1
# -*- coding: utf-8 -*-
3
# Based on FreeBSD src/lib/libcrypt/crypt.c 1.2
4
# http://www.freebsd.org/cgi/cvsweb.cgi/~checkout~/src/lib/libcrypt/crypt.c?rev=1.2&content-type=text/plain
7
# * "THE BEER-WARE LICENSE" (Revision 42):
8
# * <phk@login.dknet.dk> wrote this file. As long as you retain this notice you
9
# * can do whatever you want with this stuff. If we meet some day, and you think
10
# * this stuff is worth it, you can buy me a beer in return. Poul-Henning Kamp
12
# This port adds no further stipulations. I forfeit any copyright interest.
16
def md5crypt(password, salt, magic='$1$'):
17
# /* The password first, since that is what is most unknown */ /* Then our magic string */ /* Then the raw salt */
19
m.update(password + magic + salt)
21
# /* Then just as many characters of the MD5(pw,salt,pw) */
22
mixin = md5.md5(password + salt + password).digest()
23
for i in range(0, len(password)):
24
m.update(mixin[i % 16])
26
# /* Then something really weird... */
27
# Also really broken, as far as I can tell. -m
38
# /* and now, just to make sure things don't run too fast */
59
# This is the bit that uses to64() in the original code.
61
itoa64 = './0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz'
64
for a, b, c in ((0, 6, 12), (1, 7, 13), (2, 8, 14), (3, 9, 15), (4, 10, 5)):
65
v = ord(final[a]) << 16 | ord(final[b]) << 8 | ord(final[c])
67
rearranged += itoa64[v & 0x3f]; v >>= 6
71
rearranged += itoa64[v & 0x3f]; v >>= 6
73
return magic + salt + '$' + rearranged
75
if __name__ == '__main__':
77
def test(clear_password, the_hash):
78
magic, salt = the_hash[1:].split('$')[:2]
79
magic = '$' + magic + '$'
80
return md5crypt(clear_password, salt, magic) == the_hash
83
(' ', '$1$yiiZbNIH$YiCsHZjcTkYd31wkgW8JF.'),
84
('pass', '$1$YeNsbWdH$wvOF8JdqsoiLix754LTW90'),
85
('____fifteen____', '$1$s9lUWACI$Kk1jtIVVdmT01p0z3b/hw1'),
86
('____sixteen_____', '$1$dL3xbVZI$kkgqhCanLdxODGq14g/tW1'),
87
('____seventeen____', '$1$NaH5na7J$j7y8Iss0hcRbu3kzoJs5V.'),
88
('__________thirty-three___________', '$1$HO7Q6vzJ$yGwp2wbL5D7eOVzOmxpsy.'),
89
('apache', '$apr1$J.w5a/..$IW9y6DR0oO/ADuhlMF5/X1')
92
for clearpw, hashpw in test_cases:
93
if test(clearpw, hashpw):
94
print '%s: pass' % clearpw
96
print '%s: FAIL' % clearpw