From 26086981a24e72f283da38dbdb992f27b4135a80 Mon Sep 17 00:00:00 2001 From: Aleksander Machniak <alec@alec.pl> Date: Tue, 08 Sep 2015 11:38:19 -0400 Subject: [PATCH] Improve randomness of security tokens (#1490529) --- program/lib/Roundcube/rcube_utils.php | 182 +++++++++++++++++++++++++++++---------------- 1 files changed, 116 insertions(+), 66 deletions(-) diff --git a/program/lib/Roundcube/rcube_utils.php b/program/lib/Roundcube/rcube_utils.php index 0ca2a9e..063296d 100644 --- a/program/lib/Roundcube/rcube_utils.php +++ b/program/lib/Roundcube/rcube_utils.php @@ -1,6 +1,6 @@ <?php -/* +/** +-----------------------------------------------------------------------+ | This file is part of the Roundcube Webmail client | | Copyright (C) 2008-2012, The Roundcube Dev Team | @@ -134,7 +134,6 @@ return false; } - /** * Validates IPv4 or IPv6 address * @@ -144,41 +143,8 @@ */ public static function check_ip($ip) { - // IPv6, but there's no build-in IPv6 support - if (strpos($ip, ':') !== false && !defined('AF_INET6')) { - $parts = explode(':', $ip); - $count = count($parts); - - if ($count > 8 || $count < 2) { - return false; - } - - foreach ($parts as $idx => $part) { - $length = strlen($part); - if (!$length) { - // there can be only one :: - if ($found_empty) { - return false; - } - $found_empty = true; - } - // last part can be an IPv4 address - else if ($idx == $count - 1) { - if (!preg_match('/^[0-9a-f]{1,4}$/i', $part)) { - return @inet_pton($part) !== false; - } - } - else if (!preg_match('/^[0-9a-f]{1,4}$/i', $part)) { - return false; - } - } - - return true; - } - - return @inet_pton($ip) !== false; + return filter_var($ip, FILTER_VALIDATE_IP) !== false; } - /** * Check whether the HTTP referer matches the current request @@ -187,18 +153,18 @@ */ public static function check_referer() { - $uri = parse_url($_SERVER['REQUEST_URI']); + $uri = parse_url($_SERVER['REQUEST_URI']); $referer = parse_url(self::request_header('Referer')); + return $referer['host'] == self::request_header('Host') && $referer['path'] == $uri['path']; } - /** * Replacing specials characters to a specific encoding type * * @param string Input string * @param string Encoding type: text|html|xml|js|url - * @param string Replace mode for tags: show|replace|remove + * @param string Replace mode for tags: show|remove|strict * @param boolean Convert newlines * * @return string The quoted string @@ -206,8 +172,8 @@ public static function rep_specialchars_output($str, $enctype = '', $mode = '', $newlines = true) { static $html_encode_arr = false; - static $js_rep_table = false; - static $xml_rep_table = false; + static $js_rep_table = false; + static $xml_rep_table = false; if (!is_string($str)) { $str = strval($str); @@ -222,8 +188,11 @@ $encode_arr = $html_encode_arr; - // don't replace quotes and html tags - if ($mode == 'show' || $mode == '') { + if ($mode == 'remove') { + $str = strip_tags($str); + } + else if ($mode != 'strict') { + // don't replace quotes and html tags $ltpos = strpos($str, '<'); if ($ltpos !== false && strpos($str, '>', $ltpos) !== false) { unset($encode_arr['"']); @@ -231,9 +200,6 @@ unset($encode_arr['>']); unset($encode_arr['&']); } - } - else if ($mode == 'remove') { - $str = strip_tags($str); } $out = strtr($str, $encode_arr); @@ -256,8 +222,8 @@ $js_rep_table["'"] = "\\'"; $js_rep_table["\\"] = "\\\\"; // Unicode line and paragraph separators (#1486310) - $js_rep_table[chr(hexdec(E2)).chr(hexdec(80)).chr(hexdec(A8))] = '
'; - $js_rep_table[chr(hexdec(E2)).chr(hexdec(80)).chr(hexdec(A9))] = '
'; + $js_rep_table[chr(hexdec('E2')).chr(hexdec('80')).chr(hexdec('A8'))] = '
'; + $js_rep_table[chr(hexdec('E2')).chr(hexdec('80')).chr(hexdec('A9'))] = '
'; } // encode for javascript use @@ -267,7 +233,7 @@ // encode for plaintext if ($enctype == 'text') { - return str_replace("\r\n", "\n", $mode=='remove' ? strip_tags($str) : $str); + return str_replace("\r\n", "\n", $mode == 'remove' ? strip_tags($str) : $str); } if ($enctype == 'url') { @@ -282,7 +248,6 @@ // no encoding given -> return original string return $str; } - /** * Read input value and convert it for internal use @@ -323,7 +288,6 @@ return self::parse_input_value($value, $allow_html, $charset); } - /** * Parse/validate input value. See self::get_input_value() @@ -375,7 +339,6 @@ return $value; } - /** * Convert array of request parameters (prefixed with _) * to a regular array with non-prefixed keys. @@ -401,7 +364,6 @@ return $out; } - /** * Convert the given string into a valid HTML identifier * Same functionality as done in app.js with rcube_webmail.html_identifier() @@ -415,7 +377,6 @@ return asciiwords($str, true, '_'); } } - /** * Replace all css definitions with #container [def] @@ -493,7 +454,6 @@ return $source; } - /** * Generate CSS classes from mimetype and filename extension * @@ -524,7 +484,6 @@ return join(" ", $classes); } - /** * Decode escaped entities used by known XSS exploits. * See http://downloads.securityfocus.com/vulnerabilities/exploits/26800.eml for examples @@ -543,7 +502,6 @@ return $out; } - /** * preg_replace_callback callback for xss_entity_decode * @@ -555,7 +513,6 @@ { return chr(hexdec($matches[1])); } - /** * Check if we can process not exceeding memory_limit @@ -571,7 +528,6 @@ return $mem_limit > 0 && $memory + $need > $mem_limit ? false : true; } - /** * Check if working in SSL mode @@ -600,7 +556,6 @@ return false; } - /** * Replaces hostname variables. @@ -639,7 +594,6 @@ return str_replace(array('%n', '%t', '%d', '%h', '%z', '%s'), array($n, $t, $d, $h, $z, $s[2]), $name); } - /** * Returns remote IP address and forwarded addresses if found * @@ -664,7 +618,6 @@ return $address; } - /** * Returns the real remote IP address @@ -746,7 +699,6 @@ return $result; } - /** * Improved equivalent to strtotime() @@ -878,7 +830,6 @@ return self::idn_convert($str, true); } - /* * Idn_to_ascii wrapper. * Intl/Idn modules version of this function doesn't work with e-mail address @@ -888,8 +839,7 @@ return self::idn_convert($str, false); } - - public static function idn_convert($input, $is_utf=false) + public static function idn_convert($input, $is_utf = false) { if ($at = strpos($input, '@')) { $user = substr($input, 0, $at); @@ -1138,4 +1088,104 @@ return $url; } + + /** + * Generate a random string + * + * @param int $length String length + * @param bool $raw Return RAW data instead of ascii + * + * @return string The generated random string + */ + public static function random_bytes($length, $raw = false) + { + // Use PHP7 true random generator + if (function_exists('random_bytes')) { + $random = @random_bytes($length); + } + + if (!$random) { + $random = openssl_random_pseudo_bytes($length); + } + + if ($raw) { + return $random; + } + + $random = self::bin2ascii($random); + + // truncate to the specified size... + if ($length < strlen($random)) { + $random = substr($random, 0, $length); + } + + return $random; + } + + /** + * Convert binary data into readable form (containing a-zA-Z0-9 characters) + * + * @param string $input Binary input + * + * @return string Readable output + */ + public static function bin2ascii($input) + { + // Above method returns "hexits". + // Based on bin_to_readable() function in ext/session/session.c. + // Note: removed ",-" characters from hextab + $hextab = "0123456789abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ"; + $nbits = 6; // can be 4, 5 or 6 + $length = strlen($input); + $result = ''; + $char = 0; + $i = 0; + $have = 0; + $mask = (1 << $nbits) - 1; + + while (true) { + if ($have < $nbits) { + if ($i < $length) { + $char |= ord($input[$i++]) << $have; + $have += 8; + } + else if (!$have) { + break; + } + else { + $have = $nbits; + } + } + + // consume nbits + $result .= $hextab[$char & $mask]; + $char >>= $nbits; + $have -= $nbits; + } + + return $result; + } + + /** + * Format current date according to specified format. + * This method supports microseconds (u). + * + * @param string $format Date format (default: 'd-M-Y H:i:s O') + * + * @return string Formatted date + */ + public static function date_format($format = null) + { + if (empty($format)) { + $format = 'd-M-Y H:i:s O'; + } + + if (strpos($format, 'u') !== false + && ($date = date_create_from_format('U.u.e', microtime(true) . '.' . date_default_timezone_get())) + ) { + return $date->format($format); + } + + return date($format); + } } -- Gitblit v1.9.1