*/wcto=16/' \
  cupp.cfg

After updating the configuration, execute CUPP with your target wordlist:


# Generate passwords respecting the new length constraints

python cupp.py -i input_wordlist.txt -o generated_passwords.txt

The generator will now only process words whose length falls between 8 and 16 characters, applying transformations exclusively to words within that range.

How the Filter Works in cupp.py

The cupp.py script reads the cupp.cfg file at initialization and parses the [Word length shaping] section into runtime variables. As it iterates through the input wordlist, it performs a length check against the wcfrom and wcto values before adding words to the permutation buffer. This filtering occurs early in the pipeline, improving performance by excluding irrelevant words before computational transformations begin.

Summary

  • Word length filtering in CUPP is controlled by the wcfrom and wcto parameters in cupp.cfg.
  • The [Word length shaping] section defines a closed interval [wcfrom, wcto] that filters input words.
  • Configure wcfrom to set the minimum word length and wcto to set the maximum word length.
  • Changes take effect immediately when running python cupp.py with the updated configuration file.

Frequently Asked Questions

What is the default word length range in cupp.cfg?

The default values in the repository's cupp.cfg typically set wcfrom to a lower single-digit number and wcto to a moderate upper limit around 20 characters. Consult the specific lines 49–55 in your version of cupp.cfg to verify the current defaults, as these may vary by release.

Can I disable word length filtering entirely?

While there is no explicit "disable" flag, you can effectively bypass filtering by setting wcfrom to 1 and wcto to a very high number (such as 999). This ensures virtually all words in your input list pass the length check, though this is generally not recommended for targeted password generation.

How does word length filtering affect password complexity?

Restricting word lengths to a narrower range (e.g., 8–12 characters) typically produces more predictable passwords, while a wider range increases entropy. However, filtering out very short words (under 8 characters) is a security best practice, as excessively short base words generate weaker passwords even after permutation.

Where is the word length configuration located in cupp.cfg?

The word length settings are located in the [Word length shaping] section, which appears around lines 49–55 in the standard cupp.cfg file from the Mebus/cupp repository. This section contains the wcfrom and wcto key-value pairs that control the length boundaries.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →