# CUPP Leet Mode Character Combinations: The Complete 1337 Substitution Guide

> Discover CUPP leet mode character combinations! Explore the complete 1337 substitution guide for Mebus/cupp to enhance your wordlist generation with these 8 key substitutions.

- Repository: [Mebus/cupp](https://github.com/Mebus/cupp)
- Tags: deep-dive
- Published: 2026-07-03

---

**CUPP’s leet mode supports eight specific character substitutions—`a` to `4`, `e` to `3`, `i` to `1`, `o` to `0`, `s` to `5`, `t` to `7`, `g` to `9`, and `z` to `2`—which are defined in the [`cupp.cfg`](https://github.com/Mebus/cupp/blob/main/cupp.cfg) configuration file and applied during wordlist generation.**

The Common User Passwords Profiler (CUPP), hosted at `Mebus/cupp`, is a wordlist generation tool that mimics how users modify passwords to meet complexity requirements. Its **leet mode** (also known as 1337 speak) transforms candidate passwords by replacing alphabetic characters with visually similar numeric equivalents, significantly expanding the search space for password audits.

## The 8 Character Mappings in CUPP Leet Mode

CUPP’s leet mode operates on exactly eight character combinations. These mappings are stored in the `[leet]` section of **[`cupp.cfg`](https://github.com/Mebus/cupp/blob/main/cupp.cfg)** (lines 19-26) and loaded into memory at runtime:

- **a → 4**
- **e → 3**
- **i → 1**
- **o → 0**
- **s → 5**
- **t → 7**
- **g → 9**
- **z → 2**

When active, the program iterates over this dictionary and replaces every occurrence of each letter with its corresponding digit.

## How CUPP Implements Leet Mode

The leet substitution logic resides in **[`cupp.py`](https://github.com/Mebus/cupp/blob/main/cupp.py)** and executes through two distinct phases: configuration initialization and string transformation.

### Configuration Loading

During startup, CUPP parses [`cupp.cfg`](https://github.com/Mebus/cupp/blob/main/cupp.cfg) and stores the leet mappings in the global `CONFIG["LEET"]` dictionary (lines 76-84). This structure enables constant-time lookups when processing candidate passwords.

### The make_leet Function

The actual transformation occurs in the **`make_leet`** function (lines 95-99). This helper iterates over the configuration dictionary and applies substitutions sequentially:

```python
def make_leet(x):
    for letter, number in CONFIG["LEET"].items():
        x = x.replace(letter, number)
    return x

```

## Enabling Leet Mode in CUPP

You can activate leet mode through two primary workflows:

1. **Interactive Profile Mode (`-i`):** When generating a profile-based wordlist, CUPP prompts you to enable leet mode. Answering `y` triggers the transformation on all generated candidates.
2. **Wordlist Improvement (`-w`):** When enhancing existing wordlists, leet mode automatically applies the eight substitutions to each input word.

### Practical Code Examples

When constructing a profile with leet mode enabled:

```python
profile = {
    "name": "alice",
    "surname": "smith",
    "leetmode": "y"  # Activates 1337 substitution

}

# Generated variants include "4l1c3" and "sm17h"

```

Using the `make_leet` function directly in custom scripts:

```python
from cupp import CONFIG, make_leet, read_config

# Initialize configuration including leet mappings

read_config("cupp.cfg")

# Transform strings using CUPP's leet logic

print(make_leet("password"))  # Output: p4ssw0rd

print(make_leet("test"))      # Output: 7357

```

## Customizing Leet Character Combinations

The eight default mappings are fully extensible. You can customize CUPP’s leet mode by editing the `[leet]` section in [`cupp.cfg`](https://github.com/Mebus/cupp/blob/main/cupp.cfg) and adding new key-value pairs. For example, appending `b = 8` or `l = 1` extends the transformation logic without modifying the Python source code.

## Summary

- CUPP’s leet mode supports **eight character combinations**: `a→4`, `e→3`, `i→1`, `o→0`, `s→5`, `t→7`, `g→9`, and `z→2`.
- Mappings are defined in **[`cupp.cfg`](https://github.com/Mebus/cupp/blob/main/cupp.cfg)** (lines 19-26) and loaded into `CONFIG["LEET"]` at runtime (lines 76-84).
- The **`make_leet`** function in **[`cupp.py`](https://github.com/Mebus/cupp/blob/main/cupp.py)** (lines 95-99) performs substitutions by iterating over the configuration dictionary.
- Enable leet mode via the **`-i`** interactive prompt or **`-w`** wordlist improvement options.
- You can extend supported combinations by adding entries to the `[leet]` section in [`cupp.cfg`](https://github.com/Mebus/cupp/blob/main/cupp.cfg).

## Frequently Asked Questions

### What characters does CUPP replace in leet mode?

CUPP replaces eight alphabetic characters with digits: `a` becomes `4`, `e` becomes `3`, `i` becomes `1`, `o` becomes `0`, `s` becomes `5`, `t` becomes `7`, `g` becomes `9`, and `z` becomes `2`. These mappings are stored in the `[leet]` section of [`cupp.cfg`](https://github.com/Mebus/cupp/blob/main/cupp.cfg) and loaded into `CONFIG["LEET"]` during initialization.

### How do I enable leet mode when generating wordlists?

You can enable leet mode by using the `-i` flag for interactive profile creation and responding `y` when prompted, or by using the `-w` flag when improving existing wordlists. Both methods trigger the `make_leet` function to process candidate passwords according to the mappings defined in [`cupp.cfg`](https://github.com/Mebus/cupp/blob/main/cupp.cfg).

### Can I add custom leet character combinations to CUPP?

Yes. Edit the [`cupp.cfg`](https://github.com/Mebus/cupp/blob/main/cupp.cfg) file and append new key-value pairs to the `[leet]` section following the existing format. CUPP automatically loads these custom mappings into `CONFIG["LEET"]` and applies them through the `make_leet` function without requiring changes to [`cupp.py`](https://github.com/Mebus/cupp/blob/main/cupp.py).

### Where is the leet mode logic implemented in the CUPP source code?

The leet mode logic is implemented in **[`cupp.py`](https://github.com/Mebus/cupp/blob/main/cupp.py)**. The configuration parser loads mappings into `CONFIG["LEET"]` at lines 76-84, while the substitution algorithm resides in the `make_leet` function at lines 95-99. The actual character definitions are stored in **[`cupp.cfg`](https://github.com/Mebus/cupp/blob/main/cupp.cfg)** at lines 19-26.