function login($email, $password) { global $sid, $master_key, $rsa_priv_key; $password_aes = prepare_key(str_to_a32($password)); $uh = stringhash(strtolower($email), $password_aes); $res = api_req(array('a' => 'us', 'user' => $email, 'uh' => $uh)); $enc_master_key = base64_to_a32($res->k); $master_key = decrypt_key($enc_master_key, $password_aes); if (!empty($res->csid)) { $enc_rsa_priv_key = base64_to_a32($res->privk); $rsa_priv_key = decrypt_key($enc_rsa_priv_key, $master_key); $privk = a32_to_str($rsa_priv_key); $rsa_priv_key = array(0, 0, 0, 0); for ($i = 0; $i < 4; $i++) { $l = (ord($privk[0]) * 256 + ord($privk[1]) + 7) / 8 + 2; $rsa_priv_key[$i] = mpi2bc(substr($privk, 0, $l)); $privk = substr($privk, $l); } $enc_sid = mpi2bc(base64urldecode($res->csid)); $sid = rsa_decrypt($enc_sid, $rsa_priv_key[0], $rsa_priv_key[1], $rsa_priv_key[2]); $sid = base64urlencode(substr(strrev($sid), 0, 43)); } }
function Login($user, $pass) { global $T8; if (!extension_loaded('bcmath')) { html_error('This plugin needs BCMath extension for login.'); } $password_aes = prepare_key(str_to_a32($pass)); $T8['user_handle'] = stringhash($user, $password_aes); $res = apiReq(array('a' => 'us', 'user' => $user, 'uh' => $T8['user_handle'])); if (is_numeric($res[0])) { check_errors($res[0], 'Cannot login'); } $T8['master_key'] = decrypt_key(base64_to_a32($res[0]['k']), $password_aes); $privk = a32_to_str(decrypt_key(base64_to_a32($res[0]['privk']), $T8['master_key'])); $rsa_priv_key = array(0, 0, 0, 0); for ($i = 0; $i < 4; $i++) { $l = (ord($privk[0]) * 256 + ord($privk[1]) + 7) / 8 + 2; $rsa_priv_key[$i] = mpi2bc(substr($privk, 0, $l)); $privk = substr($privk, $l); } $T8['sid'] = rsa_decrypt(mpi2bc(base64url_decode($res[0]['csid'])), $rsa_priv_key[0], $rsa_priv_key[1], $rsa_priv_key[2]); $T8['sid'] = base64url_encode(substr(strrev($T8['sid']), 0, 43)); getRootNode(); t8ArrToCookieArr($rsa_priv_key); SaveCookies($user, $pass); // Update cookies file. $cookie = ''; }