How to Increase the Random Number Range for Password Suffixes in CUPP

Edit the cupp.cfg configuration file and modify the from and to values under the [nums] section to expand the range of numeric suffixes appended to generated passwords.

CUPP (Common User Passwords Profiler) generates targeted wordlists for password security testing by appending numeric suffixes to base words when using the -w (improve dictionary) or -i (interactive) options. By default, the tool draws from a limited numeric range defined in its configuration file. Increasing this range allows you to create more comprehensive password candidates without modifying the Python source code.

Where the Number Range Is Configured

The numeric range is controlled through the [nums] section in cupp.cfg:

[nums]
from=0
to=100

The from parameter sets the lowest number appended, while to acts as the exclusive upper bound (the range stops at to - 1). This means the default configuration generates numbers from 0 through 99.

How to Increase the Random Number Range

To expand the range, edit cupp.cfg and adjust the values:

nano cupp.cfg

Set your desired range. For example, to generate suffixes from 0 to 9999:

[nums]
from=0
to=9999

Save the file after editing. CUPP automatically reads these values at startup through the read_config() function in cupp.py (lines 64-68), so no code changes are required.

How the Range Is Applied in the Source Code

Understanding the implementation helps verify your configuration changes:

Configuration Loading The read_config() function parses cupp.cfg and stores the values in the global CONFIG dictionary under CONFIG["global"]["numfrom"] and CONFIG["global"]["numto"].

Concatenation Logic The concats() function (lines 104-107 in cupp.py) generates combinations by iterating through range(numfrom, numto) and appending each number to every word in the list.

Usage Contexts Both workflows invoke concats() to append numbers:

  • Interactive mode: generate_wordlist_from_profile() (lines 112-118) calls it when users confirm random number addition during the -i workflow.
  • Dictionary improvement mode: improve_dictionary() (lines 54-57) uses it when processing existing wordlists with the -w flag.

Practical Examples

Interactive Mode (-i)

Run the interactive profiler:

python3 cupp.py -i

When prompted to add random numbers at the end of words, confirm with y. With to=9999 in your config, generated passwords will include suffixes from 0000 to 9999:

grep -E 'alice[0-9]{4}' alice.txt | head

Output:

alice0001
alice0234
alice5678

Dictionary Improvement (-w)

Process an existing wordlist:

python3 cupp.py -w mywordlist.txt

The output file mywordlist.txt.cupp.txt will contain entries with numeric suffixes up to 9998:

tail -n 5 mywordlist.txt.cupp.txt

Output:

password9995
password9996
password9997
password9998
password9999

Performance Considerations

Expanding the number range increases the wordlist size exponentially. If you increase the range from 0-100 to 0-10000, the output grows by a factor of 100, which can impact memory usage and processing time. If you encounter performance issues, adjust the threshold setting in cupp.cfg to manage resource consumption during large generation tasks.

Summary

  • The random number range for password suffixes in CUPP is defined in cupp.cfg under the [nums] section.
  • Edit the from and to values to customize the numeric range; remember that to is exclusive (use 10000 to include 9999).
  • Changes take effect immediately without code modifications because read_config() loads these values at program startup.
  • The concats() function in cupp.py applies this range when generating wordlists in both interactive (-i) and dictionary improvement (-w) modes.
  • Large ranges significantly increase output file size and memory consumption; monitor the threshold setting if processing large datasets.

Frequently Asked Questions

Is the upper bound in cupp.cfg inclusive or exclusive?

The to value is exclusive. If you set to=100, CUPP generates numbers from 0 through 99. To include numbers up to 9999, you must set to=10000.

Do I need to restart CUPP after editing cupp.cfg?

No. CUPP reads the configuration file fresh each time you execute it through the read_config() function. Simply save your changes to cupp.cfg and run your command again.

Which CUPP modes use the random number suffix feature?

The feature activates in both interactive mode (-i) and dictionary improvement mode (-w), specifically when you answer y to the prompt asking "Do you want to add some random numbers at the end of words?"

Will increasing the range affect processing speed?

Yes. Expanding the range from 0-100 to 0-10000 increases the number of generated password candidates by a factor of 100. This requires more memory during generation and produces significantly larger output files. Monitor the threshold setting in cupp.cfg to prevent resource exhaustion when working with expanded ranges.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →