From bbff5ae4d3961d5c2bff61e7d989c4a69c17ffc7 Mon Sep 17 00:00:00 2001 From: Naram Qashat Date: Sun, 8 Aug 2010 21:53:32 -0400 Subject: Add a db-upgrade to convert base64-encoded encrypted passwords to hexadecimal strings of the raw data, add in Anope::Hex for C-style strings and added Anope::Unhex, modified the encryption modules to use Hex and Unhex. --- modules/core/enc_md5.cpp | 6 ++---- modules/core/enc_old.cpp | 4 +--- modules/core/enc_sha1.cpp | 4 +--- modules/core/enc_sha256.cpp | 14 +++++--------- 4 files changed, 9 insertions(+), 19 deletions(-) (limited to 'modules/core') diff --git a/modules/core/enc_md5.cpp b/modules/core/enc_md5.cpp index 63ac5f101..3ec3f8ecd 100644 --- a/modules/core/enc_md5.cpp +++ b/modules/core/enc_md5.cpp @@ -330,14 +330,12 @@ class EMD5 : public Module MD5_CTX context; char digest[17] = ""; Anope::string buf = "md5:"; - Anope::string cpass; MD5Init(&context); MD5Update(&context, reinterpret_cast(src.c_str()), src.length()); - MD5Final(reinterpret_cast(digest), &context); + MD5Final(reinterpret_cast(digest), &context); - b64_encode(digest, cpass); - buf += cpass; + buf += Anope::Hex(digest, 16); Alog(LOG_DEBUG_2) << "(enc_md5) hashed password from [" << src << "] to [" << buf << "]"; dest = buf; return EVENT_ALLOW; diff --git a/modules/core/enc_old.cpp b/modules/core/enc_old.cpp index 2928b4d0d..dfaa838a9 100644 --- a/modules/core/enc_old.cpp +++ b/modules/core/enc_old.cpp @@ -334,7 +334,6 @@ class EOld : public Module { MD5_CTX context; char digest[33] = "", digest2[17] = ""; - Anope::string cpass; int i; Anope::string buf = "oldmd5:"; @@ -346,8 +345,7 @@ class EOld : public Module for (i = 0; i < 32; i += 2) digest2[i / 2] = XTOI(digest[i]) << 4 | XTOI(digest[i + 1]); - b64_encode(digest2, cpass); - buf += cpass; + buf += Anope::Hex(digest2, 16); Alog(LOG_DEBUG_2) << "(enc_old) hashed password from [" << src << "] to [" << buf << "]"; dest = buf; return EVENT_ALLOW; diff --git a/modules/core/enc_sha1.cpp b/modules/core/enc_sha1.cpp index 4047f539a..5c4f2b066 100644 --- a/modules/core/enc_sha1.cpp +++ b/modules/core/enc_sha1.cpp @@ -184,14 +184,12 @@ class ESHA1 : public Module SHA1_CTX context; char digest[21] = ""; Anope::string buf = "sha1:"; - Anope::string cpass; SHA1Init(&context); SHA1Update(&context, reinterpret_cast(src.c_str()), src.length()); SHA1Final(reinterpret_cast(digest), &context); - b64_encode(digest, cpass); - buf += cpass; + buf += Anope::Hex(digest, 20); Alog(LOG_DEBUG_2) << "(enc_sha1) hashed password from [" << src << "] to [" << buf << "]"; dest = buf; return EVENT_ALLOW; diff --git a/modules/core/enc_sha256.cpp b/modules/core/enc_sha256.cpp index 15dfce120..4fb076b8a 100644 --- a/modules/core/enc_sha256.cpp +++ b/modules/core/enc_sha256.cpp @@ -135,12 +135,10 @@ class ESHA256 : public Module Anope::string GetIVString() { char buf[33]; - Anope::string buf2; for (int i = 0; i < 8; ++i) UNPACK32(iv[i], reinterpret_cast(&buf[i << 2])); buf[32] = '\0'; - b64_encode(buf, buf2); - return buf2; + return Anope::Hex(buf, 32); } /* splits the appended IV from the password string so it can be used for the next encryption */ @@ -149,8 +147,8 @@ class ESHA256 : public Module { size_t pos = password.find(':'); Anope::string buf = password.substr(password.find(':', pos + 1) + 1, password.length()); - Anope::string buf2; - b64_decode(buf, buf2); + char buf2[33]; + Anope::Unhex(buf, buf2); for (int i = 0 ; i < 8; ++i) PACK32(reinterpret_cast(&buf2[i << 2]), iv[i]); } @@ -263,8 +261,7 @@ class ESHA256 : public Module EventReturn OnEncrypt(const Anope::string &src, Anope::string &dest) { - char digest[SHA256_DIGEST_SIZE+1]; - Anope::string cpass; + char digest[SHA256_DIGEST_SIZE + 1]; SHA256Context ctx; std::stringstream buf; @@ -277,8 +274,7 @@ class ESHA256 : public Module SHA256Update(&ctx, reinterpret_cast(src.c_str()), src.length()); SHA256Final(&ctx, reinterpret_cast(digest)); digest[SHA256_DIGEST_SIZE] = '\0'; - b64_encode(digest, cpass); - buf << "sha256:" << cpass << ":" << GetIVString(); + buf << "sha256:" << Anope::Hex(digest, SHA256_DIGEST_SIZE) << ":" << GetIVString(); Alog(LOG_DEBUG_2) << "(enc_sha256) hashed password from [" << src << "] to [" << buf.str() << " ]"; dest = buf.str(); return EVENT_ALLOW; -- cgit