Order of Password Generation Operations in CUPP: Complete Pipeline Guide

CUPP generates passwords through a 14-step pipeline defined in cupp.py that processes raw profile data into birthday fragments, name variants, systematic concatenations with special characters and years, optional leet transformations, and final length filtering before writing to disk.

CUPP (Common User Passwords Profiler) is a powerful tool for generating targeted wordlists based on personal information. Understanding the order of password generation operations in CUPP is essential for security researchers and penetration testers who need to predict output structure or debug candidate creation. The entire workflow is encapsulated in the generate_wordlist_from_profile() function within the Mebus/cupp repository.

The Order of Password Generation Operations in CUPP

The generate_wordlist_from_profile() function in cupp.py executes a fixed 14-step pipeline. The process moves from raw data preparation through systematic concatenation to final refinement and output.

Phase 1: Data Preparation and Fragmentation

Step 1: Special Character Collection If the user opts to add special characters (profile["spechars1"] equals "y"), the script first builds a list of 1-, 2-, and 3-character combinations stored in profile["spechars"] (lines 81-88 in cupp.py).

Step 2-3: Birthday Fragment Extraction and Combination The script slices each supplied birthdate into year, month, and day components (e.g., birthdate_yy, birthdate_dd) (lines 95-102). It then generates single, double, and triple concatenations of these fragments, storing them in bdss, wbdss, and kbdss lists (lines 124-88).

Step 4-5: Name Variants and Base Word Groups CUPP creates original, title-cased, and reversed name variants for the victim, spouse, and child (e.g., nameup, rev_name). These feed into distinct base word groups: kombina (personal names), kombinaaw (spouse), kombinaak (child), and kombinaac (pet and company) (lines 118-138 and 151-172).

Phase 2: Systematic Word Combination

Step 6: Core Concatenations with Dates and Years The komb() function combines name groups with birthday fragments and years. The dictionary kombi is populated with specific indices:

  • kombi[1]: Personal names plus birthday fragments (with optional "_")
  • kombi[2]: Spouse names plus spouse birthday fragments
  • kombi[3]: Child names plus child birthday fragments
  • kombi[4] through kombi[11]: All groups combined with year lists (lines 176-206).

Step 7: Numeric Suffix Integration When random numbers are enabled, kombi[12] through kombi[16] and kombi[21] receive numeric ranges via the concats() function (lines 212-218).

Step 8: Reversed String Combinations The script generates combinations using reversed name lists (rev_name, rev_wname, rev_kname) combined with years, birthday fragments, and special characters (lines 220-226).

Step 9: Special Character Appends If special characters were requested, the script generates additional entries komb001 through komb006 that append those characters to earlier word groups (lines 232-240).

Phase 3: Deduplication and Final Processing

Step 10: Sub-list Deduplication Each kombi[i] entry is converted to a unique list stored in komb_unique[i] to eliminate duplicates within individual combination sets (lines 244-247).

Step 11: Final Pool Collection The script concatenates all birthday lists, the reverse list, unique name groups, and all kombi sets into a single uniqlist (lines 250-274).

Step 12: Leet Transformation When "Leet mode" is enabled, each entry in the final list is passed through make_leet() and appended to unique_leet (lines 276-283).

Step 13: Length Constraint Filtering Passwords are filtered to retain only those with lengths between wcfrom and wcto as defined in cupp.cfg (lines 286-291).

Step 14: Dictionary File Export The resulting list is written to disk via print_to_file() as <victim>.txt (lines 293-295).

Programmatic Pipeline Execution

Below is a minimal example demonstrating how the 14-step pipeline is triggered programmatically. The same sequence executes when running cupp.py -i interactively:

import cupp

# Load configuration (required for lengths, specials, etc.)

cupp.read_config('cupp.cfg')

# Fake profile – normally gathered interactively

profile = {
    "name": "alice",
    "surname": "smith",
    "nick": "ali",
    "birthdate": "01011990",
    "wife": "bob",
    "wifen": "bobby",
    "wifeb": "02021985",
    "kid": "charlie",
    "kidn": "chaz",
    "kidb": "15051995",
    "pet": "fluffy",
    "company": "acme",
    "words": ["secret", "admin"],
    "spechars1": "y",          # add special chars

    "randnum": "y",            # add numbers

    "leetmode": "y",           # leet conversion

}
cupp.generate_wordlist_from_profile(profile)

Running this snippet produces alice.txt containing all generated password candidates in the exact order described above.

Summary

  • CUPP processes profile data through generate_wordlist_from_profile() in cupp.py using a fixed 14-step sequence.
  • Phase 1 prepares raw data: special characters, birthday fragments, name variants, and base word groups.
  • Phase 2 systematically concatenates these elements with dates, years, numbers, and special characters.
  • Phase 3 deduplicates entries, applies optional leet transformation, filters by length constraints from cupp.cfg, and writes the final wordlist.

Frequently Asked Questions

What function controls the order of password generation in CUPP?

The generate_wordlist_from_profile() function in cupp.py encapsulates the entire pipeline, executing 14 distinct steps from raw profile parsing to final file output. This function is called both interactively through the CLI and programmatically to ensure consistent generation order.

How does CUPP handle special characters in the generation pipeline?

Special characters are collected first (if enabled) and stored in profile["spechars"], then appended to word groups in two phases: initial combinations with base words (Step 6) and final dedicated combinations (Step 9) via komb001 through komb006.

When does leet transformation occur during password generation?

Leet transformation happens near the end of the pipeline (Step 12) after all concatenations and deduplication are complete. The make_leet() function processes each entry in the final unique list before length filtering occurs.

Can the order of operations in CUPP be modified?

The order is hardcoded in cupp.py within the generate_wordlist_from_profile() function. While you cannot change the sequence without editing the source, you can influence which steps execute by enabling or disabling options in the interactive profile or the configuration file.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →