How to Work with Combo Files (COMBO00, COMBO01) for Username:Password Lists in Patator

Patator processes multi-column credential files using the COMBO<file-id><column-id> placeholder syntax, where you specify which column maps to which payload position directly in your command arguments.

Patator's combo file mechanism allows you to reference specific columns from delimited text files without pre-processing your wordlists. This feature treats credential lists as CSV-like data sources, enabling you to map usernames, passwords, and additional fields to distinct payload positions while maintaining their row relationships according to the implementation in lanjelot/patator.

Understanding the COMBO Syntax

Patator implements a positional placeholder system for accessing individual columns within combo files. The syntax follows the pattern COMBO<file-id><column-id>:

  • <file-id> – The numeric index of the combo file as it appears in the command line arguments. The first combo file specified after the module options is 0, the second is 1, and so on.

  • <column-id> – The zero-based column number inside that specific file.

When Patator builds the payload product, it replaces every occurrence of COMBOxy with the value from column y of file x. By default, Patator splits each line on the colon character (:), though this delimiter is configurable.

Source Code Implementation

The core combo file logic resides in src/patator/patator.py. Three specific areas handle the parsing and substitution:

Placeholder Detection

The find_combo_keys function (lines 31-33) scans payload strings and returns a list of (file-id, column-id) tuples identifying which columns Patator needs to extract.

Runtime Substitution

The actual value replacement occurs in the substitution loop (lines 1356-1359):

payload[k] = payload[k].replace(
    'COMBO%d%d' % (i, j),
    prod[i].split(self.combo_delim, max(j for j, _ in keys))[j])

This code splits the raw line prod[i] from the i-th combo file on self.combo_delim (set via the global -C option), ensuring the split creates enough fields to access the maximum requested column index.

Delimiter Configuration

The combo delimiter defaults to : but can be modified using the -C command-line option defined at line 819.

Basic Usage Examples

To implement username:password spraying with combo files, follow these workflow patterns:

1. Create a Combo File

Structure your credentials with the default colon delimiter:

admin:admin123
guest:guest
alice:alicePwd
root:toor

Save this as combos.txt.

2. Reference Columns in Your Command

Map file 0 (the first combo file) to your payload positions:

patator http_fuzz url=http://10.0.0.1/login \
    user=COMBO00 password=COMBO01 \
    0=combos.txt \
    -x ignore:code=401

In this example:

  • COMBO00 extracts column 0 (usernames) from combos.txt
  • COMBO01 extracts column 1 (passwords) from combos.txt

3. Use Multiple Combo Files

You can reference several combo files simultaneously by incrementing the file-id:

patator http_fuzz url=http://example.com/login \
    user=COMBO00 password=COMBO01 \
    domain=COMBO10 \
    0=users.txt 1=domains.txt \
    -x ignore:code=401

Here, COMBO00 and COMBO01 target columns from users.txt (file 0), while COMBO10 targets column 0 from domains.txt (file 1).

Advanced Configuration Options

Custom Delimiters

If your credential file uses comma separators instead of colons, specify the delimiter with -C:

patator http_fuzz url=http://host/login \
    user=COMBO00 password=COMBO01 \
    0=combos.csv \
    -C ',' \
    -x ignore:code=401

Combining with Other Payload Types

The COMBO mechanism integrates with FILE, NET, RANGE, and other payload generators because Patator constructs a Cartesian product of all payload sets before performing placeholder substitution. This allows you to combine static combo credentials with dynamic host lists or numeric ranges.

Summary

  • Patator uses the COMBO<file-id><column-id> syntax to map specific columns from delimited files to payload positions
  • File IDs are assigned sequentially starting from 0 based on argument order; column IDs are zero-indexed
  • The default delimiter is :, configurable via the -C global option
  • Source implementation in src/patator/patator.py handles detection via find_combo_keys (lines 31-33) and substitution (lines 1356-1359)
  • Multiple combo files can be used simultaneously by incrementing the file ID in subsequent arguments

Frequently Asked Questions

What is the maximum number of columns supported in a Patator combo file?

Patator dynamically determines the maximum column index needed based on your COMBO placeholders. The split() operation uses max(j for j, _ in keys) to ensure enough fields are created, so you are limited only by Python's string processing capabilities and available memory, not by an arbitrary column limit.

Can I use spaces or tabs as delimiters in combo files?

Yes, you can specify any single character as the delimiter using the -C option. For a tab delimiter, you would use -C $'\t' in Bash or quote the tab character appropriately. The source code at line 819 in src/patator/patator.py stores this in self.combo_delim and applies it during the substitution phase.

How does Patator handle missing columns in a combo file line?

If a line in your combo file contains fewer columns than requested by your highest COMBO column-id, Python's split() with the maxsplit parameter will return a list shorter than expected, causing an IndexError during substitution. Ensure all lines contain sufficient fields or preprocess your lists to handle empty values (e.g., using placeholder text for blank passwords).

Can I mix COMBO placeholders with standard FILE inputs in the same attack?

Absolutely. Patator builds a Cartesian product (or pitchfork with --groups) across all payload types before performing placeholder substitution. You can combine 0=combos.txt with 1=hosts.txt and reference both COMBO00 for usernames and FILE1 for target hosts in the same command.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →