| 2159 | |
| 2160 | |
| 2161 | void CUpDownClient::ProcessSignaturePacket(const uint8_t* pachPacket, uint32 nSize) |
| 2162 | { |
| 2163 | // here we spread the good guys from the bad ones ;) |
| 2164 | |
| 2165 | wxCHECK2(m_socket != NULL, return); |
| 2166 | wxCHECK2(credits != NULL, return); |
| 2167 | if (nSize == 0) { |
| 2168 | AddDebugLogLineN(logClient, "Invalid packet size (0)"); |
| 2169 | return; |
| 2170 | } |
| 2171 | if (nSize > 250) { |
| 2172 | AddDebugLogLineN(logClient, CFormat("Invalid packet size (%d > 250)") % nSize); |
| 2173 | return; |
| 2174 | } |
| 2175 | |
| 2176 | uint8 byChaIPKind; |
| 2177 | if (pachPacket[0] == nSize-1) |
| 2178 | byChaIPKind = 0; |
| 2179 | else if (pachPacket[0] == nSize-2 && (m_bySupportSecIdent & 2) > 0) //v2 |
| 2180 | byChaIPKind = pachPacket[nSize-1]; |
| 2181 | else { |
| 2182 | // Unknown or invalid format |
| 2183 | AddDebugLogLineN(logClient, "Invalid or unknown challenge format - ignoring"); |
| 2184 | return; |
| 2185 | } |
| 2186 | |
| 2187 | if (!theApp->CryptoAvailable()) |
| 2188 | return; |
| 2189 | |
| 2190 | // we accept only one signature per IP, to avoid floods which need a lot cpu time for cryptfunctions |
| 2191 | if (m_dwLastSignatureIP == GetIP()){ |
| 2192 | AddDebugLogLineN( logClient, "received multiple signatures from one client" ); |
| 2193 | return; |
| 2194 | } |
| 2195 | // also make sure this client has a public key |
| 2196 | if (credits->GetSecIDKeyLen() == 0){ |
| 2197 | AddDebugLogLineN( logClient, "received signature for client without public key" ); |
| 2198 | return; |
| 2199 | } |
| 2200 | // and one more check: did we ask for a signature and sent a challenge packet? |
| 2201 | if (credits->m_dwCryptRndChallengeFor == 0){ |
| 2202 | AddDebugLogLineN( logClient, "received signature for client with invalid challenge value - User " + GetUserName() ); |
| 2203 | return; |
| 2204 | } |
| 2205 | |
| 2206 | // cppcheck-suppress duplicateBranch |
| 2207 | if (theApp->clientcredits->VerifyIdent(credits, pachPacket+1, pachPacket[0], GetIP(), byChaIPKind ) ) { |
| 2208 | // result is saved in function above |
| 2209 | AddDebugLogLineN( logClient, CFormat( "'%s' has passed the secure identification, V2 State: %i" ) % GetUserName() % byChaIPKind ); |
| 2210 | } else { |
| 2211 | AddDebugLogLineN( logClient, CFormat( "'%s' has failed the secure identification, V2 State: %i" ) % GetUserName() % byChaIPKind ); |
| 2212 | } |
| 2213 | |
| 2214 | m_dwLastSignatureIP = GetIP(); |
| 2215 | } |
| 2216 | |
| 2217 | void CUpDownClient::SendSecIdentStatePacket() |
| 2218 | { |
no test coverage detected