From e5051e4aa5cfc9e80ac965a6a82e4cab8d17387c Mon Sep 17 00:00:00 2001 From: "Robin Burchell w00t@inspircd.org" Date: Thu, 2 Oct 2008 16:03:16 +0000 Subject: Merge commit 'cbx/anopeng-uid' into anopeng-uid Conflicts: include/extern.h include/services.h src/protocol/bahamut.c src/protocol/inspircd11.c git-svn-id: http://anope.svn.sourceforge.net/svnroot/anope/trunk@1320 5417fbe8-f217-4b02-8779-1006273d7864 --- src/core/ns_register.c | 21 +++++++-------------- src/core/ns_saset.c | 6 +----- src/core/ns_set.c | 4 ---- 3 files changed, 8 insertions(+), 23 deletions(-) (limited to 'src/core') diff --git a/src/core/ns_register.c b/src/core/ns_register.c index 7f79b2a3d..8908a1917 100644 --- a/src/core/ns_register.c +++ b/src/core/ns_register.c @@ -198,7 +198,11 @@ int do_register(User * u) } passcode[idx] = '\0'; nr = makerequest(u->nick); nr->passcode = sstrdup(passcode); - nr->password = sstrdup(pass); + strscpy(nr->password, pass, PASSMAX); + memset(pass, 0, strlen(pass)); + /* We are paranoid about keeping a plain text pass in memory, yet we would write + * it to a database.. - Viper */ + enc_encrypt_in_place(nr->password, PASSMAX); if (email) { nr->email = sstrdup(email); } @@ -238,7 +242,6 @@ int do_confirm(User * u) NickRequest *nr = NULL; NickAlias *na = NULL; char *passcode = strtok(NULL, " "); - char *pass = NULL; char *email = NULL; int forced = 0; User *utmp = NULL; @@ -255,7 +258,7 @@ int do_confirm(User * u) if (!nr) { if (is_services_admin(u)) { -/* If an admin, thier nick is obviously already regged, so look at the passcode to get the nick +/* If an admin, their nick is obviously already regged, so look at the passcode to get the nick of the user they are trying to validate, and push that user through regardless of passcode */ nr = findrequestnick(passcode); if (nr) { @@ -295,7 +298,6 @@ int do_confirm(User * u) notice_lang(s_NickServ, u, NICK_REGISTRATION_FAILED); return MOD_CONT; } - pass = sstrdup(nr->password); if (nr->email) { email = sstrdup(nr->email); @@ -307,16 +309,7 @@ int do_confirm(User * u) char tsbuf[16]; char tmp_pass[PASSMAX]; - len = strlen(pass); - na->nc->pass = (char *)smalloc(PASSMAX); - if (enc_encrypt(pass, len, na->nc->pass, PASSMAX - 1) < 0) { - memset(pass, 0, strlen(pass)); - alog("%s: Failed to encrypt password for %s (register)", - s_NickServ, nr->nick); - notice_lang(s_NickServ, u, NICK_REGISTRATION_FAILED); - return MOD_CONT; - } - memset(pass, 0, strlen(pass)); + memcpy(na->nc->pass, nr->password, PASSMAX); na->status = (int16) (NS_IDENTIFIED | NS_RECOGNIZED); /* na->nc->flags |= NI_ENCRYPTEDPW; */ diff --git a/src/core/ns_saset.c b/src/core/ns_saset.c index 7261a55ce..cfa6bd0a4 100644 --- a/src/core/ns_saset.c +++ b/src/core/ns_saset.c @@ -240,10 +240,6 @@ int do_saset_password(User * u, NickCore * nc, char *param) return MOD_CONT; } - if (nc->pass) - free(nc->pass); - - nc->pass = (char *)smalloc(PASSMAX); if (enc_encrypt(param, len, nc->pass, PASSMAX - 1) < 0) { memset(param, 0, len); alog("%s: Failed to encrypt password for %s (set)", s_NickServ, @@ -253,7 +249,7 @@ int do_saset_password(User * u, NickCore * nc, char *param) return MOD_CONT; } memset(param, 0, len); - + if(enc_decrypt(nc->pass,tmp_pass,PASSMAX - 1)==1) { notice_lang(s_NickServ, u, NICK_SASET_PASSWORD_CHANGED_TO, nc->display, tmp_pass); diff --git a/src/core/ns_set.c b/src/core/ns_set.c index a5a9b71b3..61b28c99d 100644 --- a/src/core/ns_set.c +++ b/src/core/ns_set.c @@ -213,10 +213,6 @@ int do_set_password(User * u, NickCore * nc, char *param) return MOD_CONT; } - if (nc->pass) - free(nc->pass); - - nc->pass = (char *)smalloc(PASSMAX); if (enc_encrypt(param, len, nc->pass, PASSMAX - 1) < 0) { memset(param, 0, len); alog("%s: Failed to encrypt password for %s (set)", s_NickServ, -- cgit