# Order of Password Generation Operations in CUPP: Complete Pipeline Guide

> Understand the 14 step password generation operations pipeline in CUPP. Learn how raw profile data becomes password fragments, name variants, and leet transformations. Full pipeline guide.

- Repository: [Mebus/cupp](https://github.com/Mebus/cupp)
- Tags: internals
- Published: 2026-07-01

---

**CUPP generates passwords through a 14-step pipeline defined in [`cupp.py`](https://github.com/Mebus/cupp/blob/main/cupp.py) that processes raw profile data into birthday fragments, name variants, systematic concatenations with special characters and years, optional leet transformations, and final length filtering before writing to disk.**

CUPP (Common User Passwords Profiler) is a powerful tool for generating targeted wordlists based on personal information. Understanding the order of password generation operations in CUPP is essential for security researchers and penetration testers who need to predict output structure or debug candidate creation. The entire workflow is encapsulated in the `generate_wordlist_from_profile()` function within the Mebus/cupp repository.

## The Order of Password Generation Operations in CUPP

The `generate_wordlist_from_profile()` function in [`cupp.py`](https://github.com/Mebus/cupp/blob/main/cupp.py) executes a fixed 14-step pipeline. The process moves from raw data preparation through systematic concatenation to final refinement and output.

### Phase 1: Data Preparation and Fragmentation

**Step 1: Special Character Collection**
If the user opts to add special characters (`profile["spechars1"]` equals "y"), the script first builds a list of 1-, 2-, and 3-character combinations stored in `profile["spechars"]` (lines 81-88 in [`cupp.py`](https://github.com/Mebus/cupp/blob/main/cupp.py)).

**Step 2-3: Birthday Fragment Extraction and Combination**
The script slices each supplied birthdate into year, month, and day components (e.g., `birthdate_yy`, `birthdate_dd`) (lines 95-102). It then generates single, double, and triple concatenations of these fragments, storing them in `bdss`, `wbdss`, and `kbdss` lists (lines 124-88).

**Step 4-5: Name Variants and Base Word Groups**
CUPP creates original, title-cased, and reversed name variants for the victim, spouse, and child (e.g., `nameup`, `rev_name`). These feed into distinct base word groups: `kombina` (personal names), `kombinaaw` (spouse), `kombinaak` (child), and `kombinaac` (pet and company) (lines 118-138 and 151-172).

### Phase 2: Systematic Word Combination

**Step 6: Core Concatenations with Dates and Years**
The `komb()` function combines name groups with birthday fragments and years. The dictionary `kombi` is populated with specific indices:
- `kombi[1]`: Personal names plus birthday fragments (with optional "_")
- `kombi[2]`: Spouse names plus spouse birthday fragments
- `kombi[3]`: Child names plus child birthday fragments
- `kombi[4]` through `kombi[11]`: All groups combined with year lists (lines 176-206).

**Step 7: Numeric Suffix Integration**
When random numbers are enabled, `kombi[12]` through `kombi[16]` and `kombi[21]` receive numeric ranges via the `concats()` function (lines 212-218).

**Step 8: Reversed String Combinations**
The script generates combinations using reversed name lists (`rev_name`, `rev_wname`, `rev_kname`) combined with years, birthday fragments, and special characters (lines 220-226).

**Step 9: Special Character Appends**
If special characters were requested, the script generates additional entries `komb001` through `komb006` that append those characters to earlier word groups (lines 232-240).

### Phase 3: Deduplication and Final Processing

**Step 10: Sub-list Deduplication**
Each `kombi[i]` entry is converted to a unique list stored in `komb_unique[i]` to eliminate duplicates within individual combination sets (lines 244-247).

**Step 11: Final Pool Collection**
The script concatenates all birthday lists, the reverse list, unique name groups, and all `kombi` sets into a single `uniqlist` (lines 250-274).

**Step 12: Leet Transformation**
When "Leet mode" is enabled, each entry in the final list is passed through `make_leet()` and appended to `unique_leet` (lines 276-283).

**Step 13: Length Constraint Filtering**
Passwords are filtered to retain only those with lengths between `wcfrom` and `wcto` as defined in [`cupp.cfg`](https://github.com/Mebus/cupp/blob/main/cupp.cfg) (lines 286-291).

**Step 14: Dictionary File Export**
The resulting list is written to disk via `print_to_file()` as `<victim>.txt` (lines 293-295).

## Programmatic Pipeline Execution

Below is a minimal example demonstrating how the 14-step pipeline is triggered programmatically. The same sequence executes when running `cupp.py -i` interactively:

```python
import cupp

# Load configuration (required for lengths, specials, etc.)

cupp.read_config('cupp.cfg')

# Fake profile – normally gathered interactively

profile = {
    "name": "alice",
    "surname": "smith",
    "nick": "ali",
    "birthdate": "01011990",
    "wife": "bob",
    "wifen": "bobby",
    "wifeb": "02021985",
    "kid": "charlie",
    "kidn": "chaz",
    "kidb": "15051995",
    "pet": "fluffy",
    "company": "acme",
    "words": ["secret", "admin"],
    "spechars1": "y",          # add special chars

    "randnum": "y",            # add numbers

    "leetmode": "y",           # leet conversion

}
cupp.generate_wordlist_from_profile(profile)

```

Running this snippet produces [`alice.txt`](https://github.com/Mebus/cupp/blob/main/alice.txt) containing all generated password candidates in the exact order described above.

## Summary

- CUPP processes profile data through `generate_wordlist_from_profile()` in [`cupp.py`](https://github.com/Mebus/cupp/blob/main/cupp.py) using a fixed 14-step sequence.
- **Phase 1** prepares raw data: special characters, birthday fragments, name variants, and base word groups.
- **Phase 2** systematically concatenates these elements with dates, years, numbers, and special characters.
- **Phase 3** deduplicates entries, applies optional leet transformation, filters by length constraints from [`cupp.cfg`](https://github.com/Mebus/cupp/blob/main/cupp.cfg), and writes the final wordlist.

## Frequently Asked Questions

### What function controls the order of password generation in CUPP?

The `generate_wordlist_from_profile()` function in [`cupp.py`](https://github.com/Mebus/cupp/blob/main/cupp.py) encapsulates the entire pipeline, executing 14 distinct steps from raw profile parsing to final file output. This function is called both interactively through the CLI and programmatically to ensure consistent generation order.

### How does CUPP handle special characters in the generation pipeline?

Special characters are collected first (if enabled) and stored in `profile["spechars"]`, then appended to word groups in two phases: initial combinations with base words (Step 6) and final dedicated combinations (Step 9) via `komb001` through `komb006`.

### When does leet transformation occur during password generation?

Leet transformation happens near the end of the pipeline (Step 12) after all concatenations and deduplication are complete. The `make_leet()` function processes each entry in the final unique list before length filtering occurs.

### Can the order of operations in CUPP be modified?

The order is hardcoded in [`cupp.py`](https://github.com/Mebus/cupp/blob/main/cupp.py) within the `generate_wordlist_from_profile()` function. While you cannot change the sequence without editing the source, you can influence which steps execute by enabling or disabling options in the interactive profile or the configuration file.