How to Increase the Random Number Range for Password Suffixes in CUPP
Edit the cupp.cfg configuration file and modify the from and to values under the [nums] section to expand the range of numeric suffixes appended to generated passwords.
CUPP (Common User Passwords Profiler) generates targeted wordlists for password security testing by appending numeric suffixes to base words when using the -w (improve dictionary) or -i (interactive) options. By default, the tool draws from a limited numeric range defined in its configuration file. Increasing this range allows you to create more comprehensive password candidates without modifying the Python source code.
Where the Number Range Is Configured
The numeric range is controlled through the [nums] section in cupp.cfg:
[nums]
from=0
to=100
The from parameter sets the lowest number appended, while to acts as the exclusive upper bound (the range stops at to - 1). This means the default configuration generates numbers from 0 through 99.
How to Increase the Random Number Range
To expand the range, edit cupp.cfg and adjust the values:
nano cupp.cfg
Set your desired range. For example, to generate suffixes from 0 to 9999:
[nums]
from=0
to=9999
Save the file after editing. CUPP automatically reads these values at startup through the read_config() function in cupp.py (lines 64-68), so no code changes are required.
How the Range Is Applied in the Source Code
Understanding the implementation helps verify your configuration changes:
Configuration Loading
The read_config() function parses cupp.cfg and stores the values in the global CONFIG dictionary under CONFIG["global"]["numfrom"] and CONFIG["global"]["numto"].
Concatenation Logic
The concats() function (lines 104-107 in cupp.py) generates combinations by iterating through range(numfrom, numto) and appending each number to every word in the list.
Usage Contexts
Both workflows invoke concats() to append numbers:
- Interactive mode:
generate_wordlist_from_profile()(lines 112-118) calls it when users confirm random number addition during the-iworkflow. - Dictionary improvement mode:
improve_dictionary()(lines 54-57) uses it when processing existing wordlists with the-wflag.
Practical Examples
Interactive Mode (-i)
Run the interactive profiler:
python3 cupp.py -i
When prompted to add random numbers at the end of words, confirm with y. With to=9999 in your config, generated passwords will include suffixes from 0000 to 9999:
grep -E 'alice[0-9]{4}' alice.txt | head
Output:
alice0001
alice0234
alice5678
Dictionary Improvement (-w)
Process an existing wordlist:
python3 cupp.py -w mywordlist.txt
The output file mywordlist.txt.cupp.txt will contain entries with numeric suffixes up to 9998:
tail -n 5 mywordlist.txt.cupp.txt
Output:
password9995
password9996
password9997
password9998
password9999
Performance Considerations
Expanding the number range increases the wordlist size exponentially. If you increase the range from 0-100 to 0-10000, the output grows by a factor of 100, which can impact memory usage and processing time. If you encounter performance issues, adjust the threshold setting in cupp.cfg to manage resource consumption during large generation tasks.
Summary
- The random number range for password suffixes in CUPP is defined in
cupp.cfgunder the[nums]section. - Edit the
fromandtovalues to customize the numeric range; remember thattois exclusive (use10000to include 9999). - Changes take effect immediately without code modifications because
read_config()loads these values at program startup. - The
concats()function incupp.pyapplies this range when generating wordlists in both interactive (-i) and dictionary improvement (-w) modes. - Large ranges significantly increase output file size and memory consumption; monitor the
thresholdsetting if processing large datasets.
Frequently Asked Questions
Is the upper bound in cupp.cfg inclusive or exclusive?
The to value is exclusive. If you set to=100, CUPP generates numbers from 0 through 99. To include numbers up to 9999, you must set to=10000.
Do I need to restart CUPP after editing cupp.cfg?
No. CUPP reads the configuration file fresh each time you execute it through the read_config() function. Simply save your changes to cupp.cfg and run your command again.
Which CUPP modes use the random number suffix feature?
The feature activates in both interactive mode (-i) and dictionary improvement mode (-w), specifically when you answer y to the prompt asking "Do you want to add some random numbers at the end of words?"
Will increasing the range affect processing speed?
Yes. Expanding the range from 0-100 to 0-10000 increases the number of generated password candidates by a factor of 100. This requires more memory during generation and produces significantly larger output files. Monitor the threshold setting in cupp.cfg to prevent resource exhaustion when working with expanded ranges.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →