How to Customize the Random Number Range in CUPP for Password Generation
CUPP controls random numeric suffixes via the [nums] section in cupp.cfg, storing the bounds in CONFIG["global"]["numfrom"] and CONFIG["global"]["numto"] for use by the concats() function when generating password combinations.
The Common User Passwords Profiler (CUPP) appends random numbers to generated passwords by reading configurable bounds from its initialization file. To customize the random number range in CUPP, you edit the from and to values under the [nums] section in cupp.cfg, or override the global CONFIG dictionary programmatically after the configuration loads. This guide references the actual implementation in the Mebus/cupp repository to show you exactly how the range is parsed and applied.
How CUPP Loads Numeric Configuration
CUPP initializes its numeric range early in execution, parsing the configuration file before any password generation begins.
The read_config() Function
In cupp.py at lines 66-69, the read_config() function reads the cupp.cfg file and populates the global CONFIG dictionary:
# Inside read_config()
CONFIG["global"]["numfrom"] = int(config.get("nums", "from"))
CONFIG["global"]["numto"] = int(config.get("nums", "to"))
These values persist for the entire session and define the boundaries for all subsequent numeric suffix generation.
The concats() Helper Function
The actual concatenation logic resides in concats() at lines 101-107 of cupp.py. This function accepts a sequence and the start/stop integers, yielding every combination of a word with each number in the half-open interval [start, stop):
def concats(seq, start, stop):
for myword in seq:
for num in range(start, stop):
yield myword + str(num)
Because Python's range() excludes the upper bound, setting to=10000 generates numbers through 9999.
Modifying the Configuration File
The simplest method to customize the random number range requires no code changes—only an edit to the configuration file.
Locating the [nums] Section
Open cupp.cfg in the repository root and find the [nums] section:
[nums]
from=0 # Lower bound (included)
to=100 # Upper bound (excluded)
Setting Inclusive and Exclusive Bounds
To generate specific numeric suffixes, adjust both values. For four-digit suffixes ranging from 1000 to 9999:
[nums]
from=1000
to=10000
Save the file. The next execution of cupp.py automatically loads these bounds. No command-line flags are required to activate the changes.
Programmatic Customization at Runtime
If you need to override the configuration without editing the file, modify the CONFIG dictionary after calling read_config():
import cupp
# Load default configuration
cupp.read_config('cupp.cfg')
# Override the numeric range for this session
cupp.CONFIG['global']['numfrom'] = 5000
cupp.CONFIG['global']['numto'] = 5010
# Execute generation—the suffixes will now range from 5000 to 5009
cupp.improve_dictionary('mywordlist.txt')
This approach is useful when integrating CUPP into larger pipelines that require dynamic range adjustment.
Where the Range Is Applied in the Codebase
The configured bounds are consumed in two primary password generation paths.
Wordlist Improvement Mode (-w)
In improve_dictionary() at lines 54-56 of cupp.py, the numeric range is applied when processing the -w flag:
kombinacija[4] = list(concats(listica, numfrom, numto))
This line appends the configured numeric range to every word in the supplied dictionary file.
Interactive Profile Generation (-i)
In generate_wordlist_from_profile() around lines 112-118, the code makes multiple calls to concats() using the global numfrom and numto variables:
# Example usage within profile generation
list(concats(some_word_list, numfrom, numto))
These calls occur when building variations of profile-derived words (pet names, birthdates, etc.), allowing the interactive mode to optionally include numeric suffixes within your specified range.
Summary
- Configuration file: Edit
cupp.cfgunder the[nums]section to set permanent bounds usingfrom(inclusive) andto(exclusive). - Global variables: The
read_config()function stores values inCONFIG["global"]["numfrom"]andCONFIG["global"]["numto"]. - Half-open interval: The
concats()function usesrange(start, stop), meaning the upper bound is never included in output. - Application points: The range is consumed in
improve_dictionary()(lines 54-56) andgenerate_wordlist_from_profile()(lines 112-118). - Runtime override: Modify
cupp.CONFIG['global']dictionary values after loading the configuration to change behavior without editing the file.
Frequently Asked Questions
What file contains the random number range settings in CUPP?
The settings reside in cupp.cfg at the repository root. The [nums] section defines the from and to parameters that control the numeric suffix range.
Is the upper bound inclusive or exclusive when customizing the range?
The upper bound is exclusive. The concats() function uses Python's range(start, stop), which generates numbers from start up to but not including stop. Setting to=10000 produces a maximum value of 9999.
Can I change the numeric range without editing the configuration file?
Yes. After importing CUPP and running cupp.read_config('cupp.cfg'), you can programmatically override cupp.CONFIG['global']['numfrom'] and cupp.CONFIG['global']['numto'] with integer values before calling any generation functions.
Which CUPP functions use the configured numeric range?
The improve_dictionary() function (lines 54-56) applies the range when processing the -w option, and generate_wordlist_from_profile() (lines 112-118) uses it during interactive profile generation (-i option). Both rely on the concats() helper to combine words with numbers from the configured range.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →