| 374 | |
| 375 | |
| 376 | bool CClientCreditsList::VerifyIdent(CClientCredits* pTarget, const uint8_t* pachSignature, uint8 nInputSize, uint32 dwForIP, uint8 byChaIPKind) |
| 377 | { |
| 378 | wxASSERT( pTarget ); |
| 379 | wxASSERT( pachSignature ); |
| 380 | if ( !CryptoAvailable() ){ |
| 381 | pTarget->SetIdentState(IS_NOTAVAILABLE); |
| 382 | return false; |
| 383 | } |
| 384 | bool bResult; |
| 385 | try { |
| 386 | CryptoPP::StringSource ss_Pubkey((uint8_t*)pTarget->GetSecureIdent(),pTarget->GetSecIDKeyLen(),true,0); |
| 387 | CryptoPP::RSASSA_PKCS1v15_SHA_Verifier pubkey(ss_Pubkey); |
| 388 | // 4 additional bytes random data send from this client +5 bytes v2 |
| 389 | uint8_t abyBuffer[MAXPUBKEYSIZE+9]; |
| 390 | memcpy(abyBuffer,m_abyMyPublicKey,m_nMyPublicKeyLen); |
| 391 | uint32 challenge = pTarget->m_dwCryptRndChallengeFor; |
| 392 | wxASSERT ( challenge != 0 ); |
| 393 | PokeUInt32(abyBuffer+m_nMyPublicKeyLen, challenge); |
| 394 | |
| 395 | // v2 security improvements (not supported by 29b, not used as default by 29c) |
| 396 | uint8 nChIpSize = 0; |
| 397 | if (byChaIPKind != 0){ |
| 398 | nChIpSize = 5; |
| 399 | uint32 ChallengeIP = 0; |
| 400 | switch (byChaIPKind) { |
| 401 | case CRYPT_CIP_LOCALCLIENT: |
| 402 | ChallengeIP = dwForIP; |
| 403 | break; |
| 404 | case CRYPT_CIP_REMOTECLIENT: |
| 405 | // Ignore local ip... |
| 406 | if (!theApp->GetPublicIP(true)) { |
| 407 | if (::IsLowID(theApp->GetED2KID())){ |
| 408 | AddDebugLogLineN(logCredits, "Warning: Maybe SecureHash Ident fails because LocalIP is unknown"); |
| 409 | // Fallback to local ip... |
| 410 | ChallengeIP = theApp->GetPublicIP(); |
| 411 | } else { |
| 412 | ChallengeIP = theApp->GetED2KID(); |
| 413 | } |
| 414 | } else { |
| 415 | ChallengeIP = theApp->GetPublicIP(); |
| 416 | } |
| 417 | break; |
| 418 | case CRYPT_CIP_NONECLIENT: // maybe not supported in future versions |
| 419 | ChallengeIP = 0; |
| 420 | break; |
| 421 | } |
| 422 | PokeUInt32(abyBuffer+m_nMyPublicKeyLen+4, ChallengeIP); |
| 423 | PokeUInt8(abyBuffer+m_nMyPublicKeyLen+4+4, byChaIPKind); |
| 424 | } |
| 425 | //v2 end |
| 426 | |
| 427 | bResult = pubkey.VerifyMessage(abyBuffer, m_nMyPublicKeyLen+4+nChIpSize, pachSignature, nInputSize); |
| 428 | } catch (const CryptoPP::Exception& e) { |
| 429 | AddDebugLogLineC(logCredits, wxString("Error while verifying identity: ") + wxString(char2unicode(e.what()))); |
| 430 | bResult = false; |
| 431 | } |
| 432 | |
| 433 | if (!bResult){ |
no test coverage detected