How to Customize the Years Range for Password Generation in CUPP

To customize the years range for password generation in CUPP, edit the cupp.cfg configuration file and modify the comma-separated list under the [years] section, which the read_config function parses into CONFIG["global"]["years"] at program startup.

CUPP (Common User Passwords Profiler) generates targeted wordlists by combining personal information with common years. Unlike hardcoded values, the year range is fully configurable through the cupp.cfg file, allowing penetration testers to adapt the tool to specific target demographics or password policies. This configuration-driven approach ensures that all password generation modes use your custom year list without requiring code modifications.

Where CUPP Stores the Year Range Configuration

The year values are defined in the [years] section of the cupp.cfg file (located at line 15 in the default configuration). When CUPP initializes, the read_config function (implemented in cupp.py at lines 64-66) parses this section and stores the comma-separated values in the global configuration dictionary under CONFIG["global"]["years"].

This design means the year list is loaded once at program initialization and referenced throughout the password generation pipeline by functions like generate_wordlist_from_profile (lines 74-76) and the improve mode logic (lines 46-48).

Step-by-Step Guide to Customizing the Year Range

To modify the years used in password generation, follow these steps:

  1. Open cupp.cfg in your preferred text editor.

  2. Locate the [years] section.

  3. Replace the existing comma-separated list with your desired years. Note that CUPP does not support range syntax (e.g., "1980-1999"); you must enumerate each year individually.

  4. Save the file.

For example, to target the 1980-1999 decade:

[years]
years = 1980,1981,1982,1983,1984,1985,1986,1987,1988,1989,1990,1991,1992,1993,1994,1995,1996,1997,1998,1999

Applying Custom Years in Different CUPP Modes

After editing cupp.cfg, the custom year range automatically applies to all operations. When you run CUPP in interactive mode, the tool combines profile inputs (such as names and birthdates) with your specified years:

python3 cupp.py -i

The tool produces variations like john1995 or smith2003 based on the CONFIG["global"]["years"] list.

Similarly, when using the improve mode to enhance existing wordlists:

python3 cupp.py -w existing_wordlist.txt

CUPP references the same configuration key to append years to transformed words in the dictionary.

Summary

  • The year range for password generation in CUPP is controlled exclusively through the cupp.cfg configuration file.
  • The read_config function parses the [years] section at startup and stores values in CONFIG["global"]["years"] for global access.
  • You must specify years as a comma-separated list without range syntax.
  • Changes take effect immediately upon restart for all modes, including interactive (-i) and improve (-w), without requiring modifications to cupp.py.

Frequently Asked Questions

Can I use year ranges like "1990-2020" in cupp.cfg?

No. According to the CUPP source code in cupp.py, the configuration parser expects a comma-separated list of individual years in the [years] section. You must enumerate each year explicitly (e.g., 1990,1991,1992) rather than using hyphenated range syntax, as the read_config function splits values by commas without additional parsing logic.

Do I need to restart CUPP after editing cupp.cfg?

Yes. CUPP reads the configuration file once at program startup via the read_config function. Any changes to cupp.cfg require restarting the tool to take effect, as the CONFIG["global"]["years"] dictionary is populated during initialization and referenced throughout the session.

Which CUPP modes use the custom year configuration?

All password generation modes utilize the year configuration. This includes the interactive profile mode (-i), the wordlist improvement mode (-w), and any other operations that invoke generate_wordlist_from_profile or similar combination logic that references CONFIG["global"]["years"] as implemented in the Mebus/cupp repository.

Where is the year configuration stored in memory after parsing?

After parsing cupp.cfg, the year list is stored in the global configuration dictionary under the key CONFIG["global"]["years"], as defined in cupp.py. Both the main generation logic and the improve mode access this specific dictionary key to retrieve the year values for appending to password candidates.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →