diff options
| author | rob rob@31f1291d-b8d6-0310-a050-a5561fc1590b <rob rob@31f1291d-b8d6-0310-a050-a5561fc1590b@5417fbe8-f217-4b02-8779-1006273d7864> | 2006-10-17 20:42:40 +0000 |
|---|---|---|
| committer | rob rob@31f1291d-b8d6-0310-a050-a5561fc1590b <rob rob@31f1291d-b8d6-0310-a050-a5561fc1590b@5417fbe8-f217-4b02-8779-1006273d7864> | 2006-10-17 20:42:40 +0000 |
| commit | 9bf8366451b60148699657ed966c0913fbae9465 (patch) | |
| tree | 3a48a1aaa582ec259657ff1029dd691b3a99fb92 /src/core | |
| parent | 3dbe219758f5c9712a5c1935d85be1434cf0eee8 (diff) | |
BUILD : 1.7.17 (1185) BUGS : N/A NOTES : Encryption now offers the choice of none, old and md5 - the md5 module is nicely taken from irc-services and actaully works, yes, real md5, in anope, wow eh?
git-svn-id: svn://svn.anope.org/anope/trunk@1185 31f1291d-b8d6-0310-a050-a5561fc1590b
git-svn-id: http://anope.svn.sourceforge.net/svnroot/anope/trunk@905 5417fbe8-f217-4b02-8779-1006273d7864
Diffstat (limited to 'src/core')
| -rw-r--r-- | src/core/cs_getpass.c | 28 | ||||
| -rw-r--r-- | src/core/cs_identify.c | 5 | ||||
| -rw-r--r-- | src/core/cs_register.c | 25 | ||||
| -rw-r--r-- | src/core/cs_sendpass.c | 68 | ||||
| -rw-r--r-- | src/core/cs_set.c | 14 | ||||
| -rw-r--r-- | src/core/enc_md5.c | 422 | ||||
| -rw-r--r-- | src/core/enc_none.c | 76 | ||||
| -rw-r--r-- | src/core/enc_old.c | 451 | ||||
| -rw-r--r-- | src/core/ns_getpass.c | 23 | ||||
| -rw-r--r-- | src/core/ns_ghost.c | 2 | ||||
| -rw-r--r-- | src/core/ns_group.c | 2 | ||||
| -rw-r--r-- | src/core/ns_identify.c | 2 | ||||
| -rw-r--r-- | src/core/ns_recover.c | 2 | ||||
| -rw-r--r-- | src/core/ns_register.c | 28 | ||||
| -rw-r--r-- | src/core/ns_release.c | 2 | ||||
| -rw-r--r-- | src/core/ns_saset.c | 21 | ||||
| -rw-r--r-- | src/core/ns_sendpass.c | 66 | ||||
| -rw-r--r-- | src/core/ns_set.c | 17 | ||||
| -rw-r--r-- | src/core/os_modlist.c | 22 |
19 files changed, 1111 insertions, 165 deletions
diff --git a/src/core/cs_getpass.c b/src/core/cs_getpass.c index ef9ea3cbb..fd1f241e1 100644 --- a/src/core/cs_getpass.c +++ b/src/core/cs_getpass.c @@ -38,11 +38,8 @@ int AnopeInit(int argc, char **argv) moduleAddCommand(CHANSERV, c, MOD_UNIQUE); moduleSetChanHelp(myChanServHelp); -#ifdef USE_ENCRYPTION - return MOD_STOP; -#else + return MOD_CONT; -#endif } /** @@ -75,6 +72,7 @@ void myChanServHelp(User * u) int do_getpass(User * u) { char *chan = strtok(NULL, " "); + char tmp_pass[PASSMAX]; ChannelInfo *ci; if (!chan) { @@ -86,15 +84,19 @@ int do_getpass(User * u) } else if (CSRestrictGetPass && !is_services_root(u)) { notice_lang(s_ChanServ, u, PERMISSION_DENIED); } else { - alog("%s: %s!%s@%s used GETPASS on %s", - s_ChanServ, u->nick, u->username, u->host, ci->name); - if (WallGetpass) { - anope_cmd_global(s_ChanServ, - "\2%s\2 used GETPASS on channel \2%s\2", - u->nick, chan); - } - notice_lang(s_ChanServ, u, CHAN_GETPASS_PASSWORD_IS, - chan, ci->founderpass); + if(enc_decrypt(ci->founderpass,tmp_pass,PASSMAX)==1) { + alog("%s: %s!%s@%s used GETPASS on %s", + s_ChanServ, u->nick, u->username, u->host, ci->name); + if (WallGetpass) { + anope_cmd_global(s_ChanServ, + "\2%s\2 used GETPASS on channel \2%s\2", + u->nick, chan); + } + notice_lang(s_ChanServ, u, CHAN_GETPASS_PASSWORD_IS, + chan, ci->founderpass); + } else { + notice_lang(s_ChanServ, u, CHAN_GETPASS_UNAVAILABLE); + } } return MOD_CONT; } diff --git a/src/core/cs_identify.c b/src/core/cs_identify.c index 33091c01a..6979c0f08 100644 --- a/src/core/cs_identify.c +++ b/src/core/cs_identify.c @@ -17,9 +17,6 @@ int do_identify(User * u); void myChanServHelp(User * u); -#ifdef _WIN32 -extern MDE int check_password(const char *plaintext, const char *password); -#endif /** * Create the command, and tell anope about it. @@ -92,7 +89,7 @@ int do_identify(User * u) } else { int res; - if ((res = check_password(pass, ci->founderpass)) == 1) { + if ((res = enc_check_password(pass, ci->founderpass)) == 1) { if (!is_identified(u, ci)) { uc = scalloc(sizeof(*uc), 1); uc->next = u->founder_chans; diff --git a/src/core/cs_register.c b/src/core/cs_register.c index d480f03c0..6d0167a1d 100644 --- a/src/core/cs_register.c +++ b/src/core/cs_register.c @@ -75,9 +75,8 @@ int do_register(User * u) ChannelInfo *ci; struct u_chaninfolist *uc; int is_servadmin = is_services_admin(u); -#ifdef USE_ENCRYPTION char founderpass[PASSMAX + 1]; -#endif + char tmp_pass[PASSMAX]; if (readonly) { notice_lang(s_ChanServ, u, CHAN_REGISTER_DISABLED); @@ -130,15 +129,12 @@ int do_register(User * u) alog("%s: makechan() failed for REGISTER %s", s_ChanServ, chan); notice_lang(s_ChanServ, u, CHAN_REGISTRATION_FAILED); -#ifdef USE_ENCRYPTION } else if (strscpy(founderpass, pass, PASSMAX + 1), - encrypt_in_place(founderpass, PASSMAX) < 0) { + enc_encrypt_in_place(founderpass, PASSMAX) < 0) { alog("%s: Couldn't encrypt password for %s (REGISTER)", s_ChanServ, chan); notice_lang(s_ChanServ, u, CHAN_REGISTRATION_FAILED); delchan(ci); -#endif - } else { c->ci = ci; ci->c = c; @@ -148,17 +144,12 @@ int do_register(User * u) ci->memos.memomax = MSMaxMemos; ci->last_used = ci->time_registered; ci->founder = nc; -#ifdef USE_ENCRYPTION if (strlen(pass) > PASSMAX) notice_lang(s_ChanServ, u, PASSWORD_TRUNCATED, PASSMAX); memset(pass, 0, strlen(pass)); memcpy(ci->founderpass, founderpass, PASSMAX); - ci->flags |= CI_ENCRYPTEDPW; -#else - if (strlen(pass) > PASSMAX - 1) /* -1 for null byte */ - notice_lang(s_ChanServ, u, PASSWORD_TRUNCATED, PASSMAX - 1); - strscpy(ci->founderpass, pass, PASSMAX); -#endif +// ci->flags |= CI_ENCRYPTEDPW; +// ci->desc = sstrdup(desc); if (c->topic) { ci->last_topic = sstrdup(c->topic); @@ -174,9 +165,11 @@ int do_register(User * u) alog("%s: Channel '%s' registered by %s!%s@%s", s_ChanServ, chan, u->nick, u->username, u->host); notice_lang(s_ChanServ, u, CHAN_REGISTERED, chan, u->nick); -#ifndef USE_ENCRYPTION - notice_lang(s_ChanServ, u, CHAN_PASSWORD_IS, ci->founderpass); -#endif + + if(enc_decrypt(ci->founderpass,tmp_pass,PASSMAX) == 1) { + notice_lang(s_ChanServ, u, CHAN_PASSWORD_IS, ci->founderpass); + } + uc = scalloc(sizeof(*uc), 1); uc->next = u->founder_chans; uc->prev = NULL; diff --git a/src/core/cs_sendpass.c b/src/core/cs_sendpass.c index 61eb70524..ee31287df 100644 --- a/src/core/cs_sendpass.c +++ b/src/core/cs_sendpass.c @@ -37,15 +37,12 @@ int AnopeInit(int argc, char **argv) moduleAddCommand(CHANSERV, c, MOD_UNIQUE); moduleSetChanHelp(myChanServHelp); -#ifdef USE_ENCRYPTION - return MOD_STOP; -#else + if (UseMail) { return MOD_CONT; } else { return MOD_STOP; } -#endif } /** @@ -89,35 +86,40 @@ int do_sendpass(User * u) notice_lang(s_ChanServ, u, CHAN_X_FORBIDDEN, chan); } else { char buf[BUFSIZE]; - MailInfo *mail; - - snprintf(buf, sizeof(buf), - getstring2(founder, CHAN_SENDPASS_SUBJECT), ci->name); - mail = MailBegin(u, founder, buf, s_ChanServ); - if (!mail) - return MOD_CONT; - - fprintf(mail->pipe, getstring2(founder, CHAN_SENDPASS_HEAD)); - fprintf(mail->pipe, "\n\n"); - fprintf(mail->pipe, getstring2(founder, CHAN_SENDPASS_LINE_1), - ci->name); - fprintf(mail->pipe, "\n\n"); - fprintf(mail->pipe, getstring2(founder, CHAN_SENDPASS_LINE_2), - ci->founderpass); - fprintf(mail->pipe, "\n\n"); - fprintf(mail->pipe, getstring2(founder, CHAN_SENDPASS_LINE_3)); - fprintf(mail->pipe, "\n\n"); - fprintf(mail->pipe, getstring2(founder, CHAN_SENDPASS_LINE_4)); - fprintf(mail->pipe, "\n\n"); - fprintf(mail->pipe, getstring2(founder, CHAN_SENDPASS_LINE_5), - NetworkName); - fprintf(mail->pipe, "\n.\n"); - - MailEnd(mail); - - alog("%s: %s!%s@%s used SENDPASS on %s", s_ChanServ, u->nick, - u->username, u->host, chan); - notice_lang(s_ChanServ, u, CHAN_SENDPASS_OK, chan); + char tmp_pass[PASSMAX]; + if(enc_decrypt(ci->founderpass,tmp_pass,PASSMAX)==1) { + MailInfo *mail; + + snprintf(buf, sizeof(buf), + getstring2(founder, CHAN_SENDPASS_SUBJECT), ci->name); + mail = MailBegin(u, founder, buf, s_ChanServ); + if (!mail) + return MOD_CONT; + + fprintf(mail->pipe, getstring2(founder, CHAN_SENDPASS_HEAD)); + fprintf(mail->pipe, "\n\n"); + fprintf(mail->pipe, getstring2(founder, CHAN_SENDPASS_LINE_1), + ci->name); + fprintf(mail->pipe, "\n\n"); + fprintf(mail->pipe, getstring2(founder, CHAN_SENDPASS_LINE_2), + tmp_pass); + fprintf(mail->pipe, "\n\n"); + fprintf(mail->pipe, getstring2(founder, CHAN_SENDPASS_LINE_3)); + fprintf(mail->pipe, "\n\n"); + fprintf(mail->pipe, getstring2(founder, CHAN_SENDPASS_LINE_4)); + fprintf(mail->pipe, "\n\n"); + fprintf(mail->pipe, getstring2(founder, CHAN_SENDPASS_LINE_5), + NetworkName); + fprintf(mail->pipe, "\n.\n"); + + MailEnd(mail); + + alog("%s: %s!%s@%s used SENDPASS on %s", s_ChanServ, u->nick, + u->username, u->host, chan); + notice_lang(s_ChanServ, u, CHAN_SENDPASS_OK, chan); + } else { + notice_lang(s_ChanServ, u, CHAN_SENDPASS_UNAVAILABLE); + } } return MOD_CONT; } diff --git a/src/core/cs_set.c b/src/core/cs_set.c index 15a0395be..c926ea583 100644 --- a/src/core/cs_set.c +++ b/src/core/cs_set.c @@ -14,9 +14,7 @@ /*************************************************************************/ #include "module.h" -#ifdef USE_ENCRYPTION #include "encrypt.h" -#endif int do_set(User * u); int do_set_founder(User * u, ChannelInfo * ci, char *param); @@ -368,14 +366,14 @@ int do_set_password(User * u, ChannelInfo * ci, char *param) notice_lang(s_ChanServ, u, MORE_OBSCURE_PASSWORD); return MOD_CONT; } -#ifdef USE_ENCRYPTION + if (len > PASSMAX) { len = PASSMAX; param[len] = 0; notice_lang(s_ChanServ, u, PASSWORD_TRUNCATED, PASSMAX); } - if (encrypt(param, len, ci->founderpass, PASSMAX) < 0) { + if (enc_encrypt(param, len, ci->founderpass, PASSMAX) < 0) { memset(param, 0, strlen(param)); alog("%s: Failed to encrypt password for %s (set)", s_ChanServ, ci->name); @@ -386,14 +384,6 @@ int do_set_password(User * u, ChannelInfo * ci, char *param) memset(param, 0, strlen(param)); notice_lang(s_ChanServ, u, CHAN_PASSWORD_CHANGED, ci->name); -#else /* !USE_ENCRYPTION */ - if (strlen(param) > PASSMAX - 1) /* -1 for null byte */ - notice_lang(s_ChanServ, u, PASSWORD_TRUNCATED, PASSMAX - 1); - strscpy(ci->founderpass, param, PASSMAX); - notice_lang(s_ChanServ, u, CHAN_PASSWORD_CHANGED_TO, ci->name, - ci->founderpass); -#endif /* USE_ENCRYPTION */ - if (get_access(u, ci) < ACCESS_FOUNDER) { alog("%s: %s!%s@%s set password as Services admin for %s", s_ChanServ, u->nick, u->username, u->host, ci->name); diff --git a/src/core/enc_md5.c b/src/core/enc_md5.c new file mode 100644 index 000000000..411e9f2a4 --- /dev/null +++ b/src/core/enc_md5.c @@ -0,0 +1,422 @@ +/* Module for encryption using MD5. + * + * Modified for Anope. + * (C) 2003-2006 Anope Team + * Contact us at dev@anope.org + * + * Taken from IRC Services and is copyright (c) 1996-2002 Andrew Church. + * E-mail: <achurch@achurch.org> + * Parts written by Andrew Kempe and others. + * This program is free but copyrighted software; see the file COPYING for + * details. + */ + +#include "module.h" + + +/*************************************************************************/ + +/* Copyright (C) 1991-2, RSA Data Security, Inc. Created 1991. All +rights reserved. + +License to copy and use this software is granted provided that it +is identified as the "RSA Data Security, Inc. MD5 Message-Digest +Algorithm" in all material mentioning or referencing this software +or this function. + +License is also granted to make and use derivative works provided +that such works are identified as "derived from the RSA Data +Security, Inc. MD5 Message-Digest Algorithm" in all material +mentioning or referencing the derived work. + +RSA Data Security, Inc. makes no representations concerning either +the merchantability of this software or the suitability of this +software for any particular purpose. It is provided "as is" +without express or implied warranty of any kind. + +These notices must be retained in any copies of any part of this +documentation and/or software. + */ + +#include <string.h> + +typedef unsigned int UINT4; + +/* MD5 context. */ +typedef struct { + UINT4 state[4]; /* state (ABCD) */ + UINT4 count[2]; /* number of bits, modulo 2^64 (lsb first) */ + unsigned char buffer[64]; /* input buffer */ +} MD5_CTX; + +/* MD5C.C - RSA Data Security, Inc., MD5 message-digest algorithm + */ + +typedef void *POINTER; + +/* Constants for MD5Transform routine. + */ +#define S11 7 +#define S12 12 +#define S13 17 +#define S14 22 +#define S21 5 +#define S22 9 +#define S23 14 +#define S24 20 +#define S31 4 +#define S32 11 +#define S33 16 +#define S34 23 +#define S41 6 +#define S42 10 +#define S43 15 +#define S44 21 + +void MD5Transform (UINT4 [4], unsigned char [64]); +void Encode (unsigned char *, UINT4 *, unsigned int); +void Decode (UINT4 *, unsigned char *, unsigned int); + +static unsigned char PADDING[64] = { + 0x80, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, + 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, + 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0 +}; + +/* F, G, H and I are basic MD5 functions. + */ +#define F(x, y, z) (((x) & (y)) | ((~x) & (z))) +#define G(x, y, z) (((x) & (z)) | ((y) & (~z))) +#define H(x, y, z) ((x) ^ (y) ^ (z)) +#define I(x, y, z) ((y) ^ ((x) | (~z))) + +/* ROTATE_LEFT rotates x left n bits. + */ +#define ROTATE_LEFT(x, n) (((x) << (n)) | ((x) >> (32-(n)))) + +/* FF, GG, HH, and II transformations for rounds 1, 2, 3, and 4. +Rotation is separate from addition to prevent recomputation. + */ +#define FF(a, b, c, d, x, s, ac) { \ + (a) += F ((b), (c), (d)) + (x) + (UINT4)(ac); \ + (a) = ROTATE_LEFT ((a), (s)); \ + (a) += (b); \ + } +#define GG(a, b, c, d, x, s, ac) { \ + (a) += G ((b), (c), (d)) + (x) + (UINT4)(ac); \ + (a) = ROTATE_LEFT ((a), (s)); \ + (a) += (b); \ + } +#define HH(a, b, c, d, x, s, ac) { \ + (a) += H ((b), (c), (d)) + (x) + (UINT4)(ac); \ + (a) = ROTATE_LEFT ((a), (s)); \ + (a) += (b); \ + } +#define II(a, b, c, d, x, s, ac) { \ + (a) += I ((b), (c), (d)) + (x) + (UINT4)(ac); \ + (a) = ROTATE_LEFT ((a), (s)); \ + (a) += (b); \ + } + +/* MD5 initialization. Begins an MD5 operation, writing a new context. + */ +void MD5Init (context) +MD5_CTX *context; /* context */ +{ + context->count[0] = context->count[1] = 0; + /* Load magic initialization constants. +*/ + context->state[0] = 0x67452301; + context->state[1] = 0xefcdab89; + context->state[2] = 0x98badcfe; + context->state[3] = 0x10325476; +} + +/* MD5 block update operation. Continues an MD5 message-digest + operation, processing another message block, and updating the + context. + */ +void MD5Update (context, input, inputLen) +MD5_CTX *context; /* context */ +unsigned char *input; /* input block */ +unsigned int inputLen; /* length of input block */ +{ + unsigned int i, index, partLen; + + /* Compute number of bytes mod 64 */ + index = (unsigned int)((context->count[0] >> 3) & 0x3F); + + /* Update number of bits */ + if ((context->count[0] += ((UINT4)inputLen << 3)) + < ((UINT4)inputLen << 3)) + context->count[1]++; + context->count[1] += ((UINT4)inputLen >> 29); + + partLen = 64 - index; + + /* Transform as many times as possible. +*/ + if (inputLen >= partLen) { + memcpy + ((POINTER)&context->buffer[index], (POINTER)input, partLen); + MD5Transform (context->state, context->buffer); + + for (i = partLen; i + 63 < inputLen; i += 64) + MD5Transform (context->state, &input[i]); + + index = 0; + } + else + i = 0; + + /* Buffer remaining input */ + memcpy + ((POINTER)&context->buffer[index], (POINTER)&input[i], + inputLen-i); +} + +/* MD5 finalization. Ends an MD5 message-digest operation, writing the + the message digest and zeroizing the context. + */ +void MD5Final (digest, context) +unsigned char digest[16]; /* message digest */ +MD5_CTX *context; /* context */ +{ + unsigned char bits[8]; + unsigned int index, padLen; + + /* Save number of bits */ + Encode (bits, context->count, 8); + + /* Pad out to 56 mod 64. +*/ + index = (unsigned int)((context->count[0] >> 3) & 0x3f); + padLen = (index < 56) ? (56 - index) : (120 - index); + MD5Update (context, PADDING, padLen); + + /* Append length (before padding) */ + MD5Update (context, bits, 8); + /* Store state in digest */ + Encode (digest, context->state, 16); + + /* Zeroize sensitive information. +*/ + memset ((POINTER)context, 0, sizeof (*context)); +} + +/* MD5 basic transformation. Transforms state based on block. + */ +void MD5Transform (state, block) +UINT4 state[4]; +unsigned char block[64]; +{ + UINT4 a = state[0], b = state[1], c = state[2], d = state[3], x[16]; + + Decode (x, block, 64); + + /* Round 1 */ + FF (a, b, c, d, x[ 0], S11, 0xd76aa478); /* 1 */ + FF (d, a, b, c, x[ 1], S12, 0xe8c7b756); /* 2 */ + FF (c, d, a, b, x[ 2], S13, 0x242070db); /* 3 */ + FF (b, c, d, a, x[ 3], S14, 0xc1bdceee); /* 4 */ + FF (a, b, c, d, x[ 4], S11, 0xf57c0faf); /* 5 */ + FF (d, a, b, c, x[ 5], S12, 0x4787c62a); /* 6 */ + FF (c, d, a, b, x[ 6], S13, 0xa8304613); /* 7 */ + FF (b, c, d, a, x[ 7], S14, 0xfd469501); /* 8 */ + FF (a, b, c, d, x[ 8], S11, 0x698098d8); /* 9 */ + FF (d, a, b, c, x[ 9], S12, 0x8b44f7af); /* 10 */ + FF (c, d, a, b, x[10], S13, 0xffff5bb1); /* 11 */ + FF (b, c, d, a, x[11], S14, 0x895cd7be); /* 12 */ + FF (a, b, c, d, x[12], S11, 0x6b901122); /* 13 */ + FF (d, a, b, c, x[13], S12, 0xfd987193); /* 14 */ + FF (c, d, a, b, x[14], S13, 0xa679438e); /* 15 */ + FF (b, c, d, a, x[15], S14, 0x49b40821); /* 16 */ + + /* Round 2 */ + GG (a, b, c, d, x[ 1], S21, 0xf61e2562); /* 17 */ + GG (d, a, b, c, x[ 6], S22, 0xc040b340); /* 18 */ + GG (c, d, a, b, x[11], S23, 0x265e5a51); /* 19 */ + GG (b, c, d, a, x[ 0], S24, 0xe9b6c7aa); /* 20 */ + GG (a, b, c, d, x[ 5], S21, 0xd62f105d); /* 21 */ + GG (d, a, b, c, x[10], S22, 0x2441453); /* 22 */ + GG (c, d, a, b, x[15], S23, 0xd8a1e681); /* 23 */ + GG (b, c, d, a, x[ 4], S24, 0xe7d3fbc8); /* 24 */ + GG (a, b, c, d, x[ 9], S21, 0x21e1cde6); /* 25 */ + GG (d, a, b, c, x[14], S22, 0xc33707d6); /* 26 */ + GG (c, d, a, b, x[ 3], S23, 0xf4d50d87); /* 27 */ + GG (b, c, d, a, x[ 8], S24, 0x455a14ed); /* 28 */ + GG (a, b, c, d, x[13], S21, 0xa9e3e905); /* 29 */ + GG (d, a, b, c, x[ 2], S22, 0xfcefa3f8); /* 30 */ + GG (c, d, a, b, x[ 7], S23, 0x676f02d9); /* 31 */ + GG (b, c, d, a, x[12], S24, 0x8d2a4c8a); /* 32 */ + + /* Round 3 */ + HH (a, b, c, d, x[ 5], S31, 0xfffa3942); /* 33 */ + HH (d, a, b, c, x[ 8], S32, 0x8771f681); /* 34 */ + HH (c, d, a, b, x[11], S33, 0x6d9d6122); /* 35 */ + HH (b, c, d, a, x[14], S34, 0xfde5380c); /* 36 */ + HH (a, b, c, d, x[ 1], S31, 0xa4beea44); /* 37 */ + HH (d, a, b, c, x[ 4], S32, 0x4bdecfa9); /* 38 */ + HH (c, d, a, b, x[ 7], S33, 0xf6bb4b60); /* 39 */ + HH (b, c, d, a, x[10], S34, 0xbebfbc70); /* 40 */ + HH (a, b, c, d, x[13], S31, 0x289b7ec6); /* 41 */ + HH (d, a, b, c, x[ 0], S32, 0xeaa127fa); /* 42 */ + HH (c, d, a, b, x[ 3], S33, 0xd4ef3085); /* 43 */ + HH (b, c, d, a, x[ 6], S34, 0x4881d05); /* 44 */ + HH (a, b, c, d, x[ 9], S31, 0xd9d4d039); /* 45 */ + HH (d, a, b, c, x[12], S32, 0xe6db99e5); /* 46 */ + HH (c, d, a, b, x[15], S33, 0x1fa27cf8); /* 47 */ + HH (b, c, d, a, x[ 2], S34, 0xc4ac5665); /* 48 */ + + /* Round 4 */ + II (a, b, c, d, x[ 0], S41, 0xf4292244); /* 49 */ + II (d, a, b, c, x[ 7], S42, 0x432aff97); /* 50 */ + II (c, d, a, b, x[14], S43, 0xab9423a7); /* 51 */ + II (b, c, d, a, x[ 5], S44, 0xfc93a039); /* 52 */ + II (a, b, c, d, x[12], S41, 0x655b59c3); /* 53 */ + II (d, a, b, c, x[ 3], S42, 0x8f0ccc92); /* 54 */ + II (c, d, a, b, x[10], S43, 0xffeff47d); /* 55 */ + II (b, c, d, a, x[ 1], S44, 0x85845dd1); /* 56 */ + II (a, b, c, d, x[ 8], S41, 0x6fa87e4f); /* 57 */ + II (d, a, b, c, x[15], S42, 0xfe2ce6e0); /* 58 */ + II (c, d, a, b, x[ 6], S43, 0xa3014314); /* 59 */ + II (b, c, d, a, x[13], S44, 0x4e0811a1); /* 60 */ + II (a, b, c, d, x[ 4], S41, 0xf7537e82); /* 61 */ + II (d, a, b, c, x[11], S42, 0xbd3af235); /* 62 */ + II (c, d, a, b, x[ 2], S43, 0x2ad7d2bb); /* 63 */ + II (b, c, d, a, x[ 9], S44, 0xeb86d391); /* 64 */ + + state[0] += a; + state[1] += b; + state[2] += c; + state[3] += d; + + /* Zeroize sensitive information. +*/ + memset ((POINTER)x, 0, sizeof (x)); +} + +/* Encodes input (UINT4) into output (unsigned char). Assumes len is + a multiple of 4. + */ +void Encode (output, input, len) +unsigned char *output; +UINT4 *input; +unsigned int len; +{ + unsigned int i, j; + + for (i = 0, j = 0; j < len; i++, j += 4) { + output[j] = (unsigned char)(input[i] & 0xff); + output[j+1] = (unsigned char)((input[i] >> 8) & 0xff); + output[j+2] = (unsigned char)((input[i] >> 16) & 0xff); + output[j+3] = (unsigned char)((input[i] >> 24) & 0xff); + } +} + +/* Decodes input (unsigned char) into output (UINT4). Assumes len is + a multiple of 4. + */ +void Decode (output, input, len) +UINT4 *output; +unsigned char *input; +unsigned int len; +{ + unsigned int i, j; + + for (i = 0, j = 0; j < len; i++, j += 4) + output[i] = ((UINT4)input[j]) | (((UINT4)input[j+1]) << 8) | + (((UINT4)input[j+2]) << 16) | (((UINT4)input[j+3]) << 24); +} + +/*************************************************************************/ + +/* Our own high-level routines. See encrypt.h for documentation. */ + +#define XTOI(c) ((c)>9 ? (c)-'A'+10 : (c)-'0') + +int md5_encrypt(const char *src, int len, char *dest, int size) +{ + MD5_CTX context; + char tmp[33]; + + if (size < 16) + return -1; + + MD5Init(&context); + MD5Update(&context, src, len); + MD5Final(dest, &context); + + if(debug) { + memset(tmp,0,33); + binary_to_hex(dest,tmp,16); + alog("enc_md5: Converted [%s] to [%s]",src,tmp); + } + + return 0; +} + + +int md5_encrypt_in_place(char *buf, int size) +{ + return md5_encrypt(buf, strlen(buf), buf, size); +} + + +int md5_encrypt_check_len(int passlen, int bufsize) +{ + if (bufsize < 16) + fatal("enc_md5: md5_check_len(): buffer too small (%d)", bufsize); + return 0; +} + + +int md5_decrypt(const char *src, char *dest, int size) +{ + return 0; +} + + +int md5_check_password(const char *plaintext, const char *password) +{ + char buf[BUFSIZE]; + + if (md5_encrypt(plaintext, strlen(plaintext), buf, sizeof(buf)) < 0) + return -1; + if (memcmp(buf, password, 16) == 0) + return 1; + return 0; +} + +/*************************************************************************/ + +/* Module stuff. */ + +int AnopeInit(int argc, char **argv) { + + moduleAddAuthor("Anope"); + moduleAddVersion("$Id$"); + moduleSetType(ENCRYPTION); + + encmodule_encrypt(md5_encrypt); + encmodule_encrypt_in_place(md5_encrypt_in_place); + encmodule_encrypt_check_len(md5_encrypt_check_len); + encmodule_decrypt(md5_decrypt); + encmodule_check_password(md5_check_password); + + return MOD_CONT; +} + +void AnopeFini(void) { + encmodule_encrypt(NULL); + encmodule_encrypt_in_place(NULL); + encmodule_encrypt_check_len(NULL); + encmodule_decrypt(NULL); + encmodule_check_password(NULL); +} + + + + +/*************************************************************************/ + diff --git a/src/core/enc_none.c b/src/core/enc_none.c new file mode 100644 index 000000000..6d7f699ab --- /dev/null +++ b/src/core/enc_none.c @@ -0,0 +1,76 @@ +/* Module for encryption using MD5. + * + * (C) 2003-2006 Anope Team + * Contact us at dev@anope.org + * + * This program is free but copyrighted software; see the file COPYING for + * details. + */ + +#include "module.h" + +int plain_encrypt(const char *src,int len,char *dest,int size); +int plain_encrypt_in_place(char *buf, int size); +int plain_encrypt_check_len(int passlen, int bufsize); +int plain_decrypt(const char *src, char *dest, int size); +int plain_check_password(const char *plaintext, const char *password); + + +int AnopeInit(int argc, char **argv) { + + moduleAddAuthor("Anope"); + moduleAddVersion("$Id$"); + moduleSetType(ENCRYPTION); + + encmodule_encrypt(plain_encrypt); + encmodule_encrypt_in_place(plain_encrypt_in_place); + encmodule_encrypt_check_len(plain_encrypt_check_len); + encmodule_decrypt(plain_decrypt); + encmodule_check_password(plain_check_password); + + return MOD_CONT; +} + +void AnopeFini(void) { + encmodule_encrypt(NULL); + encmodule_encrypt_in_place(NULL); + encmodule_encrypt_check_len(NULL); + encmodule_decrypt(NULL); + encmodule_check_password(NULL); +} + +int plain_encrypt(const char *src,int len,char *dest,int size) { + if(size>=len) { + memset(dest,0,size); + strncpy(dest,src,len); + return 0; + } + return -1; +} + +int plain_encrypt_in_place(char *buf, int size) { + return 0; +} + +int plain_encrypt_check_len(int passlen, int bufsize) { + if(bufsize>=passlen) { + return 0; + } + return bufsize; +} + +int plain_decrypt(const char *src, char *dest, int size) { + memset(dest,0,size); + strncpy(dest,src,size); + return 1; +} + +int plain_check_password(const char *plaintext, const char *password) { + if(strcmp(plaintext,password)==0) { + return 1; + } + return 0; +} + +/* EOF */ + diff --git a/src/core/enc_old.c b/src/core/enc_old.c new file mode 100644 index 000000000..befd1748a --- /dev/null +++ b/src/core/enc_old.c @@ -0,0 +1,451 @@ +/* Include file for high-level encryption routines. + * + * (C) 2003-2005 Anope Team + * Contact us at info@anope.org + * + * Please read COPYING and README for further details. + * + * Based on the original code of Epona by Lara. + * Based on the original code of Services by Andy Church. + * + * $Id: encrypt.c 953 2006-01-14 11:36:29Z certus $ + * + */ + +#include "module.h" + +void binary_to_hex(unsigned char *bin, char *hex, int length) +{ + static const char trans[] = "0123456789ABCDEF"; + int i; + + for(i = 0; i < length; i++) + { + hex[i << 1] = trans[bin[i] >> 4]; + hex[(i << 1) + 1] = trans[bin[i] & 0xf]; + } + + hex[i << 1] = '\0'; +} + + +/*************************************************************************/ + +/******** Code specific to the type of encryption. ********/ + + +/* Copyright (C) 1991-2, RSA Data Security, Inc. Created 1991. All +rights reserved. + +License to copy and use this software is granted provided that it +is identified as the "RSA Data Security, Inc. MD5 Message-Digest +Algorithm" in all material mentioning or referencing this software +or this function. + +License is also granted to make and use derivative works provided +that such works are identified as "derived from the RSA Data +Security, Inc. MD5 Message-Digest Algorithm" in all material +mentioning or referencing the derived work. + +RSA Data Security, Inc. makes no representations concerning either +the merchantability of this software or the suitability of this +software for any particular purpose. It is provided "as is" +without express or implied warranty of any kind. + +These notices must be retained in any copies of any part of this +documentation and/or software. + */ + +#include <string.h> + +typedef unsigned int UINT4; + +/* MD5 context. */ +typedef struct { + UINT4 state[4]; /* state (ABCD) */ + UINT4 count[2]; /* number of bits, modulo 2^64 (lsb first) */ + unsigned char buffer[64]; /* input buffer */ +} MD5_CTX; + +/* MD5C.C - RSA Data Security, Inc., MD5 message-digest algorithm + */ + +typedef void *POINTER; + +/* Constants for MD5Transform routine. + */ +#define S11 7 +#define S12 12 +#define S13 17 +#define S14 22 +#define S21 5 +#define S22 9 +#define S23 14 +#define S24 20 +#define S31 4 +#define S32 11 +#define S33 16 +#define S34 23 +#define S41 6 +#define S42 10 +#define S43 15 +#define S44 21 + +static void MD5Transform(UINT4[4], unsigned char[64]); +static void Encode(unsigned char *, UINT4 *, unsigned int); +static void Decode(UINT4 *, unsigned char *, unsigned int); + +static unsigned char PADDING[64] = { + 0x80, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, + 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, + 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0 +}; + +/* F, G, H and I are basic MD5 functions. + */ +#define F(x, y, z) (((x) & (y)) | ((~x) & (z))) +#define G(x, y, z) (((x) & (z)) | ((y) & (~z))) +#define H(x, y, z) ((x) ^ (y) ^ (z)) +#define MD5_I(x, y, z) ((y) ^ ((x) | (~z))) + +/* ROTATE_LEFT rotates x left n bits. + */ +#define ROTATE_LEFT(x, n) (((x) << (n)) | ((x) >> (32-(n)))) + +/* FF, GG, HH, and II transformations for rounds 1, 2, 3, and 4. +Rotation is separate from addition to prevent recomputation. + */ +#define FF(a, b, c, d, x, s, ac) { \ + (a) += F ((b), (c), (d)) + (x) + (UINT4)(ac); \ + (a) = ROTATE_LEFT ((a), (s)); \ + (a) += (b); \ + } +#define GG(a, b, c, d, x, s, ac) { \ + (a) += G ((b), (c), (d)) + (x) + (UINT4)(ac); \ + (a) = ROTATE_LEFT ((a), (s)); \ + (a) += (b); \ + } +#define HH(a, b, c, d, x, s, ac) { \ + (a) += H ((b), (c), (d)) + (x) + (UINT4)(ac); \ + (a) = ROTATE_LEFT ((a), (s)); \ + (a) += (b); \ + } +#define II(a, b, c, d, x, s, ac) { \ + (a) += MD5_I ((b), (c), (d)) + (x) + (UINT4)(ac); \ + (a) = ROTATE_LEFT ((a), (s)); \ + (a) += (b); \ + } + +/* MD5 initialization. Begins an MD5 operation, writing a new context. + */ +static void MD5Init(context) +MD5_CTX *context; /* context */ +{ + context->count[0] = context->count[1] = 0; + /* Load magic initialization constants. + */ + context->state[0] = 0x67452301; + context->state[1] = 0xefcdab89; + context->state[2] = 0x98badcfe; + context->state[3] = 0x10325476; +} + +/* MD5 block update operation. Continues an MD5 message-digest + operation, processing another message block, and updating the + context. + */ +static void MD5Update(context, input, inputLen) +MD5_CTX *context; /* context */ +unsigned char *input; /* input block */ +unsigned int inputLen; /* length of input block */ +{ + unsigned int i, index, partLen; + + /* Compute number of bytes mod 64 */ + index = (unsigned int) ((context->count[0] >> 3) & 0x3F); + + /* Update number of bits */ + if ((context->count[0] += ((UINT4) inputLen << 3)) + < ((UINT4) inputLen << 3)) + context->count[1]++; + context->count[1] += ((UINT4) inputLen >> 29); + + partLen = 64 - index; + + /* Transform as many times as possible. + */ + if (inputLen >= partLen) { + memcpy + ((POINTER) & context->buffer[index], (POINTER) input, partLen); + MD5Transform(context->state, context->buffer); + + for (i = partLen; i + 63 < inputLen; i += 64) + MD5Transform(context->state, &input[i]); + + index = 0; + } else + i = 0; + + /* Buffer remaining input */ + memcpy + ((POINTER) & context->buffer[index], (POINTER) & input[i], + inputLen - i); +} + +/* MD5 finalization. Ends an MD5 message-digest operation, writing the + the message digest and zeroizing the context. + */ +static void MD5Final(digest, context) +unsigned char digest[16]; /* message digest */ +MD5_CTX *context; /* context */ +{ + unsigned char bits[8]; + unsigned int index, padLen; + + /* Save number of bits */ + Encode(bits, context->count, 8); + + /* Pad out to 56 mod 64. + */ + index = (unsigned int) ((context->count[0] >> 3) & 0x3f); + padLen = (index < 56) ? (56 - index) : (120 - index); + MD5Update(context, PADDING, padLen); + + /* Append length (before padding) */ + MD5Update(context, bits, 8); + /* Store state in digest */ + Encode(digest, context->state, 16); + + /* Zeroize sensitive information. + */ + memset((POINTER) context, 0, sizeof(*context)); +} + +/* MD5 basic transformation. Transforms state based on block. + */ +static void MD5Transform(state, block) +UINT4 state[4]; +unsigned char block[64]; +{ + UINT4 a = state[0], b = state[1], c = state[2], d = state[3], x[16]; + + Decode(x, block, 64); + + /* Round 1 */ + FF(a, b, c, d, x[0], S11, 0xd76aa478); /* 1 */ + FF(d, a, b, c, x[1], S12, 0xe8c7b756); /* 2 */ + FF(c, d, a, b, x[2], S13, 0x242070db); /* 3 */ + FF(b, c, d, a, x[3], S14, 0xc1bdceee); /* 4 */ + FF(a, b, c, d, x[4], S11, 0xf57c0faf); /* 5 */ + FF(d, a, b, c, x[5], S12, 0x4787c62a); /* 6 */ + FF(c, d, a, b, x[6], S13, 0xa8304613); /* 7 */ + FF(b, c, d, a, x[7], S14, 0xfd469501); /* 8 */ + FF(a, b, c, d, x[8], S11, 0x698098d8); /* 9 */ + FF(d, a, b, c, x[9], S12, 0x8b44f7af); /* 10 */ + FF(c, d, a, b, x[10], S13, 0xffff5bb1); /* 11 */ + FF(b, c, d, a, x[11], S14, 0x895cd7be); /* 12 */ + FF(a, b, c, d, x[12], S11, 0x6b901122); /* 13 */ + FF(d, a, b, c, x[13], S12, 0xfd987193); /* 14 */ + FF(c, d, a, b, x[14], S13, 0xa679438e); /* 15 */ + FF(b, c, d, a, x[15], S14, 0x49b40821); /* 16 */ + + /* Round 2 */ + GG(a, b, c, d, x[1], S21, 0xf61e2562); /* 17 */ + GG(d, a, b, c, x[6], S22, 0xc040b340); /* 18 */ + GG(c, d, a, b, x[11], S23, 0x265e5a51); /* 19 */ + GG(b, c, d, a, x[0], S24, 0xe9b6c7aa); /* 20 */ + GG(a, b, c, d, x[5], S21, 0xd62f105d); /* 21 */ + GG(d, a, b, c, x[10], S22, 0x2441453); /* 22 */ + GG(c, d, a, b, x[15], S23, 0xd8a1e681); /* 23 */ + GG(b, c, d, a, x[4], S24, 0xe7d3fbc8); /* 24 */ + GG(a, b, c, d, x[9], S21, 0x21e1cde6); /* 25 */ + GG(d, a, b, c, x[14], S22, 0xc33707d6); /* 26 */ + GG(c, d, a, b, x[3], S23, 0xf4d50d87); /* 27 */ + GG(b, c, d, a, x[8], S24, 0x455a14ed); /* 28 */ + GG(a, b, c, d, x[13], S21, 0xa9e3e905); /* 29 */ + GG(d, a, b, c, x[2], S22, 0xfcefa3f8); /* 30 */ + GG(c, d, a, b, x[7], S23, 0x676f02d9); /* 31 */ + GG(b, c, d, a, x[12], S24, 0x8d2a4c8a); /* 32 */ + + /* Round 3 */ + HH(a, b, c, d, x[5], S31, 0xfffa3942); /* 33 */ + HH(d, a, b, c, x[8], S32, 0x8771f681); /* 34 */ + HH(c, d, a, b, x[11], S33, 0x6d9d6122); /* 35 */ + HH(b, c, d, a, x[14], S34, 0xfde5380c); /* 36 */ + HH(a, b, c, d, x[1], S31, 0xa4beea44); /* 37 */ + HH(d, a, b, c, x[4], S32, 0x4bdecfa9); /* 38 */ + HH(c, d, a, b, x[7], S33, 0xf6bb4b60); /* 39 */ + HH(b, c, d, a, x[10], S34, 0xbebfbc70); /* 40 */ + HH(a, b, c, d, x[13], S31, 0x289b7ec6); /* 41 */ + HH(d, a, b, c, x[0], S32, 0xeaa127fa); /* 42 */ + HH(c, d, a, b, x[3], S33, 0xd4ef3085); /* 43 */ + HH(b, c, d, a, x[6], S34, 0x4881d05); /* 44 */ + HH(a, b, c, d, x[9], S31, 0xd9d4d039); /* 45 */ + HH(d, a, b, c, x[12], S32, 0xe6db99e5); /* 46 */ + HH(c, d, a, b, x[15], S33, 0x1fa27cf8); /* 47 */ + HH(b, c, d, a, x[2], S34, 0xc4ac5665); /* 48 */ + + /* Round 4 */ + II(a, b, c, d, x[0], S41, 0xf4292244); /* 49 */ + II(d, a, b, c, x[7], S42, 0x432aff97); /* 50 */ + II(c, d, a, b, x[14], S43, 0xab9423a7); /* 51 */ + II(b, c, d, a, x[5], S44, 0xfc93a039); /* 52 */ + II(a, b, c, d, x[12], S41, 0x655b59c3); /* 53 */ + II(d, a, b, c, x[3], S42, 0x8f0ccc92); /* 54 */ + II(c, d, a, b, x[10], S43, 0xffeff47d); /* 55 */ + II(b, c, d, a, x[1], S44, 0x85845dd1); /* 56 */ + II(a, b, c, d, x[8], S41, 0x6fa87e4f); /* 57 */ + II(d, a, b, c, x[15], S42, 0xfe2ce6e0); /* 58 */ + II(c, d, a, b, x[6], S43, 0xa3014314); /* 59 */ + II(b, c, d, a, x[13], S44, 0x4e0811a1); /* 60 */ + II(a, b, c, d, x[4], S41, 0xf7537e82); /* 61 */ + II(d, a, b, c, x[11], S42, 0xbd3af235); /* 62 */ + II(c, d, a, b, x[2], S43, 0x2ad7d2bb); /* 63 */ + II(b, c, d, a, x[9], S44, 0xeb86d391); /* 64 */ + + state[0] += a; + state[1] += b; + state[2] += c; + state[3] += d; + + /* Zeroize sensitive information. + */ + memset((POINTER) x, 0, sizeof(x)); +} + +/* Encodes input (UINT4) into output (unsigned char). Assumes len is + a multiple of 4. + */ +static void Encode(output, input, len) +unsigned char *output; +UINT4 *input; +unsigned int len; +{ + unsigned int i, j; + + for (i = 0, j = 0; j < len; i++, j += 4) { + output[j] = (unsigned char) (input[i] & 0xff); + output[j + 1] = (unsigned char) ((input[i] >> 8) & 0xff); + output[j + 2] = (unsigned char) ((input[i] >> 16) & 0xff); + output[j + 3] = (unsigned char) ((input[i] >> 24) & 0xff); + } +} + +/* Decodes input (unsigned char) into output (UINT4). Assumes len is + a multiple of 4. + */ +static void Decode(output, input, len) +UINT4 *output; +unsigned char *input; +unsigned int len; +{ + unsigned int i, j; + + for (i = 0, j = 0; j < len; i++, j += 4) + output[i] = ((UINT4) input[j]) | (((UINT4) input[j + 1]) << 8) | + (((UINT4) input[j + 2]) << 16) | (((UINT4) input[j + 3]) << + 24); +} + +/*************************************************************************/ + +/******** Our own high-level routines. ********/ + + +#define XTOI(c) ((c)>9 ? (c)-'A'+10 : (c)-'0') + + +/* Encrypt `src' of length `len' and store the result in `dest'. If the + * resulting string would be longer than `size', return -1 and leave `dest' + * unchanged; else return 0. + */ +int old_encrypt(const char *src, int len, char *dest, int size) +{ + + MD5_CTX context; + char digest[33]; + char tmp[33]; + int i; + + if (size < 16) + return -1; + + memset(&context, 0, sizeof(context)); + memset(&digest, 0, sizeof(digest)); + + MD5Init(&context); + MD5Update(&context, src, len); + MD5Final(digest, &context); + for (i = 0; i < 32; i += 2) + dest[i / 2] = XTOI(digest[i]) << 4 | XTOI(digest[i + 1]); + + if(debug) { + memset(tmp,0,33); + binary_to_hex(dest,tmp,16); + alog("enc_old: Converted [%s] to [%s]",src,tmp); + } + + return 0; + +} + + +/* Shortcut for encrypting a null-terminated string in place. */ +int old_encrypt_in_place(char *buf, int size) +{ + return old_encrypt(buf, strlen(buf), buf, size); +} + +int old_encrypt_check_len(int passlen, int bufsize) +{ + if (bufsize < 16) + fatal("enc_old: old_check_len(): buffer too small (%d)", bufsize); + return 0; +} + + +/* Compare a plaintext string against an encrypted password. Return 1 if + * they match, 0 if not, and -1 if something went wrong. */ + +int old_check_password(const char *plaintext, const char *password) +{ + char buf[BUFSIZE]; + + if (old_encrypt(plaintext, strlen(plaintext), buf, sizeof(buf)) < 0) + return -1; + if (memcmp(buf, password, 16) == 0) + return 1; + else + return 0; +} + +int old_decrypt(const char *src, char *dest, int size) +{ + return 0; +} + +int AnopeInit(int argc, char **argv) { + + moduleAddAuthor("Anope"); + moduleAddVersion("$Id$"); + moduleSetType(ENCRYPTION); + + encmodule_encrypt(old_encrypt); + encmodule_encrypt_in_place(old_encrypt_in_place); + encmodule_encrypt_check_len(old_encrypt_check_len); + encmodule_decrypt(old_decrypt); + encmodule_check_password(old_check_password); + + return MOD_CONT; +} + +void AnopeFini(void) { + encmodule_encrypt(NULL); + encmodule_encrypt_in_place(NULL); + encmodule_encrypt_check_len(NULL); + encmodule_decrypt(NULL); + encmodule_check_password(NULL); +} + +/*************************************************************************/ + diff --git a/src/core/ns_getpass.c b/src/core/ns_getpass.c index afacd63a9..4a526a10a 100644 --- a/src/core/ns_getpass.c +++ b/src/core/ns_getpass.c @@ -39,11 +39,7 @@ int AnopeInit(int argc, char **argv) moduleSetNickHelp(myNickServHelp); -#ifdef USE_ENCRYPTION - return MOD_STOP; -#else return MOD_CONT; -#endif } /** @@ -73,6 +69,7 @@ void myNickServHelp(User * u) int do_getpass(User * u) { char *nick = strtok(NULL, " "); + char tmp_pass[PASSMAX]; NickAlias *na; NickRequest *nr = NULL; @@ -99,13 +96,17 @@ int do_getpass(User * u) } else if (NSRestrictGetPass && !is_services_root(u)) { notice_lang(s_NickServ, u, PERMISSION_DENIED); } else { - alog("%s: %s!%s@%s used GETPASS on %s", s_NickServ, u->nick, - u->username, u->host, nick); - if (WallGetpass) - anope_cmd_global(s_NickServ, "\2%s\2 used GETPASS on \2%s\2", - u->nick, nick); - notice_lang(s_NickServ, u, NICK_GETPASS_PASSWORD_IS, nick, - na->nc->pass); + if(enc_decrypt(na->nc->pass,tmp_pass,PASSMAX)==1) { + alog("%s: %s!%s@%s used GETPASS on %s", s_NickServ, u->nick, + u->username, u->host, nick); + if (WallGetpass) + anope_cmd_global(s_NickServ, "\2%s\2 used GETPASS on \2%s\2", + u->nick, nick); + notice_lang(s_NickServ, u, NICK_GETPASS_PASSWORD_IS, nick, + na->nc->pass); + } else { + notice_lang(s_NickServ, u, NICK_GETPASS_UNAVAILABLE); + } } return MOD_CONT; } diff --git a/src/core/ns_ghost.c b/src/core/ns_ghost.c index d97cc39ff..bc56afc2f 100644 --- a/src/core/ns_ghost.c +++ b/src/core/ns_ghost.c @@ -85,7 +85,7 @@ int do_ghost(User * u) } else if (stricmp(nick, u->nick) == 0) { notice_lang(s_NickServ, u, NICK_NO_GHOST_SELF); } else if (pass) { - int res = check_password(pass, na->nc->pass); + int res = enc_check_password(pass, na->nc->pass); if (res == 1) { char buf[NICKMAX + 32]; snprintf(buf, sizeof(buf), "GHOST command used by %s", diff --git a/src/core/ns_group.c b/src/core/ns_group.c index e29a225da..8cbbac3e8 100644 --- a/src/core/ns_group.c +++ b/src/core/ns_group.c @@ -165,7 +165,7 @@ int do_group(User * u) && !nick_is_services_admin(target->nc)) { notice_lang(s_NickServ, u, NICK_GROUP_TOO_MANY, target->nick, s_NickServ, s_NickServ); - } else if (check_password(pass, target->nc->pass) != 1) { + } else if (enc_check_password(pass, target->nc->pass) != 1) { alog("%s: Failed GROUP for %s!%s@%s (invalid password)", s_NickServ, u->nick, u->username, u->host); notice_lang(s_NickServ, u, PASSWORD_INCORRECT); diff --git a/src/core/ns_identify.c b/src/core/ns_identify.c index ae7b70aa9..ccd620775 100644 --- a/src/core/ns_identify.c +++ b/src/core/ns_identify.c @@ -96,7 +96,7 @@ int do_identify(User * u) notice_lang(s_NickServ, u, NICK_X_SUSPENDED, na->nick); } else if (nick_identified(u)) { notice_lang(s_NickServ, u, NICK_ALREADY_IDENTIFIED); - } else if (!(res = check_password(pass, na->nc->pass))) { + } else if (!(res = enc_check_password(pass, na->nc->pass))) { alog("%s: Failed IDENTIFY for %s!%s@%s", s_NickServ, u->nick, u->username, u->host); notice_lang(s_NickServ, u, PASSWORD_INCORRECT); diff --git a/src/core/ns_recover.c b/src/core/ns_recover.c index 2b72d94fb..485645e83 100644 --- a/src/core/ns_recover.c +++ b/src/core/ns_recover.c @@ -83,7 +83,7 @@ int do_recover(User * u) } else if (stricmp(nick, u->nick) == 0) { notice_lang(s_NickServ, u, NICK_NO_RECOVER_SELF); } else if (pass) { - int res = check_password(pass, na->nc->pass); + int res = enc_check_password(pass, na->nc->pass); if (res == 1) { notice_lang(s_NickServ, u2, FORCENICKCHANGE_NOW); diff --git a/src/core/ns_register.c b/src/core/ns_register.c index ec37a867f..69a95bb7a 100644 --- a/src/core/ns_register.c +++ b/src/core/ns_register.c @@ -14,9 +14,7 @@ /*************************************************************************/ #include "module.h" -#ifdef USE_ENCRYPTION #include "encrypt.h" -#endif int do_confirm(User * u); int do_register(User * u); @@ -190,17 +188,10 @@ int do_register(User * u) } else if (email && !MailValidate(email)) { notice_lang(s_NickServ, u, MAIL_X_INVALID, email); } else { -#ifdef USE_ENCRYPTION if (strlen(pass) > PASSMAX) { pass[PASSMAX] = 0; notice_lang(s_NickServ, u, PASSWORD_TRUNCATED, PASSMAX); } -#else - if (strlen(pass) > PASSMAX - 1) { /* -1 for null byte */ - pass[PASSMAX] = 0; - notice_lang(s_NickServ, u, PASSWORD_TRUNCATED, PASSMAX - 1); - } -#endif for (idx = 0; idx < 9; idx++) { passcode[idx] = chars[(1 + @@ -316,11 +307,11 @@ int do_confirm(User * u) if (na) { int i; char tsbuf[16]; + char tmp_pass[PASSMAX]; -#ifdef USE_ENCRYPTION len = strlen(pass); na->nc->pass = smalloc(PASSMAX); - if (encrypt(pass, len, na->nc->pass, PASSMAX) < 0) { + if (enc_encrypt(pass, len, na->nc->pass, PASSMAX) < 0) { memset(pass, 0, strlen(pass)); alog("%s: Failed to encrypt password for %s (register)", s_NickServ, nr->nick); @@ -329,11 +320,8 @@ int do_confirm(User * u) } memset(pass, 0, strlen(pass)); na->status = (int16) (NS_IDENTIFIED | NS_RECOGNIZED); - na->nc->flags |= NI_ENCRYPTEDPW; -#else - na->nc->pass = sstrdup(pass); - na->status = (int16) (NS_IDENTIFIED | NS_RECOGNIZED); -#endif +/* na->nc->flags |= NI_ENCRYPTEDPW; */ + na->nc->flags |= NSDefFlags; for (i = 0; i < RootNumber; i++) { if (!stricmp(ServicesRoots[i], nr->nick)) { @@ -378,9 +366,10 @@ int do_confirm(User * u) notice_lang(s_NickServ, u, NICK_REGISTERED_NO_MASK, u->nick); send_event(EVENT_NICK_REGISTERED, 1, u->nick); -#ifndef USE_ENCRYPTION - notice_lang(s_NickServ, u, NICK_PASSWORD_IS, na->nc->pass); -#endif + + if(enc_decrypt(na->nc->pass,tmp_pass,PASSMAX)==1) + notice_lang(s_NickServ, u, NICK_PASSWORD_IS, tmp_pass); + u->lastnickreg = time(NULL); if (ircd->modeonreg) { len = strlen(ircd->modeonreg); @@ -507,3 +496,4 @@ int do_sendregmail(User * u, NickRequest * nr) MailEnd(mail); return 0; } + diff --git a/src/core/ns_release.c b/src/core/ns_release.c index 4112c4606..02d75021a 100644 --- a/src/core/ns_release.c +++ b/src/core/ns_release.c @@ -82,7 +82,7 @@ int do_release(User * u) } else if (!(na->status & NS_KILL_HELD)) { notice_lang(s_NickServ, u, NICK_RELEASE_NOT_HELD, nick); } else if (pass) { - int res = check_password(pass, na->nc->pass); + int res = enc_check_password(pass, na->nc->pass); if (res == 1) { release(na, 0); notice_lang(s_NickServ, u, NICK_RELEASED); diff --git a/src/core/ns_saset.c b/src/core/ns_saset.c index 8b166a29b..c521c15b8 100644 --- a/src/core/ns_saset.c +++ b/src/core/ns_saset.c @@ -14,9 +14,7 @@ /*************************************************************************/ #include "module.h" -#ifdef USE_ENCRYPTION
-#include "encrypt.h"
-#endif +#include "encrypt.h" int do_saset(User * u); int do_saset_display(User * u, NickCore * nc, char *param); @@ -221,6 +219,7 @@ int do_saset_display(User * u, NickCore * nc, char *param) int do_saset_password(User * u, NickCore * nc, char *param) { int len = strlen(param); + char tmp_pass[PASSMAX]; if (NSSecureAdmins && u->na->nc != nc && nick_is_services_admin(nc) && !is_services_root(u)) { @@ -235,10 +234,9 @@ int do_saset_password(User * u, NickCore * nc, char *param) if (nc->pass) free(nc->pass); -#ifdef USE_ENCRYPTION nc->pass = smalloc(PASSMAX); - if (encrypt(param, len, nc->pass, PASSMAX) < 0) { + if (enc_encrypt(param, len, nc->pass, PASSMAX) < 0) { memset(param, 0, len); alog("%s: Failed to encrypt password for %s (set)", s_NickServ, nc->display); @@ -248,12 +246,13 @@ int do_saset_password(User * u, NickCore * nc, char *param) } memset(param, 0, len); - notice_lang(s_NickServ, u, NICK_SASET_PASSWORD_CHANGED, nc->display); -#else - nc->pass = sstrdup(param); - notice_lang(s_NickServ, u, NICK_SASET_PASSWORD_CHANGED_TO, nc->display, - nc->pass); -#endif + + if(enc_decrypt(nc->pass,tmp_pass,PASSMAX)==1) { + notice_lang(s_NickServ, u, NICK_SASET_PASSWORD_CHANGED_TO, nc->display, + nc->pass); + } else { + notice_lang(s_NickServ, u, NICK_SASET_PASSWORD_CHANGED, nc->display); + } alog("%s: %s!%s@%s used SASET PASSWORD on %s (e-mail: %s)", s_NickServ, u->nick, u->username, u->host, nc->display, diff --git a/src/core/ns_sendpass.c b/src/core/ns_sendpass.c index 14f766252..ce12c21f7 100644 --- a/src/core/ns_sendpass.c +++ b/src/core/ns_sendpass.c @@ -41,11 +41,8 @@ int AnopeInit(int argc, char **argv) if (!UseMail) { return MOD_STOP; } -#ifdef USE_ENCRYPTION - return MOD_STOP; -#else + return MOD_CONT; -#endif } /** @@ -86,34 +83,39 @@ int do_sendpass(User * u) notice_lang(s_NickServ, u, NICK_X_FORBIDDEN, na->nick); } else { char buf[BUFSIZE]; - MailInfo *mail; - - snprintf(buf, sizeof(buf), getstring(na, NICK_SENDPASS_SUBJECT), - na->nick); - mail = MailBegin(u, na->nc, buf, s_NickServ); - if (!mail) - return MOD_CONT; - - fprintf(mail->pipe, getstring(na, NICK_SENDPASS_HEAD)); - fprintf(mail->pipe, "\n\n"); - fprintf(mail->pipe, getstring(na, NICK_SENDPASS_LINE_1), na->nick); - fprintf(mail->pipe, "\n\n"); - fprintf(mail->pipe, getstring(na, NICK_SENDPASS_LINE_2), - na->nc->pass); - fprintf(mail->pipe, "\n\n"); - fprintf(mail->pipe, getstring(na, NICK_SENDPASS_LINE_3)); - fprintf(mail->pipe, "\n\n"); - fprintf(mail->pipe, getstring(na, NICK_SENDPASS_LINE_4)); - fprintf(mail->pipe, "\n\n"); - fprintf(mail->pipe, getstring(na, NICK_SENDPASS_LINE_5), - NetworkName); - fprintf(mail->pipe, "\n.\n"); - - MailEnd(mail); - - alog("%s: %s!%s@%s used SENDPASS on %s", s_NickServ, u->nick, - u->username, u->host, nick); - notice_lang(s_NickServ, u, NICK_SENDPASS_OK, nick); + char tmp_pass[PASSMAX]; + if(enc_decrypt(na->nc->pass,tmp_pass,PASSMAX)==1) { + MailInfo *mail; + + snprintf(buf, sizeof(buf), getstring(na, NICK_SENDPASS_SUBJECT), + na->nick); + mail = MailBegin(u, na->nc, buf, s_NickServ); + if (!mail) + return MOD_CONT; + + fprintf(mail->pipe, getstring(na, NICK_SENDPASS_HEAD)); + fprintf(mail->pipe, "\n\n"); + fprintf(mail->pipe, getstring(na, NICK_SENDPASS_LINE_1), na->nick); + fprintf(mail->pipe, "\n\n"); + fprintf(mail->pipe, getstring(na, NICK_SENDPASS_LINE_2), + tmp_pass); + fprintf(mail->pipe, "\n\n"); + fprintf(mail->pipe, getstring(na, NICK_SENDPASS_LINE_3)); + fprintf(mail->pipe, "\n\n"); + fprintf(mail->pipe, getstring(na, NICK_SENDPASS_LINE_4)); + fprintf(mail->pipe, "\n\n"); + fprintf(mail->pipe, getstring(na, NICK_SENDPASS_LINE_5), + NetworkName); + fprintf(mail->pipe, "\n.\n"); + + MailEnd(mail); + + alog("%s: %s!%s@%s used SENDPASS on %s", s_NickServ, u->nick, + u->username, u->host, nick); + notice_lang(s_NickServ, u, NICK_SENDPASS_OK, nick); + } else { + notice_lang(s_NickServ, u, NICK_SENDPASS_UNAVAILABLE); + } } return MOD_CONT; diff --git a/src/core/ns_set.c b/src/core/ns_set.c index 41a8424ca..ad493b104 100644 --- a/src/core/ns_set.c +++ b/src/core/ns_set.c @@ -14,9 +14,7 @@ /*************************************************************************/ #include "module.h" -#ifdef USE_ENCRYPTION #include "encrypt.h" -#endif int do_set(User * u); int do_set_display(User * u, NickCore * nc, char *param); @@ -205,6 +203,7 @@ int do_set_display(User * u, NickCore * nc, char *param) int do_set_password(User * u, NickCore * nc, char *param) { int len = strlen(param); + char tmp_pass[PASSMAX]; if (stricmp(nc->display, param) == 0 || (StrictPasswords && len < 5)) { notice_lang(s_NickServ, u, MORE_OBSCURE_PASSWORD); @@ -214,10 +213,9 @@ int do_set_password(User * u, NickCore * nc, char *param) if (nc->pass) free(nc->pass); -#ifdef USE_ENCRYPTION nc->pass = smalloc(PASSMAX); - if (encrypt(param, len, nc->pass, PASSMAX) < 0) { + if (enc_encrypt(param, len, nc->pass, PASSMAX) < 0) { memset(param, 0, len); alog("%s: Failed to encrypt password for %s (set)", s_NickServ, nc->display); @@ -226,11 +224,12 @@ int do_set_password(User * u, NickCore * nc, char *param) } memset(param, 0, len); - notice_lang(s_NickServ, u, NICK_SET_PASSWORD_CHANGED); -#else - nc->pass = sstrdup(param); - notice_lang(s_NickServ, u, NICK_SET_PASSWORD_CHANGED_TO, nc->pass); -#endif + + if(enc_decrypt(nc->pass,tmp_pass,PASSMAX)==1) { + notice_lang(s_NickServ, u, NICK_SET_PASSWORD_CHANGED_TO, nc->pass); + } else { + notice_lang(s_NickServ, u, NICK_SET_PASSWORD_CHANGED); + } alog("%s: %s!%s@%s (e-mail: %s) changed its password.", s_NickServ, u->nick, u->username, u->host, (nc->email ? nc->email : "none")); diff --git a/src/core/os_modlist.c b/src/core/os_modlist.c index 11aee77ed..bdd2ddbea 100644 --- a/src/core/os_modlist.c +++ b/src/core/os_modlist.c @@ -73,6 +73,7 @@ int do_modlist(User * u) int showCore = 0; int showThird = 1; int showProto = 1; + int showEnc = 1; int showSupported = 1; int showQA = 1; @@ -82,6 +83,7 @@ int do_modlist(User * u) char core[] = "Core"; char third[] = "3rd"; char proto[] = "Protocol"; + char enc[] = "Encryption"; char supported[] = "Supported"; char qa[] = "QATested"; @@ -91,6 +93,7 @@ int do_modlist(User * u) showCore = 1; showThird = 0; showProto = 0; + showEnc = 0; showSupported = 0; showQA = 0; } else if (stricmp(param, third) == 0) { @@ -99,10 +102,12 @@ int do_modlist(User * u) showSupported = 0; showQA = 0; showProto = 0; + showEnc = 0; } else if (stricmp(param, proto) == 0) { showCore = 0; showThird = 0; showProto = 1; + showEnc = 0; showSupported = 0; showQA = 0; } else if (stricmp(param, supported) == 0) { @@ -110,13 +115,22 @@ int do_modlist(User * u) showThird = 0; showProto = 0; showSupported = 1; + showEnc = 0; showQA = 0; } else if (stricmp(param, qa) == 0) { showCore = 0; showThird = 0; showProto = 0; showSupported = 0; + showEnc = 0; showQA = 1; + } else if (stricmp(param, enc) == 0) { + showCore = 0; + showThird = 0; + showProto = 0; + showSupported = 0; + showEnc = 1; + showQA = 0; } } @@ -161,6 +175,14 @@ int do_modlist(User * u) count++; } break; + case ENCRYPTION: + if (showEnc) { + notice_lang(s_OperServ, u, OPER_MODULE_LIST, + current->name, current->m->version, enc); + count++; + } + break; + } } |
