Version 4.1.19
This commit is contained in:
1 parent
28bd025b35
commit
2bd5025018
2674 files changed
+233518
-77766
No files matched your search
+173
-101
@@ -2,9 +2,9 @@
|
||||
/**
|
||||
* @brief Converter Login Handler
|
||||
* @author <a href='http://www.invisionpower.com'>Invision Power Services, Inc.</a>
|
||||
* @copyright (c) 2001 - SVN_YYYY Invision Power Services, Inc.
|
||||
* @copyright (c) 2001 - 2016 Invision Power Services, Inc.
|
||||
* @license http://www.invisionpower.com/legal/standards/
|
||||
* @package IPS Social Suite
|
||||
* @package IPS Community Suite
|
||||
* @since 14 Oct 2014
|
||||
* @version SVN_VERSION_NUMBER
|
||||
*/
|
||||
@@ -76,46 +76,68 @@ class _Convert extends LoginAbstract
|
||||
throw new \IPS\Login\Exception( \IPS\Member::loggedIn()->language()->addToStack( 'login_err_no_account', FALSE, array( 'sprintf' => array( \IPS\Member::loggedIn()->language()->addToStack( $this->getLoginType( $this->authTypes ) ) ) ) ), \IPS\Login\Exception::NO_ACCOUNT );
|
||||
}
|
||||
|
||||
/* Table switcher for new IPS4 converters */
|
||||
$table = 'conv_apps';
|
||||
if ( \IPS\Db::i()->checkForTable( 'convert_apps' ) )
|
||||
/* Table switcher for new IPS4 converters */
|
||||
try
|
||||
{
|
||||
$table = 'convert_apps';
|
||||
}
|
||||
|
||||
$apps = \IPS\Db::i()->select( 'app_key', $table, array( 'login=?', 1 ) );
|
||||
|
||||
foreach( $apps as $sw )
|
||||
{
|
||||
/* loop found members */
|
||||
foreach( $members as $member )
|
||||
try
|
||||
{
|
||||
/* Check the app method exists */
|
||||
if ( !method_exists( $this, $sw ) )
|
||||
$apps = \IPS\Db::i()->select( 'app_key', 'convert_apps', array( 'login=?', 1 ) );
|
||||
}
|
||||
catch ( \IPS\Db\Exception $e )
|
||||
{
|
||||
if ( $e->getCode() === 1146 )
|
||||
{
|
||||
continue;
|
||||
$apps = \IPS\Db::i()->select( 'app_key', 'conv_apps', array( 'login=?', 1 ) );
|
||||
}
|
||||
|
||||
if ( $this->$sw( $member, $values[ 'password' ] ) )
|
||||
else
|
||||
{
|
||||
/* Update password and return */
|
||||
if ( \IPS\Db::i()->checkForColumn( 'core_members', 'misc' ) )
|
||||
throw $e;
|
||||
}
|
||||
}
|
||||
|
||||
foreach( $apps as $sw )
|
||||
{
|
||||
/* loop found members */
|
||||
foreach( $members as $member )
|
||||
{
|
||||
/* Check the app method exists */
|
||||
if ( !method_exists( $this, $sw ) )
|
||||
{
|
||||
$member->misc = "";
|
||||
continue;
|
||||
}
|
||||
$member->conv_password = "";
|
||||
$member->members_pass_salt = $member->generateSalt();
|
||||
$member->members_pass_hash = $member->encryptedPassword( $values[ 'password' ] );
|
||||
$member->save();
|
||||
$member->memberSync( 'onPassChange', array( $values[ 'password' ] ) );
|
||||
|
||||
return $member;
|
||||
/* We still want to use the parent methods (no sense in recreating them) so copy conv_password_extra to misc */
|
||||
$member->misc = $member->conv_password_extra;
|
||||
$success = $this->$sw( $member, $values['password'] );
|
||||
|
||||
unset( $member->misc );
|
||||
unset( $member->changed['misc'] );
|
||||
if ( $success )
|
||||
{
|
||||
/* Update password and return */
|
||||
$member->conv_password = NULL;
|
||||
$member->conv_password_extra = NULL;
|
||||
$member->members_pass_salt = $member->generateSalt();
|
||||
$member->members_pass_hash = $member->encryptedPassword( $values['password'] );
|
||||
$member->save();
|
||||
$member->memberSync( 'onPassChange', array( $values['password'] ) );
|
||||
|
||||
return $member;
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
catch( \IPS\Db\Exception $e )
|
||||
{
|
||||
/* Converter tables no longer exist */
|
||||
if( $e->getCode() == 1146 )
|
||||
{
|
||||
throw new \IPS\Login\Exception( 'generic_error', \IPS\Login\Exception::INTERNAL_ERROR );
|
||||
}
|
||||
}
|
||||
|
||||
/* Still here? Throw a password incorrect exception */
|
||||
throw new \IPS\Login\Exception( 'login_err_bad_password', \IPS\Login\Exception::BAD_PASSWORD, NULL, $member );
|
||||
throw new \IPS\Login\Exception( 'login_err_bad_password', \IPS\Login\Exception::BAD_PASSWORD, NULL, isset( $member ) ? $member : NULL );
|
||||
}
|
||||
|
||||
/**
|
||||
@@ -191,7 +213,7 @@ class _Convert extends LoginAbstract
|
||||
* @param string $password Password from form
|
||||
* @return bool
|
||||
*/
|
||||
protected function bbpress_standalone( $member, $password )
|
||||
protected function bbpressstandalone( $member, $password )
|
||||
{
|
||||
return $this->bbpress( $member, $password );
|
||||
}
|
||||
@@ -211,7 +233,7 @@ class _Convert extends LoginAbstract
|
||||
|
||||
if ( \strlen( $hash ) == 32 )
|
||||
{
|
||||
$success = ( bool ) ( \IPS\Login::compareHashes( md5( $password ), $member->conv_password ) );
|
||||
$success = ( bool ) ( \IPS\Login::compareHashes( $member->conv_password, md5( $password ) ) );
|
||||
}
|
||||
|
||||
// Nope, not md5.
|
||||
@@ -261,13 +283,10 @@ class _Convert extends LoginAbstract
|
||||
* @return bool
|
||||
*/
|
||||
protected function cs( $member, $password )
|
||||
{
|
||||
$hash = $member->conv_password;
|
||||
|
||||
{
|
||||
$encodedHashPass = base64_encode( pack( "H*", sha1( base64_decode( $member->misc ) . $password ) ) );
|
||||
$single_md5_pass = md5( $password );
|
||||
|
||||
if ( \IPS\Login::compareHashes( $encodedHashPass, $hash ) )
|
||||
if ( \IPS\Login::compareHashes( $member->conv_password, $encodedHashPass ) )
|
||||
{
|
||||
return TRUE;
|
||||
}
|
||||
@@ -284,7 +303,7 @@ class _Convert extends LoginAbstract
|
||||
* @param string $password Password from form
|
||||
* @return bool
|
||||
*/
|
||||
protected function CSAuth( $member, $password )
|
||||
protected function csauth( $member, $password )
|
||||
{
|
||||
$wsdl = 'https://internal.auth.com/Service.asmx?wsdl';
|
||||
$dest = 'https://interal.auth.com/Service.asmx';
|
||||
@@ -329,6 +348,41 @@ class _Convert extends LoginAbstract
|
||||
return FALSE;
|
||||
}
|
||||
|
||||
/**
|
||||
* ExpressionEngine
|
||||
*
|
||||
* @param \IPS\Member $member The member
|
||||
* @param string $password Password from form
|
||||
* @return bool
|
||||
*/
|
||||
protected function expressionengine( $member, $password )
|
||||
{
|
||||
$length = \strlen( $member->conv_password );
|
||||
$providedHash = FALSE;
|
||||
|
||||
switch( $length )
|
||||
{
|
||||
/* MD5 */
|
||||
case 32:
|
||||
$providedHash = md5( $password );
|
||||
break;
|
||||
/* SHA1 */
|
||||
case 40:
|
||||
$providedHash = sha1( $password );
|
||||
break;
|
||||
/* SHA256 */
|
||||
case 64:
|
||||
$providedHash = hash( 'sha256', $password );
|
||||
break;
|
||||
/* SHA512 */
|
||||
case 128:
|
||||
$providedHash = hash( 'sha512', $password );
|
||||
break;
|
||||
}
|
||||
|
||||
return ( \IPS\Login::compareHashes( $member->conv_password, $providedHash ) ) ? TRUE : FALSE;
|
||||
}
|
||||
|
||||
/**
|
||||
* FudForum
|
||||
*
|
||||
@@ -344,11 +398,11 @@ class _Convert extends LoginAbstract
|
||||
|
||||
if ( \strlen( $hash ) == 40 )
|
||||
{
|
||||
$success = ( \IPS\Login::compareHashes( sha1( $member->misc . sha1( $password ) ), $hash ) ) ? TRUE : FALSE;
|
||||
$success = ( \IPS\Login::compareHashes( $member->conv_password, sha1( $member->misc . sha1( $password ) ) ) ) ? TRUE : FALSE;
|
||||
}
|
||||
else
|
||||
{
|
||||
$success = ( \IPS\Login::compareHashes( $single_md5_pass, $hash ) ) ? TRUE : FALSE;
|
||||
$success = ( \IPS\Login::compareHashes( $member->conv_password, $single_md5_pass ) ) ? TRUE : FALSE;
|
||||
}
|
||||
|
||||
return $success;
|
||||
@@ -366,19 +420,19 @@ class _Convert extends LoginAbstract
|
||||
/* FusionBB Has multiple methods that can be used to check a hash, so we need to cycle through them */
|
||||
|
||||
/* md5( md5( salt ) . md5( pass ) ) */
|
||||
if ( \IPS\Login::compareHashes( md5( md5( $member->misc ) . md5( $password ) ), $member->conv_password ) )
|
||||
if ( \IPS\Login::compareHashes( $member->conv_password, md5( md5( $member->misc ) . md5( $password ) ) ) )
|
||||
{
|
||||
return TRUE;
|
||||
}
|
||||
|
||||
/* md5( md5( salt ) . pass ) */
|
||||
if ( \IPS\Login::compareHashes( md5( md5( $member->misc ) . $password ), $member->conv_password ) )
|
||||
if ( \IPS\Login::compareHashes( $member->conv_password, md5( md5( $member->misc ) . $password ) ) )
|
||||
{
|
||||
return TRUE;
|
||||
}
|
||||
|
||||
/* md5( pass ) */
|
||||
if ( \IPS\Login::compareHashes( md5( $password ), $member->conv_password ) )
|
||||
if ( \IPS\Login::compareHashes( $member->conv_password, md5( $password ) ) )
|
||||
{
|
||||
return TRUE;
|
||||
}
|
||||
@@ -399,7 +453,7 @@ class _Convert extends LoginAbstract
|
||||
{
|
||||
return TRUE;
|
||||
}
|
||||
else if ( \IPS\Login::compareHashes( $member->conv_password, md5( $password . $member->name ) ) )
|
||||
else if ( \IPS\Login::compareHashes( $member->conv_password, md5( $password . mb_strtolower( $member->conv_password_extra ) ) ) )
|
||||
{
|
||||
return TRUE;
|
||||
}
|
||||
@@ -480,18 +534,18 @@ class _Convert extends LoginAbstract
|
||||
|
||||
if ( \strlen( $hash ) == 34 )
|
||||
{
|
||||
$success = ( $this->hashCryptPrivate( $password, $hash, $itoa64 ) === $hash ) ? TRUE : FALSE;
|
||||
$success = ( \IPS\Login::compareHashes( $hash, $this->hashCryptPrivate( $password, $hash, $itoa64 ) ) ) ? TRUE : FALSE;
|
||||
}
|
||||
else
|
||||
{
|
||||
$success = ( \IPS\Login::compareHashes( $single_md5_pass, $hash ) ) ? TRUE : FALSE;
|
||||
$success = ( \IPS\Login::compareHashes( $hash, $single_md5_pass ) ) ? TRUE : FALSE;
|
||||
}
|
||||
}
|
||||
|
||||
/* phpBB2 */
|
||||
if ( ! $success )
|
||||
if ( !$success )
|
||||
{
|
||||
$success = ( $this->hashCryptPrivate( $single_md5_hash, $hash, $itoa64 ) === $hash ? TRUE : FALSE );
|
||||
$success = ( \IPS\Login::compareHashes( $hash, $this->hashCryptPrivate( $single_md5_pass, $hash, $itoa64 ) ) ) ? TRUE : FALSE ;
|
||||
}
|
||||
|
||||
return $success;
|
||||
@@ -504,7 +558,7 @@ class _Convert extends LoginAbstract
|
||||
* @param string $password Password from form
|
||||
* @return bool
|
||||
*/
|
||||
protected function phpbb_legacy( $member, $password )
|
||||
protected function phpbblegacy( $member, $password )
|
||||
{
|
||||
return $this->phpbb( $member, $password );
|
||||
}
|
||||
@@ -518,6 +572,13 @@ class _Convert extends LoginAbstract
|
||||
*/
|
||||
protected function vanilla( $member, $password )
|
||||
{
|
||||
/* Vanilla 2.2 */
|
||||
if( preg_match( '/^\$2[ay]\$(0[4-9]|[1-2][0-9]|3[0-1])\$[a-zA-Z0-9.\/]{53}/', $member->conv_password ) )
|
||||
{
|
||||
$ph = new PasswordHash( 8, TRUE );
|
||||
return $ph->CheckPassword( $password, $member->conv_password ) ? TRUE : FALSE;
|
||||
}
|
||||
|
||||
if ( \IPS\Login::compareHashes( $member->conv_password, md5( md5( str_replace( ''', "'", html_entity_decode( $password ) ) ) . $member->misc ) ) )
|
||||
{
|
||||
return TRUE;
|
||||
@@ -566,7 +627,7 @@ class _Convert extends LoginAbstract
|
||||
*/
|
||||
protected function vb5connect( $member, $password )
|
||||
{
|
||||
if ( strpos( $member->misc, 'blowfish' ) === FALSE and strpos( $member->misc, 'legacy' ) === FALSE )
|
||||
if ( \strpos( $member->misc, 'blowfish' ) === FALSE and \strpos( $member->misc, 'legacy' ) === FALSE )
|
||||
{
|
||||
return $this->vbulletin( $member, $password );
|
||||
}
|
||||
@@ -575,6 +636,18 @@ class _Convert extends LoginAbstract
|
||||
return $this->vb51connect( $member, $password );
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* vBulletin 5 Wrapper Method
|
||||
*
|
||||
* @param \IPS|Member $member
|
||||
* @param string $password
|
||||
* @return bool
|
||||
*/
|
||||
public function vbulletin5( $member, $password )
|
||||
{
|
||||
return $this->vb5connect( $member, $password );
|
||||
}
|
||||
|
||||
/**
|
||||
* Vbulletin 4
|
||||
@@ -613,7 +686,7 @@ class _Convert extends LoginAbstract
|
||||
* @param string $password Password from form
|
||||
* @return bool
|
||||
*/
|
||||
protected function vbulletin_legacy( $member, $password )
|
||||
protected function vbulletinlegacy( $member, $password )
|
||||
{
|
||||
return $this->vbulletin( $member, $password );
|
||||
}
|
||||
@@ -625,7 +698,7 @@ class _Convert extends LoginAbstract
|
||||
* @param string $password Password from form
|
||||
* @return bool
|
||||
*/
|
||||
protected function vbulletin_legacy36( $member, $password )
|
||||
protected function vbulletinlegacy36( $member, $password )
|
||||
{
|
||||
return $this->vbulletin( $member, $password );
|
||||
}
|
||||
@@ -680,9 +753,9 @@ class _Convert extends LoginAbstract
|
||||
* @param string $password Password from form
|
||||
* @return bool
|
||||
*/
|
||||
protected function smf_legacy( $member, $password )
|
||||
protected function smflegacy( $member, $password )
|
||||
{
|
||||
if ( \IPS\Login::compareHashes( sha1( strtolower( $member->name ) . $password ), $member->conv_password ) )
|
||||
if ( \IPS\Login::compareHashes( $member->conv_password, sha1( strtolower( $member->name ) . $password ) ) )
|
||||
{
|
||||
return TRUE;
|
||||
}
|
||||
@@ -699,7 +772,7 @@ class _Convert extends LoginAbstract
|
||||
* @param string $password Password from form
|
||||
* @return bool
|
||||
*/
|
||||
protected function telligent_cs( $member, $password )
|
||||
protected function telligentcs( $member, $password )
|
||||
{
|
||||
return $this->cs( $member, $password );
|
||||
}
|
||||
@@ -726,7 +799,7 @@ class _Convert extends LoginAbstract
|
||||
{
|
||||
return TRUE;
|
||||
}
|
||||
elseif ( $this->woltlab_legacy( $member, $password ) )
|
||||
elseif ( $this->woltlablegacy( $member, $password ) )
|
||||
{
|
||||
return TRUE;
|
||||
}
|
||||
@@ -741,7 +814,7 @@ class _Convert extends LoginAbstract
|
||||
* @param string $password Password from form
|
||||
* @return bool
|
||||
*/
|
||||
protected function woltlab_legacy( $member, $password )
|
||||
protected function woltlablegacy( $member, $password )
|
||||
{
|
||||
if ( \IPS\Login::compareHashes( $member->conv_password, sha1( $member->misc . sha1( $member->misc . sha1( $password ) ) ) ) )
|
||||
{
|
||||
@@ -764,7 +837,7 @@ class _Convert extends LoginAbstract
|
||||
{
|
||||
$success = FALSE;
|
||||
|
||||
if ( \IPS\Login::compareHashes( webWizAuth::HashEncode( $password . $member->misc ), $member->conv_password ) )
|
||||
if ( \IPS\Login::compareHashes( $member->conv_password, webWizAuth::HashEncode( $password . $member->misc ) ) )
|
||||
{
|
||||
$success = TRUE;
|
||||
}
|
||||
@@ -865,7 +938,7 @@ class _Convert extends LoginAbstract
|
||||
*/
|
||||
protected function phpfusion( $member, $password )
|
||||
{
|
||||
return ( bool ) \IPS\Login::compareHashes( md5( md5( $password ) ), $member->conv_password );
|
||||
return ( bool ) \IPS\Login::compareHashes( $member->conv_password, md5( md5( $password ) ) );
|
||||
}
|
||||
|
||||
/**
|
||||
@@ -893,7 +966,7 @@ class _Convert extends LoginAbstract
|
||||
}
|
||||
else
|
||||
{
|
||||
$success = ( \IPS\Login::compareHashes( md5( $password ), $hash ) ) ? TRUE : FALSE;
|
||||
$success = ( \IPS\Login::compareHashes( $hash, md5( $password ) ) ) ? TRUE : FALSE;
|
||||
}
|
||||
|
||||
return $success;
|
||||
@@ -908,23 +981,23 @@ class _Convert extends LoginAbstract
|
||||
*/
|
||||
protected function punbb( $member, $password )
|
||||
{
|
||||
$success = false;
|
||||
$hash = $member->conv_password;
|
||||
$success = FALSE;
|
||||
|
||||
if ( \strlen( $hash ) == 40 )
|
||||
if ( mb_strlen( $member->conv_password ) == 40 )
|
||||
{
|
||||
if ( \IPS\Login::compareHashes( $hash, sha1( $member->misc . sha1( $password ) ) ) )
|
||||
/* Password with salt */
|
||||
$success = \IPS\Login::compareHashes( $member->conv_password, sha1( $member->conv_password_extra . sha1( $password ) ) );
|
||||
|
||||
if ( !$success )
|
||||
{
|
||||
$success = TRUE;
|
||||
}
|
||||
elseif ( \IPS\Login::compareHashes( $hash, sha1( $password ) ) )
|
||||
{
|
||||
$success = TRUE;
|
||||
/* No salt */
|
||||
$success = \IPS\Login::compareHashes( $member->conv_password, sha1( $password ) );
|
||||
}
|
||||
}
|
||||
else
|
||||
{
|
||||
$success = ( md5( $password ) == $hash ) ? TRUE : FALSE;
|
||||
/* MD5 */
|
||||
$success = \IPS\Login::compareHashes( $member->conv_password, md5( $password ) );
|
||||
}
|
||||
|
||||
return $success;
|
||||
@@ -954,20 +1027,20 @@ class _Convert extends LoginAbstract
|
||||
$hash = $member->members_pass_hash;
|
||||
$salt = $member->members_pass_salt;
|
||||
|
||||
if ( \IPS\Login::compareHashes( md5( $password ), $hash ) )
|
||||
if ( \IPS\Login::compareHashes( $hash, md5( $password ) ) )
|
||||
{
|
||||
return TRUE;
|
||||
}
|
||||
|
||||
// Not using md5, UBB salts the password with the password
|
||||
// IPB already md5'd it though, *sigh*
|
||||
if ( \IPS\Login::compareHashes( md5( md5( $salt ) . crypt( $password, $password ) ), $hash ) )
|
||||
if ( \IPS\Login::compareHashes( $hash, md5( md5( $salt ) . crypt( $password, $password ) ) ) )
|
||||
{
|
||||
return TRUE;
|
||||
}
|
||||
|
||||
// Now standard IPB check.
|
||||
if ( \IPS\Login::compareHashes( md5( md5( $salt ) . md5( $password ) ), $hash ) )
|
||||
if ( \IPS\Login::compareHashes( $hash, md5( md5( $salt ) . md5( $password ) ) ) )
|
||||
{
|
||||
return TRUE;
|
||||
}
|
||||
@@ -986,8 +1059,6 @@ class _Convert extends LoginAbstract
|
||||
{
|
||||
$success = FALSE;
|
||||
|
||||
$password = ( trim( $_POST[ 'password' ] ) != '' ) ? trim( $_POST[ 'password' ] ) : $password;
|
||||
|
||||
// If the hash is still md5...
|
||||
if ( \strlen( $member->conv_password ) <= 32 )
|
||||
{
|
||||
@@ -997,7 +1068,8 @@ class _Convert extends LoginAbstract
|
||||
else
|
||||
{
|
||||
// Init the pass class
|
||||
$ph = new PasswordHash( 8, TRUE );
|
||||
$ph = new PasswordHash;
|
||||
$ph->PasswordHash( 8, TRUE );
|
||||
|
||||
// Check it
|
||||
$success = $ph->CheckPassword( $password, $member->conv_password ) ? TRUE : FALSE;
|
||||
@@ -1020,12 +1092,12 @@ class _Convert extends LoginAbstract
|
||||
$output = '*';
|
||||
|
||||
// Check for correct hash
|
||||
if ( substr( $setting, 0, 3 ) != '$H$' )
|
||||
if ( \substr( $setting, 0, 3 ) != '$H$' )
|
||||
{
|
||||
return $output;
|
||||
}
|
||||
|
||||
$count_log2 = strpos( $itoa64, $setting[3] );
|
||||
$count_log2 = \strpos( $itoa64, $setting[3] );
|
||||
|
||||
if ( $count_log2 < 7 || $count_log2 > 30 )
|
||||
{
|
||||
@@ -1033,7 +1105,7 @@ class _Convert extends LoginAbstract
|
||||
}
|
||||
|
||||
$count = 1 << $count_log2;
|
||||
$salt = substr( $setting, 4, 8 );
|
||||
$salt = \substr( $setting, 4, 8 );
|
||||
|
||||
if ( \strlen($salt) != 8 )
|
||||
{
|
||||
@@ -1069,7 +1141,7 @@ class _Convert extends LoginAbstract
|
||||
while ( --$count );
|
||||
}
|
||||
|
||||
$output = substr( $setting, 0, 12 );
|
||||
$output = \substr( $setting, 0, 12 );
|
||||
$output .= $this->_hashEncode64( $hash, 16, $itoa64 );
|
||||
|
||||
return $output;
|
||||
@@ -1189,7 +1261,7 @@ class PasswordHash
|
||||
$this->random_state = md5( microtime() . $this->random_state );
|
||||
$output .= pack( 'H*', md5( $this->random_state ) );
|
||||
}
|
||||
$output = substr( $output, 0, $count );
|
||||
$output = \substr( $output, 0, $count );
|
||||
}
|
||||
|
||||
return $output;
|
||||
@@ -1229,19 +1301,19 @@ class PasswordHash
|
||||
function crypt_private( $password, $setting )
|
||||
{
|
||||
$output = '*0';
|
||||
if ( substr( $setting, 0, 2 ) == $output )
|
||||
if ( \substr( $setting, 0, 2 ) == $output )
|
||||
$output = '*1';
|
||||
|
||||
if ( substr( $setting, 0, 3 ) != '$P$' )
|
||||
if ( \substr( $setting, 0, 3 ) != '$P$' )
|
||||
return $output;
|
||||
|
||||
$count_log2 = strpos( $this->itoa64, $setting[ 3 ] );
|
||||
$count_log2 = \strpos( $this->itoa64, $setting[ 3 ] );
|
||||
if ( $count_log2 < 7 || $count_log2 > 30 )
|
||||
return $output;
|
||||
|
||||
$count = 1 << $count_log2;
|
||||
|
||||
$salt = substr( $setting, 4, 8 );
|
||||
$salt = \substr( $setting, 4, 8 );
|
||||
if ( \strlen( $salt ) != 8 )
|
||||
return $output;
|
||||
|
||||
@@ -1270,7 +1342,7 @@ class PasswordHash
|
||||
while ( -- $count );
|
||||
}
|
||||
|
||||
$output = substr( $setting, 0, 12 );
|
||||
$output = \substr( $setting, 0, 12 );
|
||||
$output .= $this->encode64( $hash, 16 );
|
||||
|
||||
return $output;
|
||||
@@ -1395,7 +1467,7 @@ class webWizAuth
|
||||
|
||||
for( $intPos = 1 ; $intPos <= \strlen( $strSecret ) ; $intPos = $intPos + 56 )
|
||||
{
|
||||
$strEncode = substr( $strSecret, $intPos - 1, 56 ); //get 56 character chunks
|
||||
$strEncode = \substr( $strSecret, $intPos - 1, 56 ); //get 56 character chunks
|
||||
$strEncode = self::WordToBinary( $strEncode ); //convert to binary
|
||||
$strEncode = self::PadBinary( $strEncode ); //make it 512 bites
|
||||
$strEncode = self::BlockToHex( $strEncode ); //convert to hex value
|
||||
@@ -1406,11 +1478,11 @@ class webWizAuth
|
||||
$strEncode = self::DigestHex( $strEncode, $strH[ 0 ], $strH[ 1 ], $strH[ 2 ], $strH[ 3 ], $strH[ 4 ] );
|
||||
|
||||
//Combine the old digest with the new digest
|
||||
$strH[ 0 ] = self::HexAdd( substr( $strEncode, 0, 8 ), $strH[ 0 ] );
|
||||
$strH[ 1 ] = self::HexAdd( substr( $strEncode, 8, 8 ), $strH[ 1 ] );
|
||||
$strH[ 2 ] = self::HexAdd( substr( $strEncode, 16, 8 ), $strH[ 2 ] );
|
||||
$strH[ 3 ] = self::HexAdd( substr( $strEncode, 24, 8 ), $strH[ 3 ] );
|
||||
$strH[ 4 ] = self::HexAdd( substr( $strEncode, \strlen( $strEncode ) - ( 8 ) ), $strH[ 4 ] );
|
||||
$strH[ 0 ] = self::HexAdd( \substr( $strEncode, 0, 8 ), $strH[ 0 ] );
|
||||
$strH[ 1 ] = self::HexAdd( \substr( $strEncode, 8, 8 ), $strH[ 1 ] );
|
||||
$strH[ 2 ] = self::HexAdd( \substr( $strEncode, 16, 8 ), $strH[ 2 ] );
|
||||
$strH[ 3 ] = self::HexAdd( \substr( $strEncode, 24, 8 ), $strH[ 3 ] );
|
||||
$strH[ 4 ] = self::HexAdd( \substr( $strEncode, \strlen( $strEncode ) - ( 8 ) ), $strH[ 4 ] );
|
||||
}
|
||||
|
||||
//This is the final Hex Digest
|
||||
@@ -1541,7 +1613,7 @@ class webWizAuth
|
||||
$strBinary = '';
|
||||
for( $intPos = 1 ; $intPos <= \strlen( $strWord ) ; $intPos = $intPos + 1 )
|
||||
{
|
||||
$strTemp = substr( $strWord, intval( $intPos ) - 1, 1 );
|
||||
$strTemp = \substr( $strWord, intval( $intPos ) - 1, 1 );
|
||||
$strBinary = $strBinary . self::IntToBinary( ord( $strTemp ) );
|
||||
}
|
||||
|
||||
@@ -1599,7 +1671,7 @@ class webWizAuth
|
||||
$strHex = '';
|
||||
for( $intPos = 1 ; $intPos <= \strlen( $strBinary ) ; $intPos = $intPos + 4 )
|
||||
{
|
||||
$strHex = $strHex . self::BinaryToHex( substr( $strBinary, $intPos - 1, 4 ) );
|
||||
$strHex = $strHex . self::BinaryToHex( \substr( $strBinary, $intPos - 1, 4 ) );
|
||||
}
|
||||
return $strHex;
|
||||
}
|
||||
@@ -1621,7 +1693,7 @@ class webWizAuth
|
||||
//divide the Hex block into 16 hex words
|
||||
for( $intPos = 0 ; $intPos <= ( \strlen( $strHex ) / 8 ) - 1 ; $intPos = $intPos + 1 )
|
||||
{
|
||||
$strWords[ intval( $intPos ) ] = substr( $strHex, ( intval( $intPos ) * 8 ) + 1 - 1, 8 );
|
||||
$strWords[ intval( $intPos ) ] = \substr( $strHex, ( intval( $intPos ) * 8 ) + 1 - 1, 8 );
|
||||
}
|
||||
|
||||
//encode the Hex words using the constants above
|
||||
@@ -1782,7 +1854,7 @@ class webWizAuth
|
||||
}
|
||||
static protected function BinaryShift( $strBinary, $intPos )
|
||||
{
|
||||
return substr( $strBinary, \strlen( $strBinary ) - ( \strlen( $strBinary ) - intval( $intPos ) ) ) . substr( $strBinary, 0, intval( $intPos ) );
|
||||
return \substr( $strBinary, \strlen( $strBinary ) - ( \strlen( $strBinary ) - intval( $intPos ) ) ) . \substr( $strBinary, 0, intval( $intPos ) );
|
||||
}
|
||||
|
||||
// Function performs an exclusive or function on each position of two binary values
|
||||
@@ -1791,9 +1863,9 @@ class webWizAuth
|
||||
$strBinaryFinal = '';
|
||||
for( $intPos = 1 ; $intPos <= \strlen( $strBin1 ) ; $intPos = $intPos + 1 )
|
||||
{
|
||||
switch( substr( $strBin1, intval( $intPos ) - 1, 1 ) )
|
||||
switch( \substr( $strBin1, intval( $intPos ) - 1, 1 ) )
|
||||
{
|
||||
case substr( $strBin2, intval( $intPos ) - 1, 1 ) :
|
||||
case \substr( $strBin2, intval( $intPos ) - 1, 1 ) :
|
||||
$strBinaryFinal = $strBinaryFinal . "0";
|
||||
break;
|
||||
default :
|
||||
@@ -1811,7 +1883,7 @@ class webWizAuth
|
||||
$strBinaryFinal = '';
|
||||
for( $intPos = 1 ; $intPos <= \strlen( $strBin1 ) ; $intPos = $intPos + 1 )
|
||||
{
|
||||
if ( substr( $strBin1, intval( $intPos ) - 1, 1 ) == "1" || substr( $strBin2, intval( $intPos ) - 1, 1 ) == "1" )
|
||||
if ( \substr( $strBin1, intval( $intPos ) - 1, 1 ) == "1" || \substr( $strBin2, intval( $intPos ) - 1, 1 ) == "1" )
|
||||
{
|
||||
$strBinaryFinal = $strBinaryFinal . "1";
|
||||
}
|
||||
@@ -1830,7 +1902,7 @@ class webWizAuth
|
||||
$strBinaryFinal = '';
|
||||
for( $intPos = 1 ; $intPos <= \strlen( $strBin1 ) ; $intPos = $intPos + 1 )
|
||||
{
|
||||
if ( substr( $strBin1, intval( $intPos ) - 1, 1 ) == "1" && substr( $strBin2, intval( $intPos ) - 1, 1 ) == "1" )
|
||||
if ( \substr( $strBin1, intval( $intPos ) - 1, 1 ) == "1" && \substr( $strBin2, intval( $intPos ) - 1, 1 ) == "1" )
|
||||
{
|
||||
$strBinaryFinal = $strBinaryFinal . "1";
|
||||
}
|
||||
@@ -1849,7 +1921,7 @@ class webWizAuth
|
||||
$strBinaryFinal = '';
|
||||
for( $intPos = 1 ; $intPos <= \strlen( $strBinary ) ; $intPos = $intPos + 1 )
|
||||
{
|
||||
if ( substr( $strBinary, intval( $intPos ) - 1, 1 ) == "1" )
|
||||
if ( \substr( $strBinary, intval( $intPos ) - 1, 1 ) == "1" )
|
||||
{
|
||||
$strBinaryFinal = $strBinaryFinal . "0";
|
||||
}
|
||||
@@ -1868,7 +1940,7 @@ class webWizAuth
|
||||
$strTemp = '';
|
||||
for( $intPos = 1 ; $intPos <= \strlen( $strHex ) ; $intPos = $intPos + 1 )
|
||||
{
|
||||
$strTemp = $strTemp . self::HexToBinary( substr( $strHex, intval( $intPos ) - 1, 1 ) );
|
||||
$strTemp = $strTemp . self::HexToBinary( \substr( $strHex, intval( $intPos ) - 1, 1 ) );
|
||||
}
|
||||
|
||||
return $strTemp;
|
||||
|
||||
Reference in new issue
Block a user