From 35486d5521f6445ff998c3e91ca0c559587b8052 Mon Sep 17 00:00:00 2001 From: Peter Powell Date: Mon, 7 Mar 2016 23:42:40 +0000 Subject: Prevent using enc_none as the main encryption module. Plain text passwords are a terrible idea at best and are illegal at worst. Lets not support them. --- modules/encryption/none.cpp | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) (limited to 'modules') diff --git a/modules/encryption/none.cpp b/modules/encryption/none.cpp index 317abb132..840ab7b42 100644 --- a/modules/encryption/none.cpp +++ b/modules/encryption/none.cpp @@ -30,7 +30,8 @@ class ENone : public Module , EventHook(this) , EventHook(this) { - + if (ModuleManager::FindFirstOf(ENCRYPTION) == this) + throw ModuleException("enc_none is deprecated and can not be used as a primary encryption method"); } EventReturn OnEncrypt(const Anope::string &src, Anope::string &dest) override -- cgit From 164ad71fc36f79efc823b7523de79603f6e0ac27 Mon Sep 17 00:00:00 2001 From: Peter Powell Date: Mon, 23 May 2016 12:00:41 +0100 Subject: Remove nickserv/getpass as that module is now obsolete. --- modules/nickserv/getpass.cpp | 82 -------------------------------------------- 1 file changed, 82 deletions(-) delete mode 100644 modules/nickserv/getpass.cpp (limited to 'modules') diff --git a/modules/nickserv/getpass.cpp b/modules/nickserv/getpass.cpp deleted file mode 100644 index b8f746ccc..000000000 --- a/modules/nickserv/getpass.cpp +++ /dev/null @@ -1,82 +0,0 @@ -/* - * Anope IRC Services - * - * Copyright (C) 2003-2016 Anope Team - * - * This file is part of Anope. Anope is free software; you can - * redistribute it and/or modify it under the terms of the GNU - * General Public License as published by the Free Software - * Foundation, version 2. - * - * This program is distributed in the hope that it will be useful, - * but WITHOUT ANY WARRANTY; without even the implied warranty of - * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the - * GNU General Public License for more details. - * - * You should have received a copy of the GNU General Public License - * along with this program; if not, see see . - */ - -#include "module.h" - -class CommandNSGetPass : public Command -{ - public: - CommandNSGetPass(Module *creator) : Command(creator, "nickserv/getpass", 1, 1) - { - this->SetDesc(_("Retrieve the password for a nickname")); - this->SetSyntax(_("\037account\037")); - } - - void Execute(CommandSource &source, const std::vector ¶ms) override - { - const Anope::string &nick = params[0]; - Anope::string tmp_pass; - NickServ::Nick *na = NickServ::FindNick(nick); - - if (!na) - { - source.Reply(_("\002{0}\002 isn't registered."), nick); - return; - } - - if (Config->GetModule("nickserv")->Get("secureadmins", "yes") && na->GetAccount()->IsServicesOper()) - { - source.Reply(_("You may not get the password of other Services Operators.")); - return; - } - - if (!Anope::Decrypt(na->GetAccount()->GetPassword(), tmp_pass)) - { - source.Reply(_("The \002{0}\002 command is unavailable because encryption is in use."), source.command); - return; - } - - Log(LOG_ADMIN, source, this) << "for " << na->GetNick(); - source.Reply(_("Password of \002{0}\02 is \002%s\002."), na->GetNick(), tmp_pass); - } - - bool OnHelp(CommandSource &source, const Anope::string &subcommand) override - { - source.Reply(_("Returns the password for the given account. This command may not be available if password encryption is in use.")); - return true; - } -}; - -class NSGetPass : public Module -{ - CommandNSGetPass commandnsgetpass; - - public: - NSGetPass(const Anope::string &modname, const Anope::string &creator) : Module(modname, creator, VENDOR) - , commandnsgetpass(this) - { - - Anope::string tmp_pass = "plain:tmp"; - if (!Anope::Decrypt(tmp_pass, tmp_pass)) - throw ModuleException("Incompatible with the encryption module being used"); - - } -}; - -MODULE_INIT(NSGetPass) -- cgit From 3b0f52c92b744836520af4b9915478569f297d39 Mon Sep 17 00:00:00 2001 From: Peter Powell Date: Mon, 23 May 2016 19:09:47 +0100 Subject: Remove Anope::Decrypt now encryption is mandated. --- modules/encryption/none.cpp | 12 ------------ modules/nickserv/register.cpp | 4 ---- modules/nickserv/set.cpp | 10 ++-------- 3 files changed, 2 insertions(+), 24 deletions(-) (limited to 'modules') diff --git a/modules/encryption/none.cpp b/modules/encryption/none.cpp index 840ab7b42..3b1f49d33 100644 --- a/modules/encryption/none.cpp +++ b/modules/encryption/none.cpp @@ -21,13 +21,11 @@ class ENone : public Module , public EventHook - , public EventHook , public EventHook { public: ENone(const Anope::string &modname, const Anope::string &creator) : Module(modname, creator, ENCRYPTION | VENDOR) , EventHook(this) - , EventHook(this) , EventHook(this) { if (ModuleManager::FindFirstOf(ENCRYPTION) == this) @@ -45,16 +43,6 @@ class ENone : public Module return EVENT_ALLOW; } - EventReturn OnDecrypt(const Anope::string &hashm, const Anope::string &src, Anope::string &dest) override - { - if (!hashm.equals_cs("plain")) - return EVENT_CONTINUE; - size_t pos = src.find(':'); - Anope::string buf = src.substr(pos + 1); - Anope::B64Decode(buf, dest); - return EVENT_ALLOW; - } - void OnCheckAuthentication(User *, NickServ::IdentifyRequest *req) override { NickServ::Nick *na = NickServ::FindNick(req->GetAccount()); diff --git a/modules/nickserv/register.cpp b/modules/nickserv/register.cpp index 41c0e716b..f7e93c9a1 100644 --- a/modules/nickserv/register.cpp +++ b/modules/nickserv/register.cpp @@ -244,10 +244,6 @@ class CommandNSRegister : public Command source.Reply(_("\002{0}\002 has been registered."), u_nick); - Anope::string tmp_pass; - if (Anope::Decrypt(na->GetAccount()->GetPassword(), tmp_pass)) - source.Reply(_("Your password is \002{0}\002 - remember this for later use."), tmp_pass); - if (nsregister.equals_ci("admin")) { nc->SetS("UNCONFIRMED", true); diff --git a/modules/nickserv/set.cpp b/modules/nickserv/set.cpp index c733f93d2..12086e801 100644 --- a/modules/nickserv/set.cpp +++ b/modules/nickserv/set.cpp @@ -160,10 +160,7 @@ class CommandNSSetPassword : public Command Anope::Encrypt(param, tmp_pass); source.nc->SetPassword(tmp_pass); - if (Anope::Decrypt(source.nc->GetPassword(), tmp_pass)) - source.Reply(_("Password for \002{0}\002 changed to \002{1]\002."), source.nc->GetDisplay(), tmp_pass); - else - source.Reply(_("Password for \002{0}\002 changed."), source.nc->GetDisplay()); + source.Reply(_("Password for \002{0}\002 changed."), source.nc->GetDisplay()); } bool OnHelp(CommandSource &source, const Anope::string &) override @@ -223,10 +220,7 @@ class CommandNSSASetPassword : public Command Anope::string tmp_pass; Anope::Encrypt(params[1], tmp_pass); nc->SetPassword(tmp_pass); - if (Anope::Decrypt(nc->GetPassword(), tmp_pass) == 1) - source.Reply(_("Password for \002{0}\002 changed to \002{1}\002."), nc->GetDisplay(), tmp_pass); - else - source.Reply(_("Password for \002{0}\002 changed."), nc->GetDisplay()); + source.Reply(_("Password for \002{0}\002 changed."), nc->GetDisplay()); } bool OnHelp(CommandSource &source, const Anope::string &) override -- cgit