How CUPP Generates Password Combinations from Birthday Information
CUPP extracts seven numeric fragments from a DDMMYYYY birthdate and generates every possible single, double, and triple concatenation of these parts to build comprehensive birthday-derived password candidates.
The Common User Passwords Profiler (CUPP) is an open-source tool in the Mebus/cupp repository designed to create targeted wordlists for penetration testing. When profiling a victim, the tool heavily utilizes password combinations from birthday information to mimic common human patterns. In cupp.py, the function generate_wordlist_from_profile orchestrates this transformation by slicing the input date into multiple components and recombinating them exhaustively.
Extracting Date Fragments from the Birthdate
CUPP expects birthdates in strict DDMMYYYY format. When provided, the code slices this string into seven distinct variables that capture different representations of the date.
The Seven Date Components
According to lines 93-102 in cupp.py, the extraction uses simple string slicing:
- Two-digit year (
YY):profile["birthdate"][-2:](e.g.,92from1992) - Three-digit year (
YYY):profile["birthdate"][-3:](e.g.,992) - Four-digit year (
YYYY):profile["birthdate"][-4:](e.g.,1992) - Single-digit day (
D):profile["birthdate"][1:2](e.g.,4from24) - Single-digit month (
M):profile["birthdate"][3:4](e.g.,8from08) - Two-digit day (
DD):profile["birthdate"][:2](e.g.,24) - Two-digit month (
MM):profile["birthdate"][2:4](e.g.,08)
These extractions ensure coverage of both full and abbreviated date formats that users commonly employ in passwords.
Building the Birthday-Derived String List
Following extraction, CUPP aggregates these fragments into a list named bds (birthday-derived strings). As implemented at lines 124-132:
bds = [
birthdate_yy, birthdate_yyy, birthdate_yyyy,
birthdate_xd, birthdate_xm, birthdate_dd, birthdate_mm,
]
This list serves as the foundation for all subsequent combination generation, containing every individual numeric representation of the victim's birthdate.
Generating Concatenated Combinations
The core permutation logic resides in the nested loop structure at lines 134-150. CUPP generates order-independent combinations by concatenating 1, 2, or 3 distinct elements from the bds list.
Single, Double, and Triple Part Combinations
The algorithm ensures each element is used at most once per combination to prevent duplicates like YYYY appearing twice:
bdss = []
for bds1 in bds:
bdss.append(bds1) # single part
for bds2 in bds:
if bds.index(bds1) != bds.index(bds2):
bdss.append(bds1 + bds2) # two-part combo
for bds3 in bds:
if (bds.index(bds1) != bds.index(bds2) and
bds.index(bds2) != bds.index(bds3) and
bds.index(bds1) != bds.index(bds3)):
bdss.append(bds1 + bds2 + bds3) # three-part combo
This produces fragments such as:
92(YY alone)2408(DD + MM)9921992(YYY + YYYY)4241992(D + DD + YYYY)
Merging Birthday Fragments with Name-Based Passwords
The resulting list bdss does not stand alone. At line 184, CUPP integrates these birthday strings into the broader wordlist construction:
kombi[1] = list(bdss) # Birthday fragments added to combination dictionary
Depending on user-selected options in cupp.cfg, the tool further processes these fragments by:
- Appending special characters (e.g.,
92!,24081992#) - Adding numeric suffixes (e.g.,
24081992_01) - Combining with name derivatives (e.g.,
alice2408)
Practical Example
Running CUPP in interactive mode demonstrates the output:
$ python3 cupp.py -i
[+] Insert the information about the victim to make a dictionary
> First Name: alice
> Surname: smith
> Nickname: ali
> Birthdate (DDMMYYYY): 24081992
...
From the birthdate 24081992, CUPP generates candidates including:
92
1992
2
8
24
08
2408
24081992
921992
22408
2408199224
If special-character options are enabled, the list expands to include variations like 92!, 24081992#, and 24081992_01.
Summary
- CUPP parses birthdates in DDMMYYYY format into seven distinct numeric fragments (YY, YYY, YYYY, D, M, DD, MM).
- The function
generate_wordlist_from_profileincupp.py(lines 71-104) orchestrates the extraction and combination logic. - The tool generates all single, double, and triple concatenations of these date parts, ensuring no duplicate elements within a single combination.
- The resulting
bdsslist merges with name-based passwords at line 184 to create the final targeted wordlist. - Optional configurations in
cupp.cfgallow appending special characters and numbers to these birthday-derived fragments.
Frequently Asked Questions
What date format does CUPP require for birthday input?
CUPP requires the birthdate in DDMMYYYY format (day, month, year as eight digits). The code at lines 93-102 in cupp.py uses string slicing indices that assume this exact structure to extract two-digit days, two-digit months, and various year representations.
How many unique password fragments does CUPP generate from a single birthdate?
From the seven extracted date parts, CUPP generates all possible 1-part, 2-part, and 3-part combinations using nested loops (lines 134-150). This creates dozens of unique numeric strings ranging from single components like 92 or 24 to complex concatenations like 24081992 or 9922408.
Does CUPP prevent duplicate birthday combinations in the wordlist?
Yes. The combination logic explicitly checks bds.index(bds1) != bds.index(bds2) and similar conditions for three-part combinations. This ensures each date fragment is used at most once per combination, preventing redundant permutations such as 19921992 or 2424.
How are birthday fragments combined with name-based passwords?
CUPP merges the birthday list (bdss) with name-derived strings through the kombi dictionary at line 184. The tool concatenates birthday fragments with names, nicknames, and additional separators (like underscores) based on configuration options defined in cupp.cfg, creating realistic passwords such as alice1992 or smith_2408.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →