/* Licensed to the Apache Software Foundation (ASF) under one or more *contributorlicenseagreements.SeetheNOTICEfiledistributedwith *thisworkforadditionalinformationregardingcopyrightownership. *TheASFlicensesthisfiletoYouundertheApacheLicense,Version2.0 *(the"License");youmaynotusethisfileexceptincompliancewith *theLicense.YoumayobtainacopyoftheLicenseat * *http://www.apache.org/licenses/LICENSE-2.0 * *Unlessrequiredbyapplicablelaworagreedtoinwriting,software *distributedundertheLicenseisdistributedonan"ASIS"BASIS, *WITHOUTWARRANTIESORCONDITIONSOFANYKIND,eitherexpressorimplied. *SeetheLicenseforthespecificlanguagegoverningpermissionsand *limitationsundertheLicense.
*/
ret = mkhash(ctx); if (ret) {
ctx->out = NULL;
ctx->out_len = 0; return ret;
}
ctx->out = apr_pstrcat(ctx->pool, user, ":", hash_str, NL, NULL);
ctx->out_len = strlen(ctx->out); if (ctx->out_len >= MAX_STRING_LEN) {
ctx->errstr = "resultant record too long"; return ERR_OVERFLOW;
} return0;
}
staticvoid usage(void)
{
apr_file_printf(errfile, "Usage:" NL "\thtpasswd [-cimB25dpsDv] [-C cost] [-r rounds] passwordfile username" NL "\thtpasswd -b[cmB25dpsDv] [-C cost] [-r rounds] passwordfile username password" NL
NL "\thtpasswd -n[imB25dps] [-C cost] [-r rounds] username" NL "\thtpasswd -nb[mB25dps] [-C cost] [-r rounds] username password" NL " -c Create a new file." NL " -n Don't update file; display results on stdout." NL " -b Use the password from the command line rather than prompting " "for it." NL " -i Read password from stdin without verification (for script usage)." NL " -m Force MD5 hashing of the password (default)." NL " -2 Force SHA-256 hashing of the password (secure)." NL " -5 Force SHA-512 hashing of the password (secure)." NL " -B Force bcrypt hashing of the password (very secure)." NL " -C Set the computing time used for the bcrypt algorithm" NL " (higher is more secure but slower, default: %d, valid: 4 to 17)." NL " -r Set the number of rounds used for the SHA-256, SHA-512 algorithms" NL " (higher is more secure but slower, default: 5000)." NL " -d Force CRYPT hashing of the password (8 chars max, insecure)." NL " -s Force SHA-1 hashing of the password (insecure)." NL " -p Do not hash the password (plaintext, insecure)." NL " -D Delete the specified user." NL " -v Verify password for the specified user." NL "On other systems than Windows and NetWare the '-p' flag will " "probably not work." NL "The SHA-1 algorithm does not use a salt and is less secure than the " "MD5 algorithm." NL,
BCRYPT_DEFAULT_COST
); exit(ERR_SYNTAX);
}
if ((*mask) & (*mask - 1)) { /* not a power of two, i.e. more than one flag specified */
apr_file_printf(errfile, "%s: only one of -c -n -v -D may be specified" NL,
argv[0]); exit(ERR_SYNTAX);
} if ((*mask & APHTP_VERIFY) && ctx->passwd_src == PW_PROMPT)
ctx->passwd_src = PW_PROMPT_VERIFY;
/* *Makesurewestillhaveexactlytherightnumberofargumentsleft *(thefilename,theusername,andpossiblythepasswordif-bwas *specified).
*/
i = state->ind; if ((argc - i) != args_left) {
usage();
}
if (!(*mask & APHTP_NOFILE)) { if (strlen(argv[i]) > (APR_PATH_MAX - 1)) {
apr_file_printf(errfile, "%s: filename too long" NL, argv[0]); exit(ERR_OVERFLOW);
}
*pwfilename = apr_pstrdup(pool, argv[i++]);
} if (strlen(argv[i]) > (MAX_STRING_LEN - 1)) {
apr_file_printf(errfile, "%s: username too long (> %d)" NL,
argv[0], MAX_STRING_LEN - 1); exit(ERR_OVERFLOW);
}
*user = apr_pstrdup(pool, argv[i++]); if ((arg = strchr(*user, ':')) != NULL) {
apr_file_printf(errfile, "%s: username contains illegal " "character '%c'" NL, argv[0], *arg); exit(ERR_BADUSER);
} if (ctx->passwd_src == PW_ARG) { if (strlen(argv[i]) > (MAX_STRING_LEN - 1)) {
apr_file_printf(errfile, "%s: password too long (> %d)" NL,
argv[0], MAX_STRING_LEN); exit(ERR_OVERFLOW);
}
ctx->passwd = apr_pstrdup(pool, argv[i]);
}
}
strcpy(cp, line);
scratch = cp; while (apr_isspace(*scratch)) {
++scratch;
}
if (!*scratch || (*scratch == '#')) {
putline(ftemp, line); continue;
} /* *Seeifthisisouruser.
*/
colon = strchr(scratch, ':'); if (colon != NULL) {
*colon = '\0';
} else { /* *Ifwe'venotgotacolonontheline,thiscouldwell *notbeavalidhtpasswdfile. *Weshouldbailatthispoint.
*/
apr_file_printf(errfile, "%s: The file %s does not appear " "to be a valid htpasswd file." NL,
argv[0], pwfilename);
apr_file_close(fpw); exit(ERR_INVALID);
} if (strcmp(user, scratch) != 0) {
putline(ftemp, line); continue;
} else { /* We found the user we were looking for */
found++; if ((mask & APHTP_DELUSER)) { /* Delete entry from the file */
apr_file_printf(errfile, "Deleting ");
} elseif ((mask & APHTP_VERIFY)) { /* Verify */ char *hash = colon + 1;
size_t len;
len = strcspn(hash, "\r\n"); if (len == 0) {
apr_file_printf(errfile, "Empty hash for user %s" NL,
user); exit(ERR_INVALID);
}
hash[len] = '\0';
i = verify(&ctx, hash); if (i != 0) {
apr_file_printf(errfile, "%s" NL, ctx.errstr); exit(i);
}
} else { /* Update entry */
apr_file_printf(errfile, "Updating ");
putline(ftemp, ctx.out);
}
}
}
apr_file_close(fpw);
} if (!found) { if (mask & APHTP_DELUSER) {
apr_file_printf(errfile, "User %s not found" NL, user); exit(0);
} elseif (mask & APHTP_VERIFY) {
apr_file_printf(errfile, "User %s not found" NL, user); exit(ERR_BADUSER);
} else {
apr_file_printf(errfile, "Adding ");
putline(ftemp, ctx.out);
}
} if (mask & APHTP_VERIFY) {
apr_file_printf(errfile, "Password for user %s correct." NL, user); exit(0);
}
apr_file_printf(errfile, "password for user %s" NL, user);
/* The temporary file has all the data, just copy it to the new location.
*/ if (apr_file_copy(dirname, pwfilename, APR_OS_DEFAULT, pool) !=
APR_SUCCESS) {
apr_file_printf(errfile, "%s: unable to update file %s" NL,
argv[0], pwfilename); exit(ERR_FILEPERM);
}
apr_file_close(ftemp); return0;
}
Messung V0.5 in Prozent
¤ Dauer der Verarbeitung: 0.12 Sekunden
(vorverarbeitet am 2026-09-29)
¤
Die Informationen auf dieser Webseite wurden
nach bestem Wissen sorgfältig zusammengestellt. Es wird jedoch weder Vollständigkeit, noch Richtigkeit,
noch Qualität der bereit gestellten Informationen zugesichert.
Bemerkung:
Die farbliche Syntaxdarstellung und die Messung sind noch experimentell.