What Separator Characters Does CUPP Use When Combining Words?

CUPP uses either an empty string (no separator) or an underscore (_) when combining words in its password generation algorithm, controlled by the special parameter in the komb helper function.

The Common User Passwords Profiler (CUPP) generates wordlist entries by concatenating personal information fragments using specific separator logic defined in the Mebus/cupp repository. Understanding what separator characters CUPP uses helps security researchers analyze how the tool constructs password candidates from combined data points like names, birthdates, and keywords.

The komb Function and Separator Logic

In cupp.py, lines 1010–1014, the komb function handles all word concatenation operations:

def komb(seq, start, special=""):
    for mystr in seq:
        for mystr1 in start:
            yield mystr + special + mystr1

The special parameter defines the separator character inserted between two string fragments. The function iterates through two sequences (seq and start), yielding combined strings with the specified separator placed between them.

Default Empty String Concatenation

By default, special is an empty string (""), which concatenates words without any intervening characters. This creates compact password variants where fragments are glued directly together.

For example, when combining ['john', 'doe'] with ['1990', '2000'] using the default parameter:


# No separator (default behavior)

for candidate in komb(['john', 'doe'], ['1990', '2000']):
    print(candidate)

# Output:

# john1990

# john2000

# doe1990

# doe2000

Explicit Underscore Separation

The CUPP codebase frequently invokes komb with "_" as the separator argument to generate variants containing underscores. According to the source analysis, you can see these explicit calls at:

When passing the underscore separator:


# Using underscore as separator

for candidate in komb(['john', 'doe'], ['1990', '2000'], "_"):
    print(candidate)

# Output:

# john_1990

# john_2000

# doe_1990

# doe_2000

The underscore variant creates more readable password candidates that match common user patterns of separating words with punctuation.

Configuration and Limitations

While cupp.cfg contains configuration values for special characters used elsewhere in the tool, it does not define or override the separator logic used by the komb function. The separator behavior remains hardcoded in the function calls throughout cupp.py, limited to either empty string concatenation or underscore insertion.

Summary

  • Empty string (""): Default separator in komb that joins words directly without spaces or characters
  • Underscore ("_"): Explicitly passed in multiple calls throughout cupp.py (lines 1085–1090) to create separated variants
  • Implementation location: The komb function is defined in cupp.py at lines 1010–1014
  • Configuration independence: cupp.cfg does not control separator characters; logic is hardcoded in function calls

Frequently Asked Questions

What is the default separator in CUPP's word combination logic?

The default separator is an empty string. When the komb function is called without specifying the special parameter, it concatenates words directly together, producing outputs like john1990 rather than john_1990.

Where is the word combination logic implemented in the CUPP source code?

The combination logic resides in the komb function defined in cupp.py at lines 1010–1014. This generator function yields Cartesian product combinations of two input sequences with an optional separator inserted between elements.

Can CUPP use separators other than underscores?

While the komb function accepts any string via the special parameter, the CUPP implementation specifically uses only empty strings or underscores in its actual calls. The codebase does not invoke komb with other separators like hyphens or dots in the analyzed version.

Does modifying cupp.cfg change the separator behavior?

No. The cupp.cfg file contains configuration for special characters and wordlists, but it does not affect the separator logic. The separator characters are hardcoded in the function calls within cupp.py, specifically using either the default empty string or explicit underscore arguments.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →