예제 #1
0
function login($email, $password)
{
    global $sid, $master_key, $rsa_priv_key;
    $password_aes = prepare_key(str_to_a32($password));
    $uh = stringhash(strtolower($email), $password_aes);
    $res = api_req(array('a' => 'us', 'user' => $email, 'uh' => $uh));
    $enc_master_key = base64_to_a32($res->k);
    $master_key = decrypt_key($enc_master_key, $password_aes);
    if (!empty($res->csid)) {
        $enc_rsa_priv_key = base64_to_a32($res->privk);
        $rsa_priv_key = decrypt_key($enc_rsa_priv_key, $master_key);
        $privk = a32_to_str($rsa_priv_key);
        $rsa_priv_key = array(0, 0, 0, 0);
        for ($i = 0; $i < 4; $i++) {
            $l = (ord($privk[0]) * 256 + ord($privk[1]) + 7) / 8 + 2;
            $rsa_priv_key[$i] = mpi2bc(substr($privk, 0, $l));
            $privk = substr($privk, $l);
        }
        $enc_sid = mpi2bc(base64urldecode($res->csid));
        $sid = rsa_decrypt($enc_sid, $rsa_priv_key[0], $rsa_priv_key[1], $rsa_priv_key[2]);
        $sid = base64urlencode(substr(strrev($sid), 0, 43));
    }
}
예제 #2
0
function Login($user, $pass)
{
    global $T8;
    if (!extension_loaded('bcmath')) {
        html_error('This plugin needs BCMath extension for login.');
    }
    $password_aes = prepare_key(str_to_a32($pass));
    $T8['user_handle'] = stringhash($user, $password_aes);
    $res = apiReq(array('a' => 'us', 'user' => $user, 'uh' => $T8['user_handle']));
    if (is_numeric($res[0])) {
        check_errors($res[0], 'Cannot login');
    }
    $T8['master_key'] = decrypt_key(base64_to_a32($res[0]['k']), $password_aes);
    $privk = a32_to_str(decrypt_key(base64_to_a32($res[0]['privk']), $T8['master_key']));
    $rsa_priv_key = array(0, 0, 0, 0);
    for ($i = 0; $i < 4; $i++) {
        $l = (ord($privk[0]) * 256 + ord($privk[1]) + 7) / 8 + 2;
        $rsa_priv_key[$i] = mpi2bc(substr($privk, 0, $l));
        $privk = substr($privk, $l);
    }
    $T8['sid'] = rsa_decrypt(mpi2bc(base64url_decode($res[0]['csid'])), $rsa_priv_key[0], $rsa_priv_key[1], $rsa_priv_key[2]);
    $T8['sid'] = base64url_encode(substr(strrev($T8['sid']), 0, 43));
    getRootNode();
    t8ArrToCookieArr($rsa_priv_key);
    SaveCookies($user, $pass);
    // Update cookies file.
    $cookie = '';
}