CUPP Concatenation Threshold: How to Adjust It for Large Wordlists
The CUPP concatenation threshold defaults to 200 words to prevent memory exhaustion from quadratic expansion, and you can adjust this limit by modifying the threshold value in cupp.cfg before running the tool with the -w flag.
CUPP (Common User Passwords Profiler) from the Mebus/cupp repository generates password candidates by combining entries from supplied wordlists. The concatenation threshold serves as a critical safeguard that limits how many words can be pairwise concatenated, protecting your system from runaway memory usage when processing large dictionaries.
What Is the CUPP Concatenation Threshold?
The concatenation threshold is a memory protection mechanism that controls the maximum wordlist size eligible for pairwise concatenation. When you invoke CUPP with the -w (improve dictionary) option, the tool attempts to generate new password candidates by joining every word in the list with every other word.
This operation produces N × N combinations. With the default threshold of 200, CUPP generates approximately 40,000 concatenated strings. Without this limit, a 5,000-word list would create roughly 25 million combinations, potentially crashing the process due to RAM exhaustion.
Where the Threshold Is Configured and Enforced
Configuration in cupp.cfg
The threshold value is defined in the cupp.cfg configuration file at the repository root. Under the Threshold section, the threshold parameter sets the hard limit:
[Threshold]
threshold=200
You can typically locate this setting around line 62 in the configuration file.
Runtime Validation in cupp.py
During execution, cupp.py reads this value into CONFIG["global"]["threshold"] around line 71. The actual enforcement occurs near line 208, where the script compares your wordlist length against the configured threshold before proceeding with concatenation.
If the wordlist exceeds the limit, CUPP displays a warning and prompts for confirmation:
[-] Maximum number of words for concatenation is 200
[-] Check configuration file for increasing this number.
Do you want to concatenate all words from wordlist? Y/[N]:
How to Adjust the Concatenation Threshold for Large Wordlists
To process wordlists larger than 200 entries, modify the configuration and confirm the operation. Follow these steps to safely increase the limit:
-
Edit the configuration file
Open
cupp.cfgand locate thethresholdentry. Change the value to match your system's memory capacity:threshold=1000 -
Execute CUPP with the improve dictionary flag
Run the tool against your large wordlist:
python3 cupp.py -w large_wordlist.txt -
Confirm the operation if prompted
If your list still exceeds the new threshold, type
ywhen prompted to proceed. The warning is informational and allows you to abort if the combination count risks system stability.
Memory Impact and Scaling Considerations
Understanding the quadratic growth helps you set appropriate thresholds. The relationship between wordlist size and memory usage follows this pattern:
- 200 words: ~40,000 concatenations (default threshold)
- 1,000 words: ~1,000,000 concatenations
- 5,000 words: ~25,000,000 concatenations
When adjusting the threshold in cupp.cfg for substantial wordlists, ensure your system has sufficient RAM to handle the resulting combination set. For example, setting threshold=6000 allows processing of 5,000-entry lists but requires adequate memory to store millions of generated strings.
Summary
- The concatenation threshold in CUPP defaults to 200 words to prevent memory exhaustion from quadratic growth.
- The limit is configured in
cupp.cfgand enforced at runtime incupp.pywhen using the-wflag. - Adjust the threshold by editing
cupp.cfgand setting a higher value appropriate for your system's RAM. - Always confirm the operation when warned, as the N × N concatenation can generate millions of strings from large wordlists.
Frequently Asked Questions
What happens if I set the concatenation threshold too high in CUPP?
Setting the threshold too high risks memory exhaustion and process termination. When processing a 5,000-word list, CUPP generates approximately 25 million concatenated strings. If your system lacks sufficient RAM to store these combinations, the Python process may crash or become unresponsive during dictionary generation.
Can I bypass the concatenation threshold without editing cupp.cfg?
Yes, you can temporarily bypass the threshold by pressing y when CUPP prompts you to confirm concatenation after displaying the warning. However, this only works for that specific execution and does not change the underlying configuration in cupp.cfg. You must still confirm the operation each time you exceed the limit.
Where exactly does CUPP check the wordlist size against the threshold?
CUPP performs the threshold check in cupp.py around line 208 during the dictionary improvement workflow. The script first reads the configuration value from CONFIG["global"]["threshold"] (set around line 71), then compares your wordlist length against this value before executing the concatenation logic.
Why does CUPP use a default concatenation threshold of 200?
The default value of 200 prevents accidental resource exhaustion on standard systems. At 200 words, CUPP generates approximately 40,000 combinations, which is manageable on most machines. This safety limit ensures users must consciously decide to consume additional memory when processing larger wordlists.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →