Lowercase and Titlecase Name Variations in CUPP: Password Dictionary Generation Explained

CUPP stores every personal name in lowercase for the base wordlist and creates a titlecase variant to generate complex password combinations like "Alice1990" or "JohnDoe".

CUPP (Common User Passwords Profiler) is an open-source tool in the Mebus/cupp repository that generates targeted password dictionaries from personal information. Understanding how lowercase and titlecase name variations in CUPP are processed is essential for penetration testers who need to predict realistic password patterns. The tool employs a dual-representation strategy that captures both "all-lowercase" and "capitalized-first-letter" user habits commonly found in real-world passwords.

How CUPP Processes Name Input

Lowercase Normalization

When collecting interactive input, CUPP immediately normalizes strings to lowercase to create a standardized base. In cupp.py (lines 10-14), the code executes profile["name"] = name.lower().strip() to store the sanitized version. This lowercase variant serves as the foundation for the basic dictionary, accommodating users who type passwords without capital letters.

Titlecase Derivation

Immediately after storing the lowercase version, CUPP derives a titlecase variant using Python's str.title() method. Around line 22 of cupp.py, the assignment nameup = profile["name"].title() creates the capitalized version (e.g., "alice" becomes "Alice"). This titlecase variable (along with surnameup, nicknameup, and similar variants) feeds into the advanced combination engine.

Implementation in Wordlist Generation

The generate_wordlist_from_profile routine in cupp.py treats these variants differently to maximize coverage. The lowercase strings populate the core dictionary entries, while the titlecase versions are concatenated with dates, special characters, and other profile fields.

The tool constructs combinations such as:

  • Alice1990
  • John!
  • SarahDoe

This approach covers the common user behavior of capitalizing names while adding complexity through suffixes and prefixes defined in cupp.cfg.

Code Example: From Input to Combination


# Interactive input capture (lines 10-14 in cupp.py)

name = input("> First Name: ").lower().strip()   # User types "robert"

profile["name"] = name                           # Stored as "robert"

# Titlecase derivation (around line 22)

nameup = profile["name"].title()                 # Becomes "Robert"

# Later in wordlist generation (kombinaa array construction)

kombinaa.append(nameup)                          # "Robert"

kombinaa.append(nameup + "2024")                 # "Robert2024"

kombinaa.append(nameup + "!")                    # "Robert!"

The same pattern repeats for surnames, nicknames, spouse names, child names, pet names, and company fields throughout the source code.

Configuration and Testing

The transformation rules are supported by cupp.cfg, which defines character sets and years used when mixing name variations. The test_cupp.py file validates both processing paths to ensure that lowercase normalization and titlecase conversion work correctly across all profile fields, including edge cases with multiple words or special characters.

Summary

  • CUPP stores all name inputs in lowercase using profile["name"] = name.lower().strip() to build the base dictionary in cupp.py.
  • A titlecase variant is created via nameup = profile["name"].title() for generating complex password patterns.
  • The lowercase version targets users who type entirely in lowercase, while the titlecase version captures "Capitalized" naming conventions mixed with dates and symbols.
  • Both representations are essential for comprehensive coverage of real-world password creation habits stored in the kombinaa arrays.

Frequently Asked Questions

Why does CUPP use both lowercase and titlecase instead of just one format?

CUPP uses both formats because real-world passwords exhibit both patterns. Some users type "john1990" entirely in lowercase, while others prefer "John1990" with a capital first letter. The dual approach in cupp.py ensures the generated wordlist covers both conventions without manual configuration.

Where in the source code is the titlecase conversion performed?

The titlecase conversion occurs in cupp.py around line 22, where the code executes nameup = profile["name"].title(). This happens immediately after the lowercase storage and applies to first names, surnames, nicknames, and other profile fields.

Does CUPP apply this lowercase and titlecase logic to fields other than names?

Yes. According to the source code, the same pattern applies to surnames, nicknames, spouse names, child names, pet names, and company names. Each field gets a lowercase entry in the profile dictionary and a corresponding titlecase variable (e.g., surnameup, nicknameup) for combination generation.

How does the titlecase variant improve password cracking success?

The titlecase variant improves success rates by modeling the common user habit of capitalizing the first letter of their name when creating passwords. Without this variant, CUPP would miss passwords like "Alice2024" or "Mike!", which are statistically common patterns in leaked password databases.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →