CUPP komb vs concats: Differences Between Password Combination Functions

The komb function produces concatenations of two string iterables with an optional separator, while concats appends numeric range values directly to strings, serving distinct mutation strategies in CUPP's wordlist generation.

CUPP (Common User Passwords Profiler) builds targeted password dictionaries by combining personal data elements through specialized generator functions. Understanding the differences between CUPP's komb and concats combination functions reveals how the tool constructs variants mixing lexical strings with years, special characters, or numeric suffixes. Both functions reside in cupp.py but operate on different input types and concatenation logic.

How komb Works in CUPP

The komb function serves as a generic combinatorial primitive that joins every element from two string sequences with an optional separator. Defined in cupp.py at lines 110-114, this generator iterates over a base sequence (seq) and a secondary sequence (start), yielding concatenated results.

The function signature is:

def komb(seq, start, special=""):
    for mystr in seq:
        for mystr1 in start:
            yield mystr + special + mystr1

Typical use cases include attaching years or special character strings to base words. For example, combining the name john with years [1990, 1991] produces john1990 and john1991. When the special parameter is provided, it inserts a separator between elements, such as john_1995.

How concats Works in CUPP

The concats function specializes in numeric suffix appending, attaching sequential integers from a defined range to each string in a sequence. Implemented in cupp.py at lines 103-107, this generator handles the -w and -r command-line options that add "random numbers at the end of words."

The function signature is:

def concats(seq, start, stop):
    for mystr in seq:
        for num in range(start, stop):
            yield mystr + str(num)

Unlike komb, which accepts two iterables, concats expects a string iterable (seq) and integer boundaries (start, stop). It directly concatenates the numeric value without separators, generating variants like admin0, admin1, through admin99 when called with concats(["admin"], 0, 100).

Key Differences Between komb and concats

Feature komb concats
Input Types Two string iterables (seq, start) String iterable (seq) and numeric range (start, stop)
Separator Support Optional special parameter for delimiters No separator; direct concatenation only
Output Format string + [separator] + string string + number
Primary Use Generic word-list combinations (years, special chars) Numeric suffix generation (random number options)

Input type distinction represents the most critical difference: komb processes two collections of strings (such as names and years), while concats converts integers from a Python range() into string suffixes. This architectural separation allows CUPP to handle lexical combinations separately from brute-force numeric mutations.

Implementation Examples in cupp.py

In the CUPP source code, these functions appear in distinct contexts. The komb generator handles combinations between base words and year lists, or words and special character strings:


# Example: Combining profile words with years

komb(listica, years)  # Produces variants like "john1995"

# Example: With separator for special patterns

komb(listica, special_chars, "_")  # Produces "john_!"

Conversely, concats appears when processing user requests for appended random numbers:


# Example: Adding numeric range 0-99 to base words

concats(listica, numfrom, numto)  # Produces "john0", "john1", etc.

The numfrom and numto variables typically derive from user input or default configuration values when invoking the tool with numeric permutation flags.

Summary

  • komb combines two string iterables with an optional separator, located at cupp.py lines 110-114, used for joining base words with years or special characters.
  • concats appends numeric range values directly to strings, located at cupp.py lines 103-107, used for generating sequential numeric suffixes.
  • The primary distinction lies in input handling: komb expects string sequences for both operands, while concats accepts a numeric range.
  • komb supports separator insertion via the special parameter; concats does not support separators.

Frequently Asked Questions

What inputs does the komb function accept in CUPP?

The komb function accepts two string iterables as its first two arguments (seq and start), plus an optional string special parameter that acts as a separator. According to the CUPP source code in cupp.py lines 110-114, it yields every combination of the first sequence's elements with the second sequence's elements, optionally joined by the separator string.

How does concats differ from komb in password generation?

While komb combines two word lists (such as names and years), concats specifically appends numeric values from a range to existing strings. As implemented in cupp.py lines 103-107, concats takes integer start and stop parameters to generate sequential numeric suffixes, making it suitable for creating variants like password0 through password99 without any separator characters.

When should I use komb versus concats in CUPP?

Use komb when you need to combine lexical elements such as attaching years, special characters, or additional words to base strings—particularly when you require separator characters between components. Use concats exclusively for appending sequential numeric suffixes to words, typically when enabling CUPP's random number permutation options (-w or -r flags) that generate numbered password variants.

Can I use a separator with the concats function in CUPP?

No, the concats function does not support separator insertion. According to the source code in cupp.py, it performs direct concatenation using mystr + str(num). If you need to insert characters between a base word and a suffix (such as john_1995), you must use komb instead, providing the separator string via the special parameter.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →