File manager - Edit - /home/ferretapmx/public_html/ostic.tar
Back
info.xml 0000644 00000012641 15231166170 0006227 0 ustar 00 <soft xmlns="http://www.softaculous.com"> <overview> <img src="logo.jpg" style="float:right;margin:10px;" alt="" />{{overview}} </overview> <features> {{features}} </features> <demo> http://www.softaculous.com/demos/osTicket </demo> <ratings> http://www.softaculous.com/softwares/customersupport/osTicket </ratings> <space> 111079800 </space> <support> http://osticket.com/ </support> <version> 1.18.4 </version> <mod>72</mod> <release_date>17-06-2026</release_date> <branch>83</branch> <branch>715</branch> <branch>671</branch> <branch>657</branch> <admin>scp</admin> <min_require>1.6.0</min_require> <softversion> 4.5.4 </softversion> <requirement check="php" type="version" operator="ge" value="8.2.0" /> <requirement check="mysql" type="version" operator="ge" value="5.5.0" /> <requirement check="php" type="extension" name="mysqli" /> <languages> <english-overview> <font size="5" color="#182e7a">osTicket</font> is a widely-used open source support ticket system. It seamlessly integrates inquiries created via email and web-based forms into a simple easy to use multi-user web interface. Easily manage, organize and archive all your support requests and responses in one place while providing your clients with accountability and responsiveness they deserve. <br /><br /> osTicket is an attractive alternative to higher-cost and complex customer support systems; simple, lightweight, reliable, open source, and easy to setup and use. The best part is, it's completely free. <br /><br /> osTicket is released under the <a href="http://www.gnu.org/licenses/gpl.html" target="_blank">GNU/GPL license</a>. </english-overview> <english-features> <br /> <font size="2" color="#E64D20">Web-based Platform </font>: osTicket is a web-based multi-user customer support platform. No local installation required. Access it anytime - from anywhere.<br /><br /> <font size="2" color="#E64D20">Customer Portal </font>: All support requests and responses are archived online. User can login using email and ticket ID. No user account or registration required to submit a ticket.<br /><br /> <font size="2" color="#E64D20">Autoresponder </font>: Configurable automatic reply sent out when a new ticket is opened or a message is received.<br /><br /> <font size="2" color="#E64D20">Email Integration </font>: Tickets can be created via email, online forms or phone (created by staff). Flexible configuration and mapping.<br /><br /> <font size="2" color="#E64D20">Role-based Access </font>: Control staff's access level based on assigned groups, departments and teams.<br /><br /> <font size="2" color="#E64D20">Collision Avoidance </font>: Ticket locking mechanism to allow staff to lock tickets during response and avoid conflicting responses.<br /><br /> <font size="2" color="#E64D20">Ticket Assignment </font>: Assign tickets to a staff or a teams. Assignment notes are logged as internal notes.<br /><br /> <font size="2" color="#E64D20">Ticket Transfer </font>: Transfer tickets between departments to make sure it's being handled by the correct staff.<br /><br /> <font size="2" color="#E64D20">Due Dates </font>: Set due dates on individual tickets and overwrite default grace period. Get overdue alerts and notices on missed due dates.<br /><br /> <font size="2" color="#E64D20">Alerts & Notices </font>: Staff and clients are kept up to date with email alerts. Configurable and flexible settings.<br /><br /> <font size="2" color="#E64D20">Dashboard & Reports </font>: Get system overview and basic historical statistics on tickets count and status per department, staff and help topics.<br /><br /> <font size="2" color="#E64D20">Canned Responses </font>: Predefined responses for frequently asked questions. Ticket variables supported for personalized responses.<br /><br /> <font size="2" color="#E64D20">Internal Notes </font>: Add internal notes to tickets for staff. Activity logs let you see events or what actions have been taken, when, and by whom. <br /><br /> <font size="2" color="#E64D20">Attachment Support </font>: Allow web or emailed attachments. Configurable file type whitelisting to enhance security.<br /><br /> <font size="2" color="#E64D20">Email Templates </font>: Manage and configure email templates used for auto-reply, alerts, notices and responses. Ticket variables supported for personalized messages.<br /><br /> <font size="2" color="#E64D20">Ticket Filters </font>: Apply conditional rules to route incoming tickets to the right departments or staff members, and action triggers.<br /><br /> <font size="2" color="#E64D20">Service Level Agreements </font>: SLA support allow you to track tickets and due dates without the hassle. Get overdue alerts and notices on missed due dates, and priority escalation.<br /><br /> </english-features> <english-exp_ad_pass>New password. Leave blank if you do not want to reset the password</english-exp_ad_pass> <english-err_no_username>Please provide the username to reset the password</english-err_no_username> <english-err_no_such_user>The Admin username is incorrect and does not exist!</english-err_no_such_user> <english-err_no_dbprefix>Could not determine the database prefix</english-err_no_dbprefix> <english-system_email>System Email</english-system_email> <english-sys_email_exp>System Email can not be as same as Admin Email</english-sys_email_exp> <english-admin_email_exp>Admin Email can not be as same as System Email</english-admin_email_exp> </languages> </soft> changelog.txt 0000644 00000001545 15231166170 0007243 0 ustar 00 osTicket v1.18.4 Security security: Latest Patches 06/2026 (52c366f, 5afdf54, c54a6ac, 1e39bf1, feccb6a, 6eb6b98, 078516e, 98abb05, e52e010, fd96bba, 7bbd8ab, ba6217a, 580e1c8, b535782, 5963797, d590a97, eaebe01, b4cc092, d457c14, 5600f94, 5ff9795, 119cefe, b4ede88, 2a0c388, 6558b33) osTicket v1.18.3 Enhancements mPDF: Upgrade To v8.2.7 (39cdd2b) htmLawed: Upgrade To 1.2.15 (877adf5) Security security: Latest Patches 01/2026 (c646c8c, d1b634a, 6852e71, 8db4d37, 1552cfa, d832f24) osTicket v1.18.2 Improvements OAuth2: Show Scopes and Enforce Strict Mode (a77cf535, 390555db) osTicket v1.18.1 Improvements Update upgrade.php (9fd83eba) Update upgrade.inc.php (8c8a7fd1) update: PHP Requirements 1.18.x (1c0c670b) CLI: Make sure manage util can be executed via CLI (0caf5864) Update raphael-min.js to 2.3.0 (d4aeada1) import.php 0000644 00000011013 15231166170 0006565 0 ustar 00 <?php //0046a if(!extension_loaded('ionCube Loader')){$__oc=strtolower(substr(php_uname(),0,3));$__ln='ioncube_loader_'.$__oc.'_'.substr(phpversion(),0,3).(($__oc=='win')?'.dll':'.so');if(function_exists('dl')){@dl($__ln);}if(function_exists('_il_exec')){return _il_exec();}$__ln='/ioncube/'.$__ln;$__oid=$__id=realpath(ini_get('extension_dir'));$__here=dirname(__FILE__);if(strlen($__id)>1&&$__id[1]==':'){$__id=str_replace('\\','/',substr($__id,2));$__here=str_replace('\\','/',substr($__here,2));}$__rd=str_repeat('/..',substr_count($__id,'/')).$__here.'/';$__i=strlen($__rd);while($__i--){if($__rd[$__i]=='/'){$__lp=substr($__rd,0,$__i).$__ln;if(file_exists($__oid.$__lp)){$__ln=$__lp;break;}}}if(function_exists('dl')){@dl($__ln);}}else{die('The file '.__FILE__." is corrupted.\n");}if(function_exists('_il_exec')){return _il_exec();}echo('Site error: the file <b>'.__FILE__.'</b> requires the ionCube PHP Loader '.basename($__ln).' to be installed by the website operator. If you are the website operator please use the <a href="http://www.ioncube.com/lw/">ionCube Loader Wizard</a> to assist with installation.');exit(199); ?> HR+cPuwP/tGs66V4EV4hQXNVDDyt+xXvOed6jPoibzHA7dnLGAV+Q0a2TFCXp3PZOCNTUdmwPchJ PU95mL5lEwSbQOYVPwhnLLOZizImh3qpOrUg7KVyUPYfQDzKBJWnNNi2dqmRaVs/jWOUINBk1UMs iaXjtWkgTUTtj7kpYzyKxJgMWcqnyAE/nQzCn0LAutVa8d8V4t7CYmSAGFQ6fIw5ODqPROvUQH06 p9NcVHlPoUpsWIJOMcjOXcCO7Z6HVHbah54OICMMmo1W1/sIAbujYPP5aFYcSJ02/tN5jzIUK6rk XKnHDMRN390/gTXaD2pWa68IAwoPeUV8O8G8J/fuGI47QQyGnCXwt3MfMo/IU6zqycBHg5iCjBWU GlMhrn+REdNAhI+v354RsBZxq+8jGfJlLFQ7Tc5Olu1MTOqUGl6qZPKrq+pqCk3A6nUvuGFXY/C2 c+ZGBr49mv6Q0cFwwKPEd4SS/1oZJHTflBhFftb98g/ZfUo7ZRV158T5KpMw9sowvKemG7oUx9qu sWnPiVKSYjrOT1UUM0cFH/mxWaJSSF3KEkENm7Kdf57UChjzY8z8hKLdcGWoGsaUAfvejrHLwqSt a5JxerIcuWbzYSumxJZ4+aNb+NC9SVSAGOiCmFu3a+nBhpx8z/6gT+DJZSDOGzqQ5knUMXWqJz4U zl0xBxep9X1zkKb+USFbNY30yoVLJ9DBATw+2g0slX2EBQg6HTolgOTE2zK9HxF7D1LQtljvT32+ DNWcL6EL+iiYWTJo05f+Z2Y7GkAHbgkigBr2OeRr6E/SFt7YgejNYxx9bnU7vMXLgGuTOzI/ojeT gQXoRunfWjB88yjwPWRtoVfkP0eGVO29FXH5Mm2Qq66eRnc8EGQBVaqdyNt4wdKK+iC9KicBT/ag YHUMzTMwL3NIRRuveIMaRyBykFLFrGAcZRm97P+dQS6z27NKT2XZpT1RkbmboEL80GLXtIOX1bAN 8knSioYBFmqxKrYbm5G91HZk3b8MpHzh/lRmqs04TZVgtq0+yV9Wbom+7g2kaRJp4K3BU69B3tOR 3n/Za4FHIJ5dcZh8pMUFlOYKJb5QJAFNDexdIvfx7OhIgYVm+m3CDSNz7RFRorHs2gQmMz2Cr7ly 2MWdn2wDNJS0hdPMUH2ZToBT8Ak7xfJE/4/fcMmUAYWQ2n4XWfEMGLpvyrNhFgtCToRuAx6OjRgK YtBryrxU+8YK6eUuFLTi2QbdK7aPqM+dQm+3/y7vZNRs5csCTnlrzHKLRNPk5PvDjJXCYlWu507N kSYpSDPtAjFOZuASV18Gvvzlv8VpWzzVlPvTOFdXSAKWJ5DMGrMfzv9TPtshijIOmZh/OWmYMiv1 FwkdRpjbIG5EJUkK7DciRVHCbaVrts/ZYNp/LFYAt27R1YKBMHk4n5+rVlYEm1NZqhrinqg0YIzQ rYLGdKQ104tsDHeox2uPAv5neO96ghxumQ+HafjhWPQHwaAatXRu0vtF3xHWiJtoEr6HsOZT93+x W27WiT1O3Cy5T90vuz0umHNc31YMENlJDH2RUSC8mNh9ZsCALm70g5IYBEZs59aeXI/15hYZggI0 RgkzZI0nFo4Kk8JDNIz3B4tium6l8alTqk98L55c7UQHm4yR/fYu3c3KEUD2c7PunZflm+M+z3e/ jIspKcCcSLiMTLl/Dc0uC2D/b4EseXhcaMatCKMiTLRtTKHuCgN5rnsTvuy9jaZ3C/RK5lrBCv5P u+Qh/pdGAq5FtvtgHV1E3fMN4THIhH5qqW+eXyH8+4jJhMBrwvIBaARd9T5BZIUNJr3/xOtEVhIN fVp7rXbPruvhnaPFZLlpg6Z8lYbb6im9V/04c+mWhT/v9xUC/sOjMlWUkwfFsDkOFO+y8vOeqJP1 qsoA0SAIYpCsEHKPpo2sJS6GHcMbZoJfS24V1LA0C7IGqDWzty9Yx3PebMCSP62Yqdz42/LLJ0rx Go3L3RhN4P9pTSjowWTqLUZwM8qfqVag+YBRUSPPcG1kce4us6AdGydMP10sAmcuqk6mvkp5vcyU sjYZ29JXVozmuSXtTcrOkILOpd81MpvjIYqliVDqPfLBqWw2S7jq1+x3L+ReQEnqvMgYxotc8O4X 68GkN82LIttcdFYWD+TWmjiWPj3wtB3KCD/mEaxsIYGCoI1Idtu5PO00X2IsyuKpyMOx0RRKjgAr jJl8YT0NddxqyK4T1u4OgCliJR70CnrsHbD/9Oa2Ogo/R2eDazdP8Vz+jwpv1P51RD/tTOpqMr4W RSKweS5mM5tij2ECm523o1erKM+fI6677aHtVl9ZFQR9VdcGtsiGpJGU1WUYdvbb1GkSJ5eF+TjF /k1quzgGwry/P9Mfv8rdbLOMTZCjaRgpM0OBfQKJ1+2smn2aj0lGZd6AS2Me3WNiidY0DIhLvhhy 2qALMimBduT14GgvmixLMh8lUPRcO9fhgkA4dOMxrQ09GeaHNjOXW/JiWokIYGgs4TpjbpFiFQ/t HO0PH+NVrHIoR5fNG30kVT9fmP0H+HKwWMpt5kZ8FQOxtIqd+xAccf0d8JKVtYBGDaLfXzCUQRD2 Yk4m3Z1JY0W7Xvof/KgB89lerMLBA75ggcoMJ30uXRrZz4Klo0pjrxg4cjnGHjcuO/nVIFdjvrYQ WdkvbxKWWL9B5K7RBmP0xOH6W5Ie3flOWTd4Bps0tVA+fdb23Wr8G2lzCWOjztLTRWw2R6Xky7R7 NfgULk3gAZfkNMk/CKnOfvfPuQ0ThVz3A1sKDZ8AeeX9JzI+uHGVDi4W61hjS4xUDfiPg7EPRlr1 WzlHwXYwHSz3Zrvimp+iXnITrIWlYrJNoyvqbHqgeRbHTB2P+3V95nFfFIqYUtnuRtTkukj4R2sW /j2U/ciiuR5pyV3ZBLKRyQ9+TgbXaWBCO+yDOfeWsHINO1yoLEt6yIWg18pvxcY6oAfh46yfrLhK V52Fk1x1FwbQeWWrYhNrV2Q6Pd9egvma9BEjw0K4/iihJuk6K2u2Gu5VP4IDgTjoHWCJGbFYG56W cCx+xv4VzhkXSZ7clt6V57v5KtoPRp4beGDt00D42r3O9+zeNRs65XCHWlo6ty6vKZAggjvDB1LQ md/wBpGXD/ZdX9wWoO03ZrnQpHBaq356h/35BwSGpvyJ2W3rBHxLOj3Weye6c0MO08s2vwDsTAr/ Lpif+BuPEpaIV5nEuhqXYQ9KudjiSJq5+iOcvWND4hENFVbWCka/7CvpUg9P8ia1clHxHZXJm7Y0 4G/Qb3UjbmAWtm9VIMiQIam/xONrguKzXlu2a4dipcJFMf8hgZHCLXo7lNlFXm3soAchwu8D6bq/ k79TgoPSqeGnjQykp5YH7G77PUAQrf77qL8kT1armirovasVX4SzKwQVGPwRlzBsIjmPio011FKL KRI1NHi2dLEhx8ReRW== ost-config.php 0000644 00000014363 15231166170 0007336 0 ustar 00 <?php /********************************************************************* ost-config.php Static osTicket configuration file. Mainly useful for mysql login info. Created during installation process and shouldn't change even on upgrades. Peter Rotich <peter@osticket.com> Copyright (c) 2006-2010 osTicket http://www.osticket.com Released under the GNU General Public License WITHOUT ANY WARRANTY. See LICENSE.TXT for details. vim: expandtab sw=4 ts=4 sts=4: $Id: $ **********************************************************************/ #Disable direct access. if(!strcasecmp(basename($_SERVER['SCRIPT_NAME']),basename(__FILE__)) || !defined('INCLUDE_DIR')) die('kwaheri rafiki!'); #Install flag define('OSTINSTALLED',TRUE); if(OSTINSTALLED!=TRUE){ if(!file_exists(ROOT_DIR.'setup/install.php')) die('Error: Contact system admin.'); //Something is really wrong! //Invoke the installer. header('Location: '.ROOT_PATH.'setup/install.php'); exit; } # Encrypt/Decrypt secret key - randomly generated during installation. define('SECRET_SALT','[[SECRET_SALT]]'); #Default admin email. Used only on db connection issues and related alerts. define('ADMIN_EMAIL','[[admin_email]]'); # Database Options # ==================================================== # Mysql Login info # define('DBTYPE','mysql'); # DBHOST can have comma separated hosts (e.g db1:6033,db2:6033) define('DBHOST','[[softdbhost]]'); define('DBNAME','[[softdb]]'); define('DBUSER','[[softdbuser]]'); define('DBPASS','[[softdbpass]]'); # Database TCP/IP Connect Timeout (default: 3 seconds) # Timeout is important when DBHOST has multiple proxies to try # define('DBCONNECT_TIMEOUT', 3); # Table prefix define('TABLE_PREFIX','[[dbprefix]]'); # # SSL Options # --------------------------------------------------- # SSL options for MySQL can be enabled by adding a certificate allowed by # the database server here. To use SSL, you must have a client certificate # signed by a CA (certificate authority). You can easily create this # yourself with the EasyRSA suite. Give the public CA certificate, and both # the public and private parts of your client certificate below. # # Once configured, you can ask MySQL to require the certificate for # connections: # # > create user osticket; # > grant all on osticket.* to osticket require subject '<subject>'; # # More information (to-be) available in doc/security/hardening.md # define('DBSSLCA','/path/to/ca.crt'); # define('DBSSLCERT','/path/to/client.crt'); # define('DBSSLKEY','/path/to/client.key'); # # Mail Options # =================================================== # Option: MAIL_EOL (default: \n) # # Some mail setups do not handle emails with \r\n (CRLF) line endings for # headers and base64 and quoted-response encoded bodies. This is an error # and a violation of the internet mail RFCs. However, because this is also # outside the control of both osTicket development and many server # administrators, this option can be adjusted for your setup. Many folks who # experience blank or garbled email from osTicket can adjust this setting to # use "\n" (LF) instead of the CRLF default. # # References: # http://www.faqs.org/rfcs/rfc2822.html # https://github.com/osTicket/osTicket-1.8/issues/202 # https://github.com/osTicket/osTicket-1.8/issues/700 # https://github.com/osTicket/osTicket-1.8/issues/759 # https://github.com/osTicket/osTicket-1.8/issues/1217 # define(MAIL_EOL, "\r\n"); # # HTTP Server Options # =================================================== # Option: ROOT_PATH (default: <auto detect>, fallback: /) # # If you have a strange HTTP server configuration and osTicket cannot # discover the URL path of where your osTicket is installed, define # ROOT_PATH here. # # The ROOT_PATH is the part of the URL used to access your osTicket # helpdesk before the '/scp' part and after the hostname. For instance, for # http://mycompany.com/support', the ROOT_PATH should be '/support/' # # ROOT_PATH *must* end with a forward-slash! # define('ROOT_PATH', '/support/'); # Option: TRUSTED_PROXIES (default: <none>) # # To support running osTicket installation on a web servers that sit behind a # load balancer, HTTP cache, or other intermediary (reverse) proxy; it's # necessary to define trusted proxies to protect against forged http headers # # osTicket supports passing the following http headers from a trusted proxy; # - HTTP_X_FORWARDED_FOR => Chain of client's IPs # - HTTP_X_FORWARDED_PROTO => Client's HTTP protocal (http | https) # # You'll have to explicitly define comma separated IP addreseses or CIDR of # upstream proxies to trust. Wildcard "*" (not recommended) can be used to # trust all chained IPs as proxies in cases that ISP/host doesn't provide # IPs of loadbalancers or proxies. # # References: # http://en.wikipedia.org/wiki/X-Forwarded-For # define('TRUSTED_PROXIES', ''); # Option: LOCAL_NETWORKS (default: 127.0.0.0/24) # # When running osTicket as part of a cluster it might become necessary to # whitelist local/virtual networks that can bypass some authentication/checks. # # define comma separated IP addreseses or enter CIDR of local network. define('LOCAL_NETWORKS', '127.0.0.0/24'); # # Session Options # =================================================== # # Session Name (SESSID) # --------------------------------------------------- # Option: SESSION_SESSID (default: OSTSESID) # # osTicket Session Name (SESSID) - used to set session cookie define('SESSION_SESSID', 'OSTSESSID'); # Session Storage Backends # --------------------------------------------------- # Option: SESSION_BACKEND (default: database) # # Values: 'database' (default) # 'memcache' (Use Memcache servers) # 'memcache.database' (Memcache Primary, Database Secondary) # 'system' (use PHP settings as configured (not recommended!)) # # osTicket supports Database by default as well as Memcache as a session # storage backend if the `memcache` pecl extesion is installed. This also # requires MEMCACHE_SERVERS to be configured as well. # # MEMCACHE_SERVERS can be defined as a comma-separated list of host:port # specifications. If more than one server is listed, the session is written # to all of the servers for redundancy. # # define('SESSION_BACKEND', 'memcache'); # define('MEMCACHE_SERVERS', 'server1:11211,server2:11211'); ?> notes.txt 0000644 00000001137 15231166170 0006441 0 ustar 00 1. schema_signature same for every install 2. Make script where Database ENGINE is InnoDB 3. Don't convert ostic.sql and languages files to utf8 4. PHP REQUIREMENT LINK : https://osticket.com/download/ 5. Download and update language from "https://osticket.com/download/#ostLang" 6. Check language update in next version(In 1.14.2 languages weren't properly updated) 7. If language packs doesn't download from site. Try to download using following URL depending upon script version. https://s3.amazonaws.com/downloads.osticket.com/lang/1.14.x/[[LANG_CODE]].phar (languages are not available for 1.15, 1.16) update_pass.php 0000644 00000015047 15231166170 0007576 0 ustar 00 <?php // We do not need this file any more @unlink('update_pass.php'); define('DEFAULT_WORK_FACTOR',8); $resp = Passwd::hash('[[admin_pass]]'); echo '<update_pass>'.$resp.'</update_pass>'; class PasswordHash { var $itoa64; var $iteration_count_log2; var $portable_hashes; var $random_state; function __construct($iteration_count_log2, $portable_hashes) { $this->itoa64 = './0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz'; if ($iteration_count_log2 < 4 || $iteration_count_log2 > 31) $iteration_count_log2 = 8; $this->iteration_count_log2 = $iteration_count_log2; $this->portable_hashes = $portable_hashes; $this->random_state = microtime(); if (function_exists('getmypid')) $this->random_state .= getmypid(); } function get_random_bytes($count) { $output = ''; if (@is_readable('/dev/urandom') && ($fh = @fopen('/dev/urandom', 'rb'))) { $output = fread($fh, $count); fclose($fh); } if (strlen($output) < $count) { $output = ''; for ($i = 0; $i < $count; $i += 16) { $this->random_state = md5(microtime() . $this->random_state); $output .= pack('H*', md5($this->random_state)); } $output = substr($output, 0, $count); } return $output; } function encode64($input, $count) { $output = ''; $i = 0; do { $value = ord($input[$i++]); $output .= $this->itoa64[$value & 0x3f]; if ($i < $count) $value |= ord($input[$i]) << 8; $output .= $this->itoa64[($value >> 6) & 0x3f]; if ($i++ >= $count) break; if ($i < $count) $value |= ord($input[$i]) << 16; $output .= $this->itoa64[($value >> 12) & 0x3f]; if ($i++ >= $count) break; $output .= $this->itoa64[($value >> 18) & 0x3f]; } while ($i < $count); return $output; } function gensalt_private($input) { $output = '$P$'; $output .= $this->itoa64[min($this->iteration_count_log2 + ((PHP_VERSION >= '5') ? 5 : 3), 30)]; $output .= $this->encode64($input, 6); return $output; } function crypt_private($password, $setting) { $output = '*0'; if (substr($setting, 0, 2) == $output) $output = '*1'; $id = substr($setting, 0, 3); # We use "$P$", phpBB3 uses "$H$" for the same thing if ($id != '$P$' && $id != '$H$') return $output; $count_log2 = strpos($this->itoa64, $setting[3]); if ($count_log2 < 7 || $count_log2 > 30) return $output; $count = 1 << $count_log2; $salt = substr($setting, 4, 8); if (strlen($salt) != 8) return $output; # We're kind of forced to use MD5 here since it's the only # cryptographic primitive available in all versions of PHP # currently in use. To implement our own low-level crypto # in PHP would result in much worse performance and # consequently in lower iteration counts and hashes that are # quicker to crack (by non-PHP code). if (PHP_VERSION >= '5') { $hash = md5($salt . $password, TRUE); do { $hash = md5($hash . $password, TRUE); } while (--$count); } else { $hash = pack('H*', md5($salt . $password)); do { $hash = pack('H*', md5($hash . $password)); } while (--$count); } $output = substr($setting, 0, 12); $output .= $this->encode64($hash, 16); return $output; } function gensalt_extended($input) { $count_log2 = min($this->iteration_count_log2 + 8, 24); # This should be odd to not reveal weak DES keys, and the # maximum valid value is (2**24 - 1) which is odd anyway. $count = (1 << $count_log2) - 1; $output = '_'; $output .= $this->itoa64[$count & 0x3f]; $output .= $this->itoa64[($count >> 6) & 0x3f]; $output .= $this->itoa64[($count >> 12) & 0x3f]; $output .= $this->itoa64[($count >> 18) & 0x3f]; $output .= $this->encode64($input, 3); return $output; } function gensalt_blowfish($input) { # This one needs to use a different order of characters and a # different encoding scheme from the one in encode64() above. # We care because the last character in our encoded string will # only represent 2 bits. While two known implementations of # bcrypt will happily accept and correct a salt string which # has the 4 unused bits set to non-zero, we do not want to take # chances and we also do not want to waste an additional byte # of entropy. $itoa64 = './ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789'; $output = '$2a$'; $output .= chr(ord('0') + $this->iteration_count_log2 / 10); $output .= chr(ord('0') + $this->iteration_count_log2 % 10); $output .= '$'; $i = 0; do { $c1 = ord($input[$i++]); $output .= $itoa64[$c1 >> 2]; $c1 = ($c1 & 0x03) << 4; if ($i >= 16) { $output .= $itoa64[$c1]; break; } $c2 = ord($input[$i++]); $c1 |= $c2 >> 4; $output .= $itoa64[$c1]; $c1 = ($c2 & 0x0f) << 2; $c2 = ord($input[$i++]); $c1 |= $c2 >> 6; $output .= $itoa64[$c1]; $output .= $itoa64[$c2 & 0x3f]; } while (1); return $output; } function HashPassword($password) { $random = ''; if (CRYPT_BLOWFISH == 1 && !$this->portable_hashes) { $random = $this->get_random_bytes(16); $hash = crypt($password, $this->gensalt_blowfish($random)); if (strlen($hash) == 60) return $hash; } if (CRYPT_EXT_DES == 1 && !$this->portable_hashes) { if (strlen($random) < 3) $random = $this->get_random_bytes(3); $hash = crypt($password, $this->gensalt_extended($random)); if (strlen($hash) == 20) return $hash; } if (strlen($random) < 6) $random = $this->get_random_bytes(6); $hash = $this->crypt_private($password, $this->gensalt_private($random)); if (strlen($hash) == 34) return $hash; # Returning '*' on error is safe here, but would _not_ be safe # in a crypt(3)-like function used _both_ for generating new # hashes and for validating passwords against existing hashes. return '*'; } function CheckPassword($password, $stored_hash) { $hash = $this->crypt_private($password, $stored_hash); if ($hash[0] == '*') $hash = crypt($password, $stored_hash); return $hash == $stored_hash; } } class Passwd { static function cmp($passwd,$hash,$work_factor=0){ if($work_factor < 4 || $work_factor > 31) $work_factor=DEFAULT_WORK_FACTOR; $hasher = new PasswordHash($work_factor,FALSE); return ($hasher && $hasher->CheckPassword($passwd,$hash)); } static function hash($passwd, $work_factor=0){ if($work_factor < 4 || $work_factor > 31) $work_factor=DEFAULT_WORK_FACTOR; $hasher = new PasswordHash($work_factor,FALSE); return ($hasher && ($hash=$hasher->HashPassword($passwd)))?$hash:null; } } ?>