GO KALI FREE

CUPP

Password Attacks

Beginnerlow risk

CUPP (Common User Passwords Profiler) creates custom wordlists based on target personal information like names, birthdays, nicknames, pets, and keywords.

Installation

git clone https://github.com/Mebus/cupp.git

Basic Syntax

python3 cupp.py -i

Quick Facts

Full Name
CUPP (Common User Passwords Profiler)
License
GPLv3
Author
Mebus
Written In
Python
Platforms
Linux, macOS, Windows
Category
Wordlist Generation
Input Method
Interactive profiling / OSINT
Key Feature
Personal information-based wordlists

Tool Overview

CUPP (Common User Passwords Profiler) is a Python-based tool that generates personalized wordlists based on information about a specific target. Unlike generic wordlists, CUPP creates dictionaries using the target's name, birthday, pet names, and other personal details.

CUPP works by interactively collecting information about the target — including names, birthdates, partners, children, pets, and company details — then generating password variations based on common password patterns people use with personal information.

For social engineering engagements, CUPP is invaluable. People often use personal information in their passwords (like birthdates, pet names, or anniversaries), and CUPP systematically generates these variations for highly targeted password attacks.

Common Commands

cupp -hShow CUPP usage and all available options
cupp --helpDisplay the full help text for CUPP
cupp -iStart interactive mode to profile a target's password wordlist
cupp --interactiveRun the guided interactive questionnaire (long form)
cupp -w existing.txtImprove an existing dictionary with word mangling
cupp -lDownload huge premade wordlists from the repository
cupp -aParse default vendor usernames and passwords from the Alecto DB
cupp -vShow the CUPP version
cupp --versionPrint the program version (long form)
cupp -qRun in quiet mode without printing the banner
cupp -q -iInteractive profiling with the banner suppressed
python3 cupp.py -iRun CUPP directly from the cloned source in interactive mode
git clone https://github.com/Mebus/cupp.gitClone the CUPP source repository
sudo apt install cuppInstall CUPP from the Kali repositories
cupp -w /path/to/fileFeed a WyD.pl or wordlist file for enhancement

Step-by-Step Guide

  1. 1Collect background intelligence on your subject
  2. 2Start the script and select the interactive option
  3. 3Provide the requested details into the terminal prompts
  4. 4Examine the finalized output file
  5. 5Deploy this highly targeted list in your subsequent attacks

Warnings

Use Cases

Social Engineering

Generate wordlists from target's personal information gathered through OSINT.

Targeted Penetration Testing

Create personalized dictionaries for specific individuals during authorized engagements.

Password Policy Auditing

Test whether employees use personal information in their passwords.

CTF Challenges

Solve challenges requiring personal information-based password cracking.

Red Team Operations

Build targeted wordlists from OSINT data for credential attacks.

Key Features

People Also Ask

Is it legal to use CUPP?

CUPP generates candidate password wordlists and is intended for authorized password-strength and policy auditing — for example, testing whether your own organization's accounts resist personalized guessing, with documented consent. Building profiles to target real individuals without their permission is unethical and often illegal. Only use it within a sanctioned engagement on accounts you are cleared to assess.

Is CUPP pre-installed in Kali Linux?

Recent Kali releases do not always include CUPP by default. Install it from the repositories with `sudo apt install cupp`, or clone the project and run it directly with `git clone https://github.com/Mebus/cupp.git`. Then launch it with `cupp.py -i` or `python3 cupp.py -i`.

What Python version does CUPP require?

Current CUPP is written for Python 3, which is already present on Kali Linux. Run it with `python3 cupp.py` if the plain `cupp` command is unavailable. Older Python 2 forks exist but are unmaintained and should be avoided.

How do I download CUPP's additional wordlists?

CUPP can fetch community and common-password lists with the `-l` flag (`cupp.py -l`) and update its bundled dictionaries with `-a`. These supplement a personalized list during authorized audits. Always review any downloaded list before using it.

What is the difference between CUPP and Crunch?

Crunch builds wordlists purely from character-set patterns you specify, independent of any target. CUPP instead builds a personalized list from profile details (used only with consent for authorized auditing), producing far fewer but more targeted candidates. They typically serve different phases of a sanctioned password-strength assessment.

How do I run CUPP in interactive profiling mode?

Launch `cupp.py -i` to start the interactive questionnaire, which prompts for profile details and then writes a wordlist. This mode is intended for authorized assessments — for instance, checking whether staff accounts (with organizational consent) rely on guessable personal information. Combine the output with strength-testing tools only against systems you are permitted to test.

Related Tools

CeWL

Password Attacks

Website-based wordlist generator for target-specific dictionaries.

John the Ripper

Password Attacks

Password cracker that uses CUPP-generated personalized wordlists.

Hashcat

Password Attacks

GPU-accelerated cracker for maximum speed with CUPP-generated wordlists.

Crunch

Password Attacks

Pattern-based wordlist generator for supplementing CUPP output with pattern variations.

Medusa

Password Attacks

Online brute-forcer for testing CUPP-generated passwords against live services.

Frequently Asked Questions

What is CUPP?

CUPP (Common User Passwords Profiler) is a Python tool that generates personalized wordlists based on information about a specific target. It creates dictionaries using personal details like names, birthdays, pet names, and company information for targeted password attacks.

How do I use CUPP for social engineering?

Gather personal information about the target through OSINT (LinkedIn, social media, public records), then run python3 cupp.py -i and answer the interactive questions with the collected data. CUPP generates a wordlist of common passwords based on that information.

What information does CUPP need?

CUPP works best with: first/last name, birthdate, partner's name, children's names, pet names, company name, keywords, and favorite words. More detailed information produces more effective wordlists.

Can I enhance CUPP output with rules?

Yes! CUPP generates base variations. Feed the output into John the Ripper or Hashcat with rules for mutations like leetspeak, capitalization, and symbols: john --rules --wordlist=cupp_output.txt hashes.txt

How do I gather OSINT for CUPP?

Use social media (LinkedIn, Facebook, Instagram), public records, company websites, people search engines, and breach databases. TheHarvester extracts emails; Sherlock finds social media profiles for target intelligence.

Can CUPP work in non-interactive mode?

Yes, use -a for aggressive mode which generates a comprehensive list without prompts. You can also create profile files with target information and load them with -l for batch processing.

What makes CUPP different from CeWL?

CUPP targets individuals using personal information (names, birthdays, pets). CeWL targets organizations by spidering websites. Use CUPP for specific people, CeWL for organization-wide wordlists.

How many passwords does CUPP typically generate?

CUPP generates 5,000-50,000 variations depending on the input information. More detailed profiles produce larger, more effective wordlists. The quality depends heavily on the accuracy of gathered OSINT data.

Can CUPP generate passwords for specific languages?

CUPP works best with English names and patterns. For other languages, manually enter translated names and cultural variations in the interactive mode. The generated patterns apply universally across languages.

How do I verify CUPP-generated passwords are effective?

Compare against known password patterns using统计 analysis. Most CUPP-generated passwords follow predictable patterns (Name+Year, Name+Symbol, etc.). Validate by testing against a sample of known compromised passwords.

Can CUPP run in non-interactive mode?

Yes, use -a for aggressive mode which generates a comprehensive list without prompts. You can also create profile files with target information and load them with -l for batch processing.

How do I combine CUPP output with other wordlists?

Concatenate CUPP output with other wordlists: cat cewl_output.txt rockyou.txt | sort -u > combined.txt. The -u flag removes duplicates for a clean, combined wordlist optimized for password cracking.

What operating systems does CUPP support?

CUPP is a Python script that runs on any system with Python 3 installed. It works on Linux, macOS, Windows, and any platform supporting Python. No additional dependencies are required.

Can CUPP generate passwords from company information?

Yes, include company name, products, slogans, and keywords in the interactive prompts. CUPP generates passwords combining personal details with company-related terms, useful for corporate social engineering assessments.

How many passwords does CUPP typically generate?

CUPP generates 5,000-50,000 variations depending on the input information. More detailed profiles produce larger, more effective wordlists. The quality depends heavily on the accuracy of gathered OSINT data.

How do I improve CUPP output with mutation rules?

Feed CUPP output into John the Ripper or Hashcat with rules: john --rules --wordlist=cupp_output.txt hashes.txt. Rules mutate base words into common password variations like leetspeak, capitalization, and symbol additions.

Can CUPP be used for security awareness training?

Yes, CUPP demonstrates how personal information is used in targeted attacks. Show employees how their public social media profiles could be used to generate their password, reinforcing the importance of strong, unique passwords.

How do I gather OSINT for CUPP profiling?

Use social media (LinkedIn, Facebook, Instagram), public records, company websites, people search engines, and breach databases. theHarvester extracts emails; Sherlock finds social media profiles for target intelligence gathering.

Can CUPP handle multiple targets at once?

CUPP profiles one target at a time in interactive mode. For multiple targets, create separate profile files or run CUPP in a loop. The -l flag loads pre-made profile files for batch wordlist generation.

Tags

#password-attacks

Output Explanation

Produces a customized dictionary file containing variations and combinations of the subject's personal data.

Ethical Usage Notice

This tool is designed for authorized security testing, educational purposes, and legitimate network administration only. Unauthorized access to computer systems is illegal.