PluginProbe
ManageWP Worker / 4.9.25
ManageWP Worker v4.9.25
4.9.38 4.9.37 4.9.36 4.9.35 4.9.34 3.8.7 3.8.8 3.9.0 3.9.1 3.9.10 3.9.11 3.9.12 3.9.13 3.9.14 3.9.15 3.9.16 3.9.17 3.9.18 3.9.19 3.9.2 3.9.20 3.9.21 3.9.22 3.9.23 3.9.24 All 73 releases
worker / src / PHPSecLib / Crypt / RC4.php

RC4.php in ManageWP Worker 4.9.25, at src/PHPSecLib/Crypt/RC4.php

339 lines 9.1 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 <?php
2
3 /**
4 * Pure-PHP implementation of RC4.
5 *
6 * Uses mcrypt, if available, and an internal implementation, otherwise.
7 *
8 * PHP versions 4 and 5
9 *
10 * Useful resources are as follows:
11 *
12 * - {@link http://www.mozilla.org/projects/security/pki/nss/draft-kaukonen-cipher-arcfour-03.txt ARCFOUR Algorithm}
13 * - {@link http://en.wikipedia.org/wiki/RC4 - Wikipedia: RC4}
14 *
15 * RC4 is also known as ARCFOUR or ARC4. The reason is elaborated upon at Wikipedia. This class is named RC4 and not
16 * ARCFOUR or ARC4 because RC4 is how it is referred to in the SSH1 specification.
17 *
18 * Here's a short example of how to use this library:
19 * <code>
20 * <?php
21 * include 'Crypt/RC4.php';
22 *
23 * $rc4 = new Crypt_RC4();
24 *
25 * $rc4->setKey('abcdefgh');
26 *
27 * $size = 10 * 1024;
28 * $plaintext = '';
29 * for ($i = 0; $i < $size; $i++) {
30 * $plaintext.= 'a';
31 * }
32 *
33 * echo $rc4->decrypt($rc4->encrypt($plaintext));
34 * ?>
35 * </code>
36 *
37 * LICENSE: Permission is hereby granted, free of charge, to any person obtaining a copy
38 * of this software and associated documentation files (the "Software"), to deal
39 * in the Software without restriction, including without limitation the rights
40 * to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
41 * copies of the Software, and to permit persons to whom the Software is
42 * furnished to do so, subject to the following conditions:
43 *
44 * The above copyright notice and this permission notice shall be included in
45 * all copies or substantial portions of the Software.
46 *
47 * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
48 * IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
49 * FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
50 * AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
51 * LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
52 * OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN
53 * THE SOFTWARE.
54 *
55 * @category Crypt
56 * @package Crypt_RC4
57 * @author Jim Wigginton <terrafrost@php.net>
58 * @copyright MMVII Jim Wigginton
59 * @license http://www.opensource.org/licenses/mit-license.html MIT License
60 * @link http://phpseclib.sourceforge.net
61 */
62
63 /**
64 * Include Crypt_Base
65 *
66 * Base cipher class
67 */
68 if (!class_exists('Crypt_Base')) {
69 require_once dirname(__FILE__).'/Base.php';
70 }
71
72 /**#@+
73 * @access private
74 * @see Crypt_RC4::Crypt_RC4()
75 */
76 /**
77 * Toggles the internal implementation
78 */
79 define('CRYPT_RC4_MODE_INTERNAL', CRYPT_MODE_INTERNAL);
80 /**
81 * Toggles the mcrypt implementation
82 */
83 define('CRYPT_RC4_MODE_MCRYPT', CRYPT_MODE_MCRYPT);
84 /**#@-*/
85
86 /**#@+
87 * @access private
88 * @see Crypt_RC4::_crypt()
89 */
90 define('CRYPT_RC4_ENCRYPT', 0);
91 define('CRYPT_RC4_DECRYPT', 1);
92 /**#@-*/
93
94 /**
95 * Pure-PHP implementation of RC4.
96 *
97 * @package Crypt_RC4
98 * @author Jim Wigginton <terrafrost@php.net>
99 * @access public
100 */
101 class Crypt_RC4 extends Crypt_Base
102 {
103 /**
104 * Block Length of the cipher
105 *
106 * RC4 is a stream cipher
107 * so we the block_size to 0
108 *
109 * @see Crypt_Base::block_size
110 * @var Integer
111 * @access private
112 */
113 public $block_size = 0;
114
115 /**
116 * The default password key_size used by setPassword()
117 *
118 * @see Crypt_Base::password_key_size
119 * @see Crypt_Base::setPassword()
120 * @var Integer
121 * @access private
122 */
123 public $password_key_size = 128; // = 1024 bits
124
125 /**
126 * The namespace used by the cipher for its constants.
127 *
128 * @see Crypt_Base::const_namespace
129 * @var String
130 * @access private
131 */
132 public $const_namespace = 'RC4';
133
134 /**
135 * The mcrypt specific name of the cipher
136 *
137 * @see Crypt_Base::cipher_name_mcrypt
138 * @var String
139 * @access private
140 */
141 public $cipher_name_mcrypt = 'arcfour';
142
143 /**
144 * Holds whether performance-optimized $inline_crypt() can/should be used.
145 *
146 * @see Crypt_Base::inline_crypt
147 * @var mixed
148 * @access private
149 */
150 public $use_inline_crypt = false; // currently not available
151
152 /**
153 * The Key
154 *
155 * @see Crypt_RC4::setKey()
156 * @var String
157 * @access private
158 */
159 public $key = "\0";
160
161 /**
162 * The Key Stream for decryption and encryption
163 *
164 * @see Crypt_RC4::setKey()
165 * @var Array
166 * @access private
167 */
168 public $stream;
169
170 /**
171 * Default Constructor.
172 *
173 * Determines whether or not the mcrypt extension should be used.
174 *
175 * @see Crypt_Base::Crypt_Base()
176 * @return Crypt_RC4
177 * @access public
178 */
179 public function __construct()
180 {
181 parent::__construct(CRYPT_MODE_STREAM);
182 }
183
184 /**
185 * Dummy function.
186 *
187 * Some protocols, such as WEP, prepend an "initialization vector" to the key, effectively creating a new key [1].
188 * If you need to use an initialization vector in this manner, feel free to prepend it to the key, yourself, before
189 * calling setKey().
190 *
191 * [1] WEP's initialization vectors (IV's) are used in a somewhat insecure way. Since, in that protocol,
192 * the IV's are relatively easy to predict, an attack described by
193 * {@link http://www.drizzle.com/~aboba/IEEE/rc4_ksaproc.pdf Scott Fluhrer, Itsik Mantin, and Adi Shamir}
194 * can be used to quickly guess at the rest of the key. The following links elaborate:
195 *
196 * {@link http://www.rsa.com/rsalabs/node.asp?id=2009 http://www.rsa.com/rsalabs/node.asp?id=2009}
197 * {@link http://en.wikipedia.org/wiki/Related_key_attack http://en.wikipedia.org/wiki/Related_key_attack}
198 *
199 * @param String $iv
200 *
201 * @see Crypt_RC4::setKey()
202 * @access public
203 */
204 public function setIV($iv)
205 {
206 }
207
208 /**
209 * Sets the key.
210 *
211 * Keys can be between 1 and 256 bytes long. If they are longer then 256 bytes, the first 256 bytes will
212 * be used. If no key is explicitly set, it'll be assumed to be a single null byte.
213 *
214 * @access public
215 * @see Crypt_Base::setKey()
216 *
217 * @param String $key
218 */
219 public function setKey($key)
220 {
221 parent::setKey(substr($key, 0, 256));
222 }
223
224 /**
225 * Encrypts a message.
226 *
227 * @see Crypt_Base::decrypt()
228 * @see Crypt_RC4::_crypt()
229 * @access public
230 *
231 * @param String $plaintext
232 *
233 * @return String $ciphertext
234 */
235 public function encrypt($plaintext)
236 {
237 if ($this->engine == CRYPT_MODE_MCRYPT) {
238 return parent::encrypt($plaintext);
239 }
240
241 return $this->_crypt($plaintext, CRYPT_RC4_ENCRYPT);
242 }
243
244 /**
245 * Decrypts a message.
246 *
247 * $this->decrypt($this->encrypt($plaintext)) == $this->encrypt($this->encrypt($plaintext)).
248 * At least if the continuous buffer is disabled.
249 *
250 * @see Crypt_Base::encrypt()
251 * @see Crypt_RC4::_crypt()
252 * @access public
253 *
254 * @param String $ciphertext
255 *
256 * @return String $plaintext
257 */
258 public function decrypt($ciphertext)
259 {
260 if ($this->engine == CRYPT_MODE_MCRYPT) {
261 return parent::decrypt($ciphertext);
262 }
263
264 return $this->_crypt($ciphertext, CRYPT_RC4_DECRYPT);
265 }
266
267 /**
268 * Setup the key (expansion)
269 *
270 * @see Crypt_Base::_setupKey()
271 * @access private
272 */
273 public function _setupKey()
274 {
275 $key = $this->key;
276 $keyLength = strlen($key);
277 $keyStream = range(0, 255);
278 $j = 0;
279 for ($i = 0; $i < 256; $i++) {
280 $j = ($j + $keyStream[$i] + ord($key[$i % $keyLength])) & 255;
281 $temp = $keyStream[$i];
282 $keyStream[$i] = $keyStream[$j];
283 $keyStream[$j] = $temp;
284 }
285
286 $this->stream = array();
287 $this->stream[CRYPT_RC4_DECRYPT] = $this->stream[CRYPT_RC4_ENCRYPT] = array(
288 0, // index $i
289 0, // index $j
290 $keyStream,
291 );
292 }
293
294 /**
295 * Encrypts or decrypts a message.
296 *
297 * @see Crypt_RC4::encrypt()
298 * @see Crypt_RC4::decrypt()
299 * @access private
300 *
301 * @param String $text
302 * @param Integer $mode
303 *
304 * @return String $text
305 */
306 public function _crypt($text, $mode)
307 {
308 if ($this->changed) {
309 $this->_setup();
310 $this->changed = false;
311 }
312
313 $stream = &$this->stream[$mode];
314 if ($this->continuousBuffer) {
315 $i = &$stream[0];
316 $j = &$stream[1];
317 $keyStream = &$stream[2];
318 } else {
319 $i = $stream[0];
320 $j = $stream[1];
321 $keyStream = $stream[2];
322 }
323
324 $len = strlen($text);
325 for ($k = 0; $k < $len; ++$k) {
326 $i = ($i + 1) & 255;
327 $ksi = $keyStream[$i];
328 $j = ($j + $ksi) & 255;
329 $ksj = $keyStream[$j];
330
331 $keyStream[$i] = $ksj;
332 $keyStream[$j] = $ksi;
333 $text[$k] = $text[$k] ^ chr($keyStream[($ksj + $ksi) & 255]);
334 }
335
336 return $text;
337 }
338 }
339