How to Customize the Year Range for Password Generation in CUPP

Edit the years entry in cupp.cfg to replace the default 1990-2020 range with your comma-separated list, and CUPP will automatically use these values when generating password candidates in both interactive and dictionary-improvement modes.

CUPP (Common User Passwords Profiler) generates targeted wordlists by combining personal data with common years. To control which years appear in generated passwords, you need to modify the configuration file that the tool reads at startup. This guide explains how to customize the year range for password generation in CUPP by editing the configuration and shows exactly how the code applies these values.

Where CUPP Defines the Year Range

The year values are not hardcoded in the main script but stored in the external configuration file cupp.cfg. According to the Mebus/cupp source code, the read_config() function in cupp.py parses the [years] section at startup and stores the comma-separated values in CONFIG["global"]["years"] (lines 64-66).

By default, the repository ships with a range covering 1990 through 2020. When you run CUPP, this list is loaded once during initialization and referenced throughout the password generation process.

How to Modify the Year Range

Follow these steps to customize which years CUPP uses:

  1. Open cupp.cfg in your preferred text editor.

  2. Locate the [years] section. You will see a line like: years = 1990,1991,1992...2020

  3. Replace the comma-separated list with your desired years. For example:

    years = 1980,1981,1982,1983,1984,1985,1986,1987,1988,1989,1990,1991,1992,1993,1994,1995
  4. Save the file. No code changes are required.

To verify your changes from the command line before running CUPP:

grep "^years" cupp.cfg

Or automate the edit with sed:

sed -i 's/years = .*/years = 1980,1981,1982,1983,1984,1985,1986,1987,1988,1989/' cupp.cfg

Removing Years Entirely

If you want to disable year-based combinations completely, delete the years line from the [years] section or leave it empty. CUPP will then use an empty list, and no year permutations will be appended to the generated passwords.

How the Code Applies Custom Years

The customized year list flows through two primary code paths in cupp.py:

Dictionary-Improvement Mode (-w)

When running python3 cupp.py -w <wordlist>, the improve_dictionary() function combines your wordlist with the configured years using komb(listica, years) (lines 46-48). The years variable here references CONFIG["global"]["years"].

Interactive Profiling Mode (-i)

In interactive mode (python3 cupp.py -i), the generate_wordlist_from_profile() function creates combinations via list(komb(kombinaa, years)) and similar calls (lines 90-94, 104-106). This appends your custom years to names, birthdates, and other personal data provided during the interview process.

Summary

  • CUPP reads the year range from cupp.cfg via read_config() at startup
  • Edit the comma-separated list in the [years] section to customize the range
  • Changes apply immediately to both interactive (-i) and dictionary-improvement (-w) modes
  • The years are stored in CONFIG["global"]["years"] and used by komb() functions throughout cupp.py
  • Removing the years entry disables year-based password generation entirely

Frequently Asked Questions

What is the default year range in CUPP?

The default configuration includes years from 1990 to 2020, defined as a comma-separated list in the [years] section of cupp.cfg.

Do I need to restart CUPP after editing the configuration file?

Yes, you must restart CUPP after saving changes to cupp.cfg. The read_config() function executes once at program startup (lines 23-24 in cupp.py), and the configuration is not reloaded during runtime.

Can I use a single year instead of a range?

Yes. You can specify a single year like years = 2024 or any arbitrary combination such as years = 1999,2000,2024. The parser treats any comma-separated values as valid entries.

Where does CUPP store the year configuration in memory?

After parsing, the years are stored in the global dictionary under CONFIG["global"]["years"] as a Python list of strings, which is then passed to the komb() function for generating password candidates.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →