ViewVC Help
View File | Revision Log | Show Annotations | View Changeset | Root Listing
root/svn/ircd-hybrid/trunk/modules/m_challenge.c
Revision: 1834
Committed: Fri Apr 19 19:50:27 2013 UTC (12 years, 4 months ago) by michael
Content type: text/x-csrc
File size: 5656 byte(s)
Log Message:
- Revert to -r1831

File Contents

# User Rev Content
1 adx 30 /*
2     * ircd-hybrid: an advanced Internet Relay Chat Daemon(ircd).
3     * m_challenge.c: Allows an IRC Operator to securely authenticate.
4     *
5     * Copyright (C) 2002 by the past and present ircd coders, and others.
6     *
7     * This program is free software; you can redistribute it and/or modify
8     * it under the terms of the GNU General Public License as published by
9     * the Free Software Foundation; either version 2 of the License, or
10     * (at your option) any later version.
11     *
12     * This program is distributed in the hope that it will be useful,
13     * but WITHOUT ANY WARRANTY; without even the implied warranty of
14     * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
15     * GNU General Public License for more details.
16     *
17     * You should have received a copy of the GNU General Public License
18     * along with this program; if not, write to the Free Software
19     * Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307
20     * USA
21     *
22 knight 31 * $Id$
23 adx 30 */
24    
25     #include "stdinc.h"
26     #include "client.h"
27     #include "ircd.h"
28     #include "modules.h"
29     #include "numeric.h"
30     #include "send.h"
31 michael 1309 #include "conf.h"
32 adx 30 #include "rsa.h"
33     #include "parse.h"
34     #include "irc_string.h"
35 michael 1309 #include "log.h"
36 adx 30 #include "s_user.h"
37 michael 1666 #include "memory.h"
38 adx 30
39    
40 michael 1415 #ifdef HAVE_LIBCRYPTO
41 michael 1230 /* failed_challenge_notice()
42     *
43     * inputs - pointer to client doing /oper ...
44     * - pointer to nick they tried to oper as
45     * - pointer to reason they have failed
46     * output - nothing
47     * side effects - notices all opers of the failed oper attempt if enabled
48     */
49     static void
50     failed_challenge_notice(struct Client *source_p, const char *name,
51     const char *reason)
52 adx 30 {
53 michael 1230 if (ConfigFileEntry.failed_oper_notice)
54 michael 1618 sendto_realops_flags(UMODE_ALL, L_ALL, SEND_NOTICE,
55     "Failed CHALLENGE attempt as %s "
56 michael 1230 "by %s (%s@%s) - %s", name, source_p->name,
57     source_p->username, source_p->host, reason);
58 michael 1247
59     ilog(LOG_TYPE_OPER, "Failed CHALLENGE attempt as %s "
60     "by %s (%s@%s) - %s", name, source_p->name,
61     source_p->username, source_p->host, reason);
62 adx 30 }
63    
64     /*
65     * m_challenge - generate RSA challenge for wouldbe oper
66     * parv[0] = sender prefix
67     * parv[1] = operator to challenge for, or +response
68     *
69     */
70     static void
71     m_challenge(struct Client *client_p, struct Client *source_p,
72     int parc, char *parv[])
73     {
74 michael 817 char *challenge = NULL;
75 michael 1632 struct MaskItem *conf = NULL;
76 adx 30
77     if (*parv[1] == '+')
78     {
79     /* Ignore it if we aren't expecting this... -A1kmm */
80 michael 817 if (source_p->localClient->response == NULL)
81 adx 30 return;
82    
83     if (irccmp(source_p->localClient->response, ++parv[1]))
84     {
85 michael 1834 sendto_one(source_p, form_str(ERR_PASSWDMISMATCH), me.name,
86 michael 1121 source_p->name);
87 adx 30 failed_challenge_notice(source_p, source_p->localClient->auth_oper,
88 michael 1121 "challenge failed");
89 adx 30 return;
90     }
91 michael 817
92 michael 1632 conf = find_exact_name_conf(CONF_OPER, source_p,
93 michael 1285 source_p->localClient->auth_oper, NULL, NULL);
94 michael 817 if (conf == NULL)
95 adx 30 {
96 michael 1247 /* XXX: logging */
97 michael 1834 sendto_one (source_p, form_str(ERR_NOOPERHOST), me.name, source_p->name);
98 adx 30 return;
99     }
100    
101     if (attach_conf(source_p, conf) != 0)
102     {
103     sendto_one(source_p,":%s NOTICE %s :Can't attach conf!",
104     me.name, source_p->name);
105     failed_challenge_notice(source_p, conf->name, "can't attach conf!");
106     return;
107     }
108    
109     oper_up(source_p);
110    
111 michael 1247 ilog(LOG_TYPE_OPER, "OPER %s by %s!%s@%s",
112 adx 30 source_p->localClient->auth_oper, source_p->name, source_p->username,
113     source_p->host);
114    
115     MyFree(source_p->localClient->response);
116     MyFree(source_p->localClient->auth_oper);
117     source_p->localClient->response = NULL;
118     source_p->localClient->auth_oper = NULL;
119     return;
120     }
121    
122     MyFree(source_p->localClient->response);
123     MyFree(source_p->localClient->auth_oper);
124     source_p->localClient->response = NULL;
125     source_p->localClient->auth_oper = NULL;
126    
127 michael 1636 conf = find_exact_name_conf(CONF_OPER, source_p, parv[1], NULL, NULL);
128 adx 30
129 michael 1632 if (!conf)
130 adx 30 {
131 michael 1834 sendto_one (source_p, form_str(ERR_NOOPERHOST), me.name, source_p->name);
132 michael 1632 conf = find_exact_name_conf(CONF_OPER, NULL, parv[1], NULL, NULL);
133 adx 30 failed_challenge_notice(source_p, parv[1], (conf != NULL)
134     ? "host mismatch" : "no oper {} block");
135     return;
136     }
137    
138 michael 1632 if (conf->rsa_public_key == NULL)
139 adx 30 {
140     sendto_one (source_p, ":%s NOTICE %s :I'm sorry, PK authentication "
141     "is not enabled for your oper{} block.", me.name,
142 michael 1230 source_p->name);
143 adx 30 return;
144     }
145    
146     if (!generate_challenge(&challenge, &(source_p->localClient->response),
147 michael 1632 conf->rsa_public_key))
148 michael 1834 sendto_one(source_p, form_str(RPL_RSACHALLENGE),
149 michael 1230 me.name, source_p->name, challenge);
150 adx 30
151 michael 1646 source_p->localClient->auth_oper = xstrdup(conf->name);
152 adx 30 MyFree(challenge);
153     }
154    
155 michael 1467 static void
156     mo_challenge(struct Client *client_p, struct Client *source_p,
157     int parc, char *parv[])
158     {
159 michael 1834 sendto_one(source_p, form_str(RPL_YOUREOPER),
160 michael 1467 me.name, source_p->name);
161     }
162    
163 michael 1230 static struct Message challenge_msgtab = {
164     "CHALLENGE", 0, 0, 2, MAXPARA, MFLG_SLOW, 0,
165 michael 1467 { m_unregistered, m_challenge, m_ignore, m_ignore, mo_challenge, m_ignore }
166 michael 1230 };
167    
168 adx 30 static void
169 michael 1230 module_init(void)
170 adx 30 {
171 michael 1230 mod_add_cmd(&challenge_msgtab);
172 adx 30 }
173 michael 1230
174     static void
175     module_exit(void)
176     {
177     mod_del_cmd(&challenge_msgtab);
178     }
179    
180 michael 1415 #else
181    
182     static void
183     module_init(void)
184     {
185     }
186    
187     static void
188     module_exit(void)
189     {
190     }
191     #endif
192    
193 michael 1230 struct module module_entry = {
194     .node = { NULL, NULL, NULL },
195     .name = NULL,
196     .version = "$Revision$",
197     .handle = NULL,
198     .modinit = module_init,
199     .modexit = module_exit,
200     .flags = 0
201     };

Properties

Name Value
svn:eol-style native
svn:keywords Id Revision