# How to Work with Combo Files (COMBO00, COMBO01) for Username:Password Lists in Patator

> Learn to effectively work with combo files in Patator. Discover how to use COMBO00 COMBO01 placeholders for username:password lists and map columns directly in your command arguments.

- Repository: [lanjelot/patator](https://github.com/lanjelot/patator)
- Tags: how-to-guide
- Published: 2026-03-05

---

**Patator processes multi-column credential files using the `COMBO<file-id><column-id>` placeholder syntax, where you specify which column maps to which payload position directly in your command arguments.**

Patator's combo file mechanism allows you to reference specific columns from delimited text files without pre-processing your wordlists. This feature treats credential lists as CSV-like data sources, enabling you to map usernames, passwords, and additional fields to distinct payload positions while maintaining their row relationships according to the implementation in `lanjelot/patator`.

## Understanding the COMBO Syntax

Patator implements a positional placeholder system for accessing individual columns within combo files. The syntax follows the pattern `COMBO<file-id><column-id>`:

- **`<file-id>`** – The numeric index of the combo file as it appears in the command line arguments. The first combo file specified after the module options is `0`, the second is `1`, and so on.

- **`<column-id>`** – The zero-based column number inside that specific file.

When Patator builds the payload product, it replaces every occurrence of `COMBOxy` with the value from column *y* of file *x*. By default, Patator splits each line on the colon character (`:`), though this delimiter is configurable.

## Source Code Implementation

The core combo file logic resides in [`src/patator/patator.py`](https://github.com/lanjelot/patator/blob/main/src/patator/patator.py). Three specific areas handle the parsing and substitution:

**Placeholder Detection**

The `find_combo_keys` function (lines 31-33) scans payload strings and returns a list of `(file-id, column-id)` tuples identifying which columns Patator needs to extract.

**Runtime Substitution**

The actual value replacement occurs in the substitution loop (lines 1356-1359):

```python
payload[k] = payload[k].replace(
    'COMBO%d%d' % (i, j),
    prod[i].split(self.combo_delim, max(j for j, _ in keys))[j])

```

This code splits the raw line `prod[i]` from the *i*-th combo file on `self.combo_delim` (set via the global `-C` option), ensuring the split creates enough fields to access the maximum requested column index.

**Delimiter Configuration**

The combo delimiter defaults to `:` but can be modified using the `-C` command-line option defined at line 819.

## Basic Usage Examples

To implement username:password spraying with combo files, follow these workflow patterns:

**1. Create a Combo File**

Structure your credentials with the default colon delimiter:

```text
admin:admin123
guest:guest
alice:alicePwd
root:toor

```

Save this as [`combos.txt`](https://github.com/lanjelot/patator/blob/main/combos.txt).

**2. Reference Columns in Your Command**

Map file `0` (the first combo file) to your payload positions:

```bash
patator http_fuzz url=http://10.0.0.1/login \
    user=COMBO00 password=COMBO01 \
    0=combos.txt \
    -x ignore:code=401

```

In this example:

- `COMBO00` extracts column 0 (usernames) from [`combos.txt`](https://github.com/lanjelot/patator/blob/main/combos.txt)
- `COMBO01` extracts column 1 (passwords) from [`combos.txt`](https://github.com/lanjelot/patator/blob/main/combos.txt)

**3. Use Multiple Combo Files**

You can reference several combo files simultaneously by incrementing the file-id:

```bash
patator http_fuzz url=http://example.com/login \
    user=COMBO00 password=COMBO01 \
    domain=COMBO10 \
    0=users.txt 1=domains.txt \
    -x ignore:code=401

```

Here, `COMBO00` and `COMBO01` target columns from [`users.txt`](https://github.com/lanjelot/patator/blob/main/users.txt) (file 0), while `COMBO10` targets column 0 from [`domains.txt`](https://github.com/lanjelot/patator/blob/main/domains.txt) (file 1).

## Advanced Configuration Options

**Custom Delimiters**

If your credential file uses comma separators instead of colons, specify the delimiter with `-C`:

```bash
patator http_fuzz url=http://host/login \
    user=COMBO00 password=COMBO01 \
    0=combos.csv \
    -C ',' \
    -x ignore:code=401

```

**Combining with Other Payload Types**

The `COMBO` mechanism integrates with `FILE`, `NET`, `RANGE`, and other payload generators because Patator constructs a Cartesian product of all payload sets before performing placeholder substitution. This allows you to combine static combo credentials with dynamic host lists or numeric ranges.

## Summary

- Patator uses the `COMBO<file-id><column-id>` syntax to map specific columns from delimited files to payload positions
- File IDs are assigned sequentially starting from `0` based on argument order; column IDs are zero-indexed
- The default delimiter is `:`, configurable via the `-C` global option
- Source implementation in [`src/patator/patator.py`](https://github.com/lanjelot/patator/blob/main/src/patator/patator.py) handles detection via `find_combo_keys` (lines 31-33) and substitution (lines 1356-1359)
- Multiple combo files can be used simultaneously by incrementing the file ID in subsequent arguments

## Frequently Asked Questions

### What is the maximum number of columns supported in a Patator combo file?

Patator dynamically determines the maximum column index needed based on your `COMBO` placeholders. The `split()` operation uses `max(j for j, _ in keys)` to ensure enough fields are created, so you are limited only by Python's string processing capabilities and available memory, not by an arbitrary column limit.

### Can I use spaces or tabs as delimiters in combo files?

Yes, you can specify any single character as the delimiter using the `-C` option. For a tab delimiter, you would use `-C $'\t'` in Bash or quote the tab character appropriately. The source code at line 819 in [`src/patator/patator.py`](https://github.com/lanjelot/patator/blob/main/src/patator/patator.py) stores this in `self.combo_delim` and applies it during the substitution phase.

### How does Patator handle missing columns in a combo file line?

If a line in your combo file contains fewer columns than requested by your highest `COMBO` column-id, Python's `split()` with the maxsplit parameter will return a list shorter than expected, causing an IndexError during substitution. Ensure all lines contain sufficient fields or preprocess your lists to handle empty values (e.g., using placeholder text for blank passwords).

### Can I mix COMBO placeholders with standard FILE inputs in the same attack?

Absolutely. Patator builds a Cartesian product (or pitchfork with `--groups`) across all payload types before performing placeholder substitution. You can combine `0=combos.txt` with `1=hosts.txt` and reference both `COMBO00` for usernames and `FILE1` for target hosts in the same command.