var/www/html/janet-photography.de/wp-includes | uid:33
class-phpass.php [X]
<?php
/**
 * Portable PHP password hashing framework.
 * @package phpass
 * @since 2.5.0
 * @version 0.5 / WordPress
 * @link https://www.openwall.com/phpass/
 */

#
# Portable PHP password hashing framework.
#
# Version 0.5.4 / WordPress.
#
# Written by Solar Designer <solar at openwall.com> in 2004-2006 and placed in
# the public domain.  Revised in subsequent years, still public domain.
#
# There's absolutely no warranty.
#
# The homepage URL for this framework is:
#
#	http://www.openwall.com/phpass/
#
# Please be sure to update the Version line if you edit this file in any way.
# It is suggested that you leave the main version number intact, but indicate
# your project name (after the slash) and add your own revision information.
#
# Please do not change the "private" password hashing method implemented in
# here, thereby making your hashes incompatible.  However, if you must, please
# change the hash type identifier (the "$P$") to something different.
#
# Obviously, since this code is in the public domain, the above are not
# requirements (there can be none), but merely suggestions.
#

/**
 * Portable PHP password hashing framework.
 *
 * @package phpass
 * @version 0.5 / WordPress
 * @link https://www.openwall.com/phpass/
 * @since 2.5.0
 */
class PasswordHash {
	var $itoa64;
	var $iteration_count_log2;
	var $portable_hashes;
	var $random_state;

	function __construct($iteration_count_log2, $portable_hashes)
	{
		$this->itoa64 = './0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz';

		if ($iteration_count_log2 < 4 || $iteration_count_log2 > 31) {
			$iteration_count_log2 = 8;
		}
		$this->iteration_count_log2 = $iteration_count_log2;

		$this->portable_hashes = $portable_hashes;

		$this->random_state = microtime();
		if (function_exists('getmypid')) {
			$this->random_state .= getmypid();
		}
	}

	function PasswordHash($iteration_count_log2, $portable_hashes)
	{
		self::__construct($iteration_count_log2, $portable_hashes);
	}

	function get_random_bytes($count)
	{
		$output = '';
		if (@is_readable('/dev/urandom') &&
		    ($fh = @fopen('/dev/urandom', 'rb'))) {
			$output = fread($fh, $count);
			fclose($fh);
		}

		if (strlen($output) < $count) {
			$output = '';
			for ($i = 0; $i < $count; $i += 16) {
				$this->random_state =
				    md5(microtime() . $this->random_state);
				$output .= md5($this->random_state, TRUE);
			}
			$output = substr($output, 0, $count);
		}

		return $output;
	}

	function encode64($input, $count)
	{
		$output = '';
		$i = 0;
		do {
			$value = ord($input[$i++]);
			$output .= $this->itoa64[$value & 0x3f];
			if ($i < $count) {
				$value |= ord($input[$i]) << 8;
			}
			$output .= $this->itoa64[($value >> 6) & 0x3f];
			if ($i++ >= $count) {
				break;
			}
			if ($i < $count) {
				$value |= ord($input[$i]) << 16;
			}
			$output .= $this->itoa64[($value >> 12) & 0x3f];
			if ($i++ >= $count) {
				break;
			}
			$output .= $this->itoa64[($value >> 18) & 0x3f];
		} while ($i < $count);

		return $output;
	}

	function gensalt_private($input)
	{
		$output = '$P$';
		$output .= $this->itoa64[min($this->iteration_count_log2 + 5,
		    30)];
		$output .= $this->encode64($input, 6);

		return $output;
	}

	function crypt_private($password, $setting)
	{
		$output = '*0';
		if (substr($setting, 0, 2) === $output) {
			$output = '*1';
		}

		$id = substr($setting, 0, 3);
		# We use "$P$", phpBB3 uses "$H$" for the same thing
		if ($id !== '$P$' && $id !== '$H$') {
			return $output;
		}

		$count_log2 = strpos($this->itoa64, $setting[3]);
		if ($count_log2 < 7 || $count_log2 > 30) {
			return $output;
		}

		$count = 1 << $count_log2;

		$salt = substr($setting, 4, 8);
		if (strlen($salt) !== 8) {
			return $output;
		}

		# We were kind of forced to use MD5 here since it's the only
		# cryptographic primitive that was available in all versions
		# of PHP in use.  To implement our own low-level crypto in PHP
		# would have resulted in much worse performance and
		# consequently in lower iteration counts and hashes that are
		# quicker to crack (by non-PHP code).
		$hash = md5($salt . $password, TRUE);
		do {
			$hash = md5($hash . $password, TRUE);
		} while (--$count);

		$output = substr($setting, 0, 12);
		$output .= $this->encode64($hash, 16);

		return $output;
	}

	function gensalt_blowfish($input)
	{
		# This one needs to use a different order of characters and a
		# different encoding scheme from the one in encode64() above.
		# We care because the last character in our encoded string will
		# only represent 2 bits.  While two known implementations of
		# bcrypt will happily accept and correct a salt string which
		# has the 4 unused bits set to non-zero, we do not want to take
		# chances and we also do not want to waste an additional byte
		# of entropy.
		$itoa64 = './ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789';

		$output = '$2a$';
		$output .= chr((int)(ord('0') + $this->iteration_count_log2 / 10));
		$output .= chr(ord('0') + $this->iteration_count_log2 % 10);
		$output .= '$';

		$i = 0;
		do {
			$c1 = ord($input[$i++]);
			$output .= $itoa64[$c1 >> 2];
			$c1 = ($c1 & 0x03) << 4;
			if ($i >= 16) {
				$output .= $itoa64[$c1];
				break;
			}

			$c2 = ord($input[$i++]);
			$c1 |= $c2 >> 4;
			$output .= $itoa64[$c1];
			$c1 = ($c2 & 0x0f) << 2;

			$c2 = ord($input[$i++]);
			$c1 |= $c2 >> 6;
			$output .= $itoa64[$c1];
			$output .= $itoa64[$c2 & 0x3f];
		} while (1);

		return $output;
	}

	function HashPassword($password)
	{
		if ( strlen( $password ) > 4096 ) {
			return '*';
		}

		$random = '';

		if (CRYPT_BLOWFISH === 1 && !$this->portable_hashes) {
			$random = $this->get_random_bytes(16);
			$hash =
			    crypt($password, $this->gensalt_blowfish($random));
			if (strlen($hash) === 60) {
				return $hash;
			}
		}

		if (strlen($random) < 6) {
			$random = $this->get_random_bytes(6);
		}
		$hash =
		    $this->crypt_private($password,
		    $this->gensalt_private($random));
		if (strlen($hash) === 34) {
			return $hash;
		}

		# Returning '*' on error is safe here, but would _not_ be safe
		# in a crypt(3)-like function used _both_ for generating new
		# hashes and for validating passwords against existing hashes.
		return '*';
	}

	function CheckPassword($password, $stored_hash)
	{
		if ( strlen( $password ) > 4096 ) {
			return false;
		}

		$hash = $this->crypt_private($password, $stored_hash);
		if ($hash[0] === '*') {
			$hash = crypt($password, $stored_hash);
		}

		# This is not constant-time.  In order to keep the code simple,
		# for timing safety we currently rely on the salts being
		# unpredictable, which they are at least in the non-fallback
		# cases (that is, when we use /dev/urandom and bcrypt).
		return $hash === $stored_hash;
	}
}
abilities-api/-O R D
ai-client/-O R D
assets/-O R D
block-bindings/-O R D
block-patterns/-O R D
block-supports/-O R D
blocks/-O R D
build/-O R D
certificates/-O R D
css/-O R D
customize/-O R D
fonts/-O R D
html-api/-O R D
ID3/-O R D
images/-O R D
interactivity-api/-O R D
IXR/-O R D
js/-O R D
l10n/-O R D
php-ai-client/-O R D
php-compat/-O R D
PHPMailer/-O R D
pomo/-O R D
Requests/-O R D
rest-api/-O R D
SimplePie/-O R D
sitemaps/-O R D
sodium_compat/-O R D
style-engine/-O R D
Text/-O R D
theme-compat/-O R D
widgets/-O R D
.t_hich4V E R D
.test_zjeclv0V E R D
abilities.php7.8KV E R D
admin-bar.php38.4KV E R D
ai-client.php2.5KV E R D
atomlib.php11.9KV E R D
author-template.php19.4KV E R D
block-bindings.php7.3KV E R D
block-i18n.json316V E R D
block-template.php17.8KV E R D
blocks.php116.6KV E R D
bookmark-template.php12.5KV E R D
bookmark.php15.1KV E R D
canonical.php33.8KV E R D
capabilities.php42.6KV E R D
category-template.php55.6KV E R D
category.php12.5KV E R D
class-avif-info.php29.3KV E R D
class-feed.php539V E R D
class-http.php367V E R D
class-phpass.php6.6KV E R D
class-phpmailer.php664V E R D
class-pop3.php20.6KV E R D
class-requests.php2.2KV E R D
class-simplepie.php453V E R D
class-smtp.php457V E R D
class-walker-category-dropdown.php2.4KV E R D
class-walker-category.php8.3KV E R D
class-walker-nav-menu.php11.8KV E R D
class-walker-page-dropdown.php2.6KV E R D
class-walker-page.php7.4KV E R D
class-wp-admin-bar.php17.6KV E R D
class-wp-ajax-response.php5.1KV E R D
class-wp-application-passwords.php16.7KV E R D
class-wp-block-bindings-registry.php8.1KV E R D
class-wp-block-bindings-source.php2.9KV E R D
class-wp-block-editor-context.php1.3KV E R D
class-wp-block-list.php4.6KV E R D
class-wp-block-metadata-registry.php11.6KV E R D
class-wp-block-parser-block.php2.5KV E R D
class-wp-block-parser-frame.php1.9KV E R D
class-wp-block-parser.php11.3KV E R D
class-wp-block-pattern-categories-registry.php4.3KV E R D
class-wp-block-patterns-registry.php10.1KV E R D
class-wp-block-processor.php68.3KV E R D
class-wp-block-styles-registry.php6.3KV E R D
class-wp-block-supports.php6.4KV E R D
class-wp-block-template.php2KV E R D
class-wp-block-templates-registry.php6.9KV E R D
class-wp-block-type-registry.php4.9KV E R D
class-wp-block-type.php16.8KV E R D
class-wp-block.php24.1KV E R D
class-wp-classic-to-block-menu-converter.php3.9KV E R D
class-wp-comment-query.php47.5KV E R D
class-wp-connector-registry.php14.1KV E R D
class-wp-customize-control.php25.5KV E R D
class-wp-customize-manager.php198.1KV E R D
class-wp-customize-nav-menus.php56.6KV E R D
class-wp-customize-panel.php10.5KV E R D
class-wp-customize-section.php10.9KV E R D
class-wp-customize-setting.php29.3KV E R D
class-wp-customize-widgets.php70.9KV E R D
class-wp-date-query.php35.1KV E R D
class-wp-dependencies.php16.7KV E R D
class-wp-duotone.php40KV E R D
class-wp-error.php7.3KV E R D
class-wp-fatal-error-handler.php8KV E R D
class-wp-feed-cache-transient.php3.2KV E R D
class-wp-feed-cache.php969V E R D
class-wp-http-cookie.php7.1KV E R D
class-wp-http-curl.php13KV E R D
class-wp-http-encoding.php3.7KV E R D
class-wp-http-ixr-client.php3.4KV E R D
class-wp-http-proxy.php5.8KV E R D
class-wp-http-requests-hooks.php2KV E R D
class-wp-http-requests-response.php4.1KV E R D
class-wp-http-response.php2.9KV E R D
class-wp-http-streams.php16.4KV E R D
class-wp-icons-registry.php7.7KV E R D
class-wp-image-editor-gd.php20.2KV E R D
class-wp-image-editor-imagick.php36.1KV E R D
class-wp-image-editor.php17KV E R D
class-wp-list-util.php7.3KV E R D
class-wp-locale-switcher.php6.6KV E R D
class-wp-locale.php16.5KV E R D
class-wp-matchesmapregex.php1.8KV E R D
class-wp-meta-query.php29.8KV E R D
class-wp-metadata-lazyloader.php6.7KV E R D
class-wp-navigation-fallback.php9KV E R D
class-wp-network-query.php19.3KV E R D
class-wp-object-cache.php17.1KV E R D
class-wp-oembed-controller.php6.7KV E R D
class-wp-paused-extensions-storage.php4.9KV E R D
class-wp-phpmailer.php4.2KV E R D
class-wp-plugin-dependencies.php24.6KV E R D
class-wp-post-type.php30KV E R D
class-wp-recovery-mode-cookie-service.php6.7KV E R D
class-wp-recovery-mode-email-service.php10.9KV E R D
class-wp-recovery-mode-key-service.php4.8KV E R D
class-wp-recovery-mode-link-service.php3.4KV E R D
class-wp-recovery-mode.php11.2KV E R D
class-wp-rewrite.php62.2KV E R D
class-wp-role.php2.5KV E R D
class-wp-roles.php9.1KV E R D
class-wp-script-modules.php39.6KV E R D
class-wp-scripts.php35.9KV E R D
class-wp-session-tokens.php7.1KV E R D
class-wp-simplepie-file.php3.5KV E R D
class-wp-simplepie-sanitize-kses.php1.9KV E R D
class-wp-site-query.php30.7KV E R D
class-wp-site.php7.3KV E R D
class-wp-speculation-rules.php7.4KV E R D
class-wp-styles.php13KV E R D
class-wp-tax-query.php19.1KV E R D
class-wp-taxonomy.php18.1KV E R D
class-wp-term-query.php39.8KV E R D
class-wp-text-diff-renderer-inline.php979V E R D
class-wp-text-diff-renderer-table.php18.5KV E R D
class-wp-textdomain-registry.php10.2KV E R D
class-wp-theme-json-data.php1.8KV E R D
class-wp-theme-json-resolver.php34.9KV E R D
class-wp-theme-json-schema.php7.2KV E R D
class-wp-theme-json.php169.6KV E R D
class-wp-token-map.php27.9KV E R D
class-wp-url-pattern-prefixer.php4.7KV E R D
class-wp-user-meta-session-tokens.php2.9KV E R D
class-wp-user-query.php43.1KV E R D
class-wp-user-request.php2.3KV E R D
class-wp-widget-factory.php3.3KV E R D
class-wp-xmlrpc-server.php210KV E R D
class.wp-dependencies.php373V E R D
class.wp-scripts.php343V E R D
class.wp-styles.php338V E R D
comment-template.php100.8KV E R D
compat-utf8.php19.1KV E R D
compat.php15.7KV E R D
connectors.php23.5KV E R D
cron.php43.9KV E R D
date.php400V E R D
default-constants.php11.1KV E R D
default-filters.php36.5KV E R D
deprecated.php189.4KV E R D
error-protection.php4KV E R D
feed-atom.php3KV E R D
feed-rdf.php2.6KV E R D
feed-rss.php1.2KV E R D
feed-rss2.php3.7KV E R D
feed.php24.6KV E R D
fonts.php9.6KV E R D
formatting.php346.6KV E R D
functions.wp-scripts.php20KV E R D
functions.wp-styles.php8.5KV E R D
general-template.php170.8KV E R D
global-styles-and-settings.php20.3KV E R D
https-detection.php5.7KV E R D
https-migration.php4.6KV E R D
kses.php81KV E R D
l10n.php69.7KV E R D
link-template.php156.4KV E R D
locale.php162V E R D
media-template.php61.8KV E R D
media.php219.7KV E R D
meta.php65.2KV E R D
ms-blogs.php25.7KV E R D
ms-default-constants.php4.8KV E R D
ms-default-filters.php6.5KV E R D
ms-deprecated.php21.2KV E R D
ms-files.php2.8KV E R D
ms-functions.php89.7KV E R D
ms-load.php19.6KV E R D
ms-settings.php4.1KV E R D
ms-site.php40.8KV E R D
nav-menu-template.php25.4KV E R D
option.php102.6KV E R D
post-formats.php6.9KV E R D
post-thumbnail-template.php10.6KV E R D
post.php289.6KV E R D
registration-functions.php200V E R D
registration.php200V E R D
revision.php30KV E R D
rewrite.php19KV E R D
robots-template.php5.1KV E R D
rss.php22.7KV E R D
script-loader.php159.3KV E R D
script-modules.php11.7KV E R D
sitemaps.php3.2KV E R D
spl-autoload-compat.php441V E R D
style-engine.php7.4KV E R D
taxonomy.php173KV E R D
template-canvas.php544V E R D
template.php36KV E R D
theme-i18n.json1.8KV E R D
theme-templates.php4KV E R D
theme.json8.8KV E R D
update.php37.4KV E R D
user.php174.6KV E R D
utf8.php7.1KV E R D
vars.php6.5KV E R D
version.php1.1KV E R D
view-transitions.php602V E R D
wp-db-repair.php3.7KV E R D
wp-db.php445V E R D
wp-diff.php799V E R D