ViewVC Help
View File | Revision Log | Show Annotations | View Changeset | Root Listing
root/svn/ircd-hybrid/trunk/modules/m_challenge.c
Revision: 1666
Committed: Sun Nov 18 17:03:18 2012 UTC (12 years, 9 months ago) by michael
Content type: text/x-csrc
File size: 5656 byte(s)
Log Message:
- Cleanup unused header file includes
- Fixed minor compile warning in conf.c

File Contents

# Content
1 /*
2 * ircd-hybrid: an advanced Internet Relay Chat Daemon(ircd).
3 * m_challenge.c: Allows an IRC Operator to securely authenticate.
4 *
5 * Copyright (C) 2002 by the past and present ircd coders, and others.
6 *
7 * This program is free software; you can redistribute it and/or modify
8 * it under the terms of the GNU General Public License as published by
9 * the Free Software Foundation; either version 2 of the License, or
10 * (at your option) any later version.
11 *
12 * This program is distributed in the hope that it will be useful,
13 * but WITHOUT ANY WARRANTY; without even the implied warranty of
14 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
15 * GNU General Public License for more details.
16 *
17 * You should have received a copy of the GNU General Public License
18 * along with this program; if not, write to the Free Software
19 * Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307
20 * USA
21 *
22 * $Id$
23 */
24
25 #include "stdinc.h"
26 #include "client.h"
27 #include "ircd.h"
28 #include "modules.h"
29 #include "numeric.h"
30 #include "send.h"
31 #include "conf.h"
32 #include "rsa.h"
33 #include "parse.h"
34 #include "irc_string.h"
35 #include "log.h"
36 #include "s_user.h"
37 #include "memory.h"
38
39
40 #ifdef HAVE_LIBCRYPTO
41 /* failed_challenge_notice()
42 *
43 * inputs - pointer to client doing /oper ...
44 * - pointer to nick they tried to oper as
45 * - pointer to reason they have failed
46 * output - nothing
47 * side effects - notices all opers of the failed oper attempt if enabled
48 */
49 static void
50 failed_challenge_notice(struct Client *source_p, const char *name,
51 const char *reason)
52 {
53 if (ConfigFileEntry.failed_oper_notice)
54 sendto_realops_flags(UMODE_ALL, L_ALL, SEND_NOTICE,
55 "Failed CHALLENGE attempt as %s "
56 "by %s (%s@%s) - %s", name, source_p->name,
57 source_p->username, source_p->host, reason);
58
59 ilog(LOG_TYPE_OPER, "Failed CHALLENGE attempt as %s "
60 "by %s (%s@%s) - %s", name, source_p->name,
61 source_p->username, source_p->host, reason);
62 }
63
64 /*
65 * m_challenge - generate RSA challenge for wouldbe oper
66 * parv[0] = sender prefix
67 * parv[1] = operator to challenge for, or +response
68 *
69 */
70 static void
71 m_challenge(struct Client *client_p, struct Client *source_p,
72 int parc, char *parv[])
73 {
74 char *challenge = NULL;
75 struct MaskItem *conf = NULL;
76
77 if (*parv[1] == '+')
78 {
79 /* Ignore it if we aren't expecting this... -A1kmm */
80 if (source_p->localClient->response == NULL)
81 return;
82
83 if (irccmp(source_p->localClient->response, ++parv[1]))
84 {
85 sendto_one(source_p, form_str(ERR_PASSWDMISMATCH), me.name,
86 source_p->name);
87 failed_challenge_notice(source_p, source_p->localClient->auth_oper,
88 "challenge failed");
89 return;
90 }
91
92 conf = find_exact_name_conf(CONF_OPER, source_p,
93 source_p->localClient->auth_oper, NULL, NULL);
94 if (conf == NULL)
95 {
96 /* XXX: logging */
97 sendto_one (source_p, form_str(ERR_NOOPERHOST), me.name, source_p->name);
98 return;
99 }
100
101 if (attach_conf(source_p, conf) != 0)
102 {
103 sendto_one(source_p,":%s NOTICE %s :Can't attach conf!",
104 me.name, source_p->name);
105 failed_challenge_notice(source_p, conf->name, "can't attach conf!");
106 return;
107 }
108
109 oper_up(source_p);
110
111 ilog(LOG_TYPE_OPER, "OPER %s by %s!%s@%s",
112 source_p->localClient->auth_oper, source_p->name, source_p->username,
113 source_p->host);
114
115 MyFree(source_p->localClient->response);
116 MyFree(source_p->localClient->auth_oper);
117 source_p->localClient->response = NULL;
118 source_p->localClient->auth_oper = NULL;
119 return;
120 }
121
122 MyFree(source_p->localClient->response);
123 MyFree(source_p->localClient->auth_oper);
124 source_p->localClient->response = NULL;
125 source_p->localClient->auth_oper = NULL;
126
127 conf = find_exact_name_conf(CONF_OPER, source_p, parv[1], NULL, NULL);
128
129 if (!conf)
130 {
131 sendto_one (source_p, form_str(ERR_NOOPERHOST), me.name, source_p->name);
132 conf = find_exact_name_conf(CONF_OPER, NULL, parv[1], NULL, NULL);
133 failed_challenge_notice(source_p, parv[1], (conf != NULL)
134 ? "host mismatch" : "no oper {} block");
135 return;
136 }
137
138 if (conf->rsa_public_key == NULL)
139 {
140 sendto_one (source_p, ":%s NOTICE %s :I'm sorry, PK authentication "
141 "is not enabled for your oper{} block.", me.name,
142 source_p->name);
143 return;
144 }
145
146 if (!generate_challenge(&challenge, &(source_p->localClient->response),
147 conf->rsa_public_key))
148 sendto_one(source_p, form_str(RPL_RSACHALLENGE),
149 me.name, source_p->name, challenge);
150
151 source_p->localClient->auth_oper = xstrdup(conf->name);
152 MyFree(challenge);
153 }
154
155 static void
156 mo_challenge(struct Client *client_p, struct Client *source_p,
157 int parc, char *parv[])
158 {
159 sendto_one(source_p, form_str(RPL_YOUREOPER),
160 me.name, source_p->name);
161 }
162
163 static struct Message challenge_msgtab = {
164 "CHALLENGE", 0, 0, 2, MAXPARA, MFLG_SLOW, 0,
165 { m_unregistered, m_challenge, m_ignore, m_ignore, mo_challenge, m_ignore }
166 };
167
168 static void
169 module_init(void)
170 {
171 mod_add_cmd(&challenge_msgtab);
172 }
173
174 static void
175 module_exit(void)
176 {
177 mod_del_cmd(&challenge_msgtab);
178 }
179
180 #else
181
182 static void
183 module_init(void)
184 {
185 }
186
187 static void
188 module_exit(void)
189 {
190 }
191 #endif
192
193 struct module module_entry = {
194 .node = { NULL, NULL, NULL },
195 .name = NULL,
196 .version = "$Revision$",
197 .handle = NULL,
198 .modinit = module_init,
199 .modexit = module_exit,
200 .flags = 0
201 };

Properties

Name Value
svn:eol-style native
svn:keywords Id Revision