version 1.33, 2007/02/21 01:26:07 |
version 1.35, 2007/02/22 04:11:35 |
|
|
package Palm::Keyring; |
package Palm::Keyring; |
# $RedRiver: Keyring.pm,v 1.32 2007/02/19 03:33:56 andrew Exp $ |
# $RedRiver: Keyring.pm,v 1.34 2007/02/21 05:24:14 andrew Exp $ |
######################################################################## |
######################################################################## |
# Keyring.pm *** Perl class for Keyring for Palm OS databases. |
# Keyring.pm *** Perl class for Keyring for Palm OS databases. |
# |
# |
|
|
use warnings; |
use warnings; |
|
|
use Carp; |
use Carp; |
|
$Carp::Verbose = 1; |
|
|
use base qw/ Palm::StdAppInfo /; |
use base qw/ Palm::StdAppInfo /; |
|
|
|
|
my $NULL = chr 0; |
my $NULL = chr 0; |
|
|
my @CRYPTS = ( |
my @CRYPTS = ( |
{ # None |
{ |
|
alias => 'None', |
name => 'None', |
name => 'None', |
keylen => 8, |
keylen => 8, |
blocksize => 1, |
blocksize => 1, |
default_iter => 500, |
default_iter => 500, |
}, |
}, |
{ # DES-EDE3 |
{ |
|
alias => 'DES-EDE3', |
name => 'DES_EDE3', |
name => 'DES_EDE3', |
keylen => 24, |
keylen => 24, |
blocksize => 8, |
blocksize => 8, |
DES_odd_parity => 1, |
DES_odd_parity => 1, |
default_iter => 1000, |
default_iter => 1000, |
}, |
}, |
{ # AES128 |
{ |
|
alias => 'AES128', |
name => 'Rijndael', |
name => 'Rijndael', |
keylen => 16, |
keylen => 16, |
blocksize => 16, |
blocksize => 16, |
default_iter => 100, |
default_iter => 100, |
}, |
}, |
{ # AES256 |
{ |
|
alias => 'AES256', |
name => 'Rijndael', |
name => 'Rijndael', |
keylen => 32, |
keylen => 32, |
blocksize => 16, |
blocksize => 16, |
|
|
return 1; |
return 1; |
} |
} |
|
|
|
# Accessors |
|
|
|
sub crypts |
|
{ |
|
my $crypt = shift; |
|
if ($crypt =~ /\D/) { |
|
foreach my $c (@CRYPTS) { |
|
if ($c->{alias} eq $crypt) { |
|
return $c; |
|
} |
|
} |
|
# didn't find it. |
|
return; |
|
} else { |
|
return $CRYPTS[$crypt]; |
|
} |
|
} |
|
|
# ParseRecord |
# ParseRecord |
|
|
sub ParseRecord |
sub ParseRecord |
|
|
$rec->{name} = $field->{data}; |
$rec->{name} = $field->{data}; |
$rec->{ivec} = $ivec; |
$rec->{ivec} = $ivec; |
$rec->{encrypted} = $encrypted; |
$rec->{encrypted} = $encrypted; |
|
delete $rec->{data}; |
|
|
} else { |
} else { |
die 'Unsupported Version'; |
die 'Unsupported Version'; |
|
|
|
|
my $unpackstr |
my $unpackstr |
= ("C1" x 8) # 8 uint8s in an array for the salt |
= ("C1" x 8) # 8 uint8s in an array for the salt |
. ("S1" x 2) # the iter (uint16) and the cipher (uint16) |
. ("n1" x 2) # the iter (uint16) and the cipher (uint16) |
. ("C1" x 8); # and finally 8 more uint8s for the hash |
. ("C1" x 8); # and finally 8 more uint8s for the hash |
|
|
my (@salt, $iter, $cipher, @hash); |
my (@salt, $iter, $cipher, @hash); |
|
|
|
|
my $packstr |
my $packstr |
= ("C1" x 8) # 8 uint8s in an array for the salt |
= ("C1" x 8) # 8 uint8s in an array for the salt |
. ("S1" x 2) # the iter (uint16) and the cipher (uint16) |
. ("n1" x 2) # the iter (uint16) and the cipher (uint16) |
. ("C1" x 8); # and finally 8 more uint8s for the hash |
. ("C1" x 8); # and finally 8 more uint8s for the hash |
|
|
my @salt = map { hex $_ } $appinfo->{salt} =~ /../gxm; |
my @salt = map { hex $_ } $appinfo->{salt} =~ /../gxm; |
|
|
my $rec = shift; |
my $rec = shift; |
my $data = shift; |
my $data = shift; |
my $pass = shift || $self->{password}; |
my $pass = shift || $self->{password}; |
|
my $ivec = shift; |
|
|
if ( ! $pass && ! $self->{appinfo}->{key}) { |
if ( ! $pass && ! $self->{appinfo}->{key}) { |
croak("password not set!\n"); |
croak("password not set!\n"); |
|
|
$rec->{name} ||= $data->{name}; |
$rec->{name} ||= $data->{name}; |
|
|
} elsif ($self->{version} == 5) { |
} elsif ($self->{version} == 5) { |
my @recs = ($data, $acct); |
my @accts = ($data, $acct); |
my $name; |
|
if ($self->{options}->{v4compatible}) { |
if ($self->{options}->{v4compatible}) { |
$rec->{name} ||= $data->{name}; |
$rec->{name} ||= $data->{name}; |
foreach my $rec (@recs) { |
foreach my $a (@accts) { |
my @fields; |
my @fields; |
foreach my $k (sort keys %{ $rec }) { |
foreach my $k (sort keys %{ $a }) { |
my $field = { |
my $field = { |
label => $k, |
label => $k, |
font => 0, |
font => 0, |
data => $rec->{$k}, |
data => $a->{$k}, |
}; |
}; |
push @fields, $field; |
push @fields, $field; |
} |
} |
$rec = \@fields; |
$a = \@fields; |
} |
} |
} |
} |
|
|
my $ivec; |
|
($encrypted, $ivec) = _encrypt_v5( |
($encrypted, $ivec) = _encrypt_v5( |
@recs, |
@accts, |
$self->{appinfo}->{key}, |
$self->{appinfo}->{key}, |
$self->{appinfo}->{cipher}, |
$self->{appinfo}->{cipher}, |
|
$ivec, |
); |
); |
if ($ivec) { |
if (defined $ivec) { |
$rec->{ivec} = $ivec; |
$rec->{ivec} = $ivec; |
} |
} |
|
|
|
|
|
|
sub _encrypt_v4 |
sub _encrypt_v4 |
{ |
{ |
require Crypt::CBC; |
|
|
|
my $new = shift; |
my $new = shift; |
my $old = shift; |
my $old = shift; |
my $digest = shift; |
my $digest = shift; |
|
|
my $old = shift; |
my $old = shift; |
my $key = shift; |
my $key = shift; |
my $cipher = shift; |
my $cipher = shift; |
my $length = $CRYPTS[ $cipher ]{blocksize}; |
my $ivec = shift; |
my $ivec = shift || pack("C*",map {rand(256)} 1..$length); |
my $blocksize = $CRYPTS[ $cipher ]{blocksize}; |
|
|
my $keylen = $CRYPTS[ $cipher ]{keylen}; |
my $keylen = $CRYPTS[ $cipher ]{keylen}; |
my $cipher_name = $CRYPTS[ $cipher ]{name}; |
my $cipher_name = $CRYPTS[ $cipher ]{name}; |
|
|
|
if (! defined $ivec) { |
|
$ivec = pack("C*",map {rand(256)} 1..$blocksize); |
|
} |
|
|
my $changed = 0; |
my $changed = 0; |
my $need_newdate = 1; |
my $need_newdate = 1; |
my $date_index; |
my $date_index; |
|
|
foreach my $field (@{ $new }) { |
foreach my $field (@{ $new }) { |
$decrypted .= _pack_field($field); |
$decrypted .= _pack_field($field); |
} |
} |
|
|
my $encrypted; |
my $encrypted; |
if ($cipher_name eq 'None') { |
if ($cipher_name eq 'None') { |
# do nothing |
# do nothing |
$encrypted = $decrypted; |
$encrypted = $decrypted; |
|
|
} elsif ($cipher_name eq 'DES_EDE3' or $cipher_name eq 'Rijndael') { |
} elsif ($cipher_name eq 'DES_EDE3' or $cipher_name eq 'Rijndael') { |
|
require Crypt::CBC; |
my $c = Crypt::CBC->new( |
my $c = Crypt::CBC->new( |
-literal_key => 1, |
|
-key => $key, |
-key => $key, |
|
-literal_key => 1, |
-iv => $ivec, |
-iv => $ivec, |
-cipher => $cipher_name, |
-cipher => $cipher_name, |
-keysize => $keylen, |
-keysize => $keylen, |
|
-blocksize => $blocksize, |
-header => 'none', |
-header => 'none', |
-padding => 'oneandzeroes', |
-padding => 'oneandzeroes', |
); |
); |
|
|
|
|
sub _decrypt_v5 |
sub _decrypt_v5 |
{ |
{ |
require Crypt::CBC; |
|
my $encrypted = shift; |
my $encrypted = shift; |
my $key = shift; |
my $key = shift; |
my $cipher = shift; |
my $cipher = shift; |
|
|
|
|
my $keylen = $CRYPTS[ $cipher ]{keylen}; |
my $keylen = $CRYPTS[ $cipher ]{keylen}; |
my $cipher_name = $CRYPTS[ $cipher ]{name}; |
my $cipher_name = $CRYPTS[ $cipher ]{name}; |
|
my $blocksize = $CRYPTS[ $cipher ]{blocksize}; |
|
|
my $decrypted; |
my $decrypted; |
|
|
|
|
$decrypted = $encrypted; |
$decrypted = $encrypted; |
|
|
} elsif ($cipher_name eq 'DES_EDE3' or $cipher_name eq 'Rijndael') { |
} elsif ($cipher_name eq 'DES_EDE3' or $cipher_name eq 'Rijndael') { |
|
require Crypt::CBC; |
my $c = Crypt::CBC->new( |
my $c = Crypt::CBC->new( |
-literal_key => 1, |
|
-key => $key, |
-key => $key, |
|
-literal_key => 1, |
-iv => $ivec, |
-iv => $ivec, |
-cipher => $cipher_name, |
-cipher => $cipher_name, |
-keysize => $keylen, |
-keysize => $keylen, |
|
-blocksize => $blocksize, |
-header => 'none', |
-header => 'none', |
-padding => 'oneandzeroes', |
-padding => 'oneandzeroes', |
); |
); |
|
|
if (! $c) { |
if (! $c) { |
croak("Unable to set up encryption!"); |
croak("Unable to set up encryption!"); |
} |
} |
$encrypted .= $NULL x $keylen; # pad out a keylen |
my $len = $blocksize - length($encrypted) % $blocksize; |
|
$encrypted .= $NULL x $len; |
$decrypted = $c->decrypt($encrypted); |
$decrypted = $c->decrypt($encrypted); |
|
|
} else { |
} else { |
|
|
} |
} |
} |
} |
} elsif ($self->{version} == 5) { |
} elsif ($self->{version} == 5) { |
return _password_verify_v5($pass, $self->{appinfo}); |
return _password_verify_v5($self->{appinfo}, $pass); |
} else { |
} else { |
# XXX unsupported version |
# XXX unsupported version |
} |
} |
|
|
|
|
sub _password_verify_v5 |
sub _password_verify_v5 |
{ |
{ |
my $pass = shift; |
|
my $appinfo = shift; |
my $appinfo = shift; |
|
my $pass = shift; |
|
|
my $salt = pack("H*", $appinfo->{salt}); |
my $salt = pack("H*", $appinfo->{salt}); |
|
|
|
|
$CRYPTS[ $appinfo->{cipher} ]{DES_odd_parity}, |
$CRYPTS[ $appinfo->{cipher} ]{DES_odd_parity}, |
); |
); |
|
|
|
#print "Iter: '" . $appinfo->{iter} . "'\n"; |
#print "Key: '". unpack("H*", $key) . "'\n"; |
#print "Key: '". unpack("H*", $key) . "'\n"; |
|
#print "Salt: '". unpack("H*", $salt) . "'\n"; |
#print "Hash: '". $hash . "'\n"; |
#print "Hash: '". $hash . "'\n"; |
#print "Hash: '". $appinfo->{masterhash} . "'\n"; |
#print "Hash: '". $appinfo->{masterhash} . "'\n"; |
|
|
|
|
return $key; |
return $key; |
} |
} |
|
|
|
# Helpers |
|
|
sub _calc_keys |
sub _calc_keys |
{ |
{ |
|
|
$labels[3] = 'lastchange'; |
$labels[3] = 'lastchange'; |
$labels[255] = 'notes'; |
$labels[255] = 'notes'; |
|
|
my ($len) = unpack "S1", $field; |
my ($len) = unpack "n1", $field; |
if ($len + 4 > length $field) { |
if ($len + 4 > length $field) { |
return undef, $field; |
return undef, $field; |
} |
} |
my $unpackstr = "S1 C1 C1 A$len"; |
my $unpackstr = "x2 C1 C1 A$len"; |
if ($len % 2 && $len + 4 < length $field) { |
my $offset = 2 +1 +1 +$len; |
|
if ($len % 2) { # && $len + 4 < length $field) { |
# trim the 0/1 byte padding for next even address. |
# trim the 0/1 byte padding for next even address. |
|
$offset++; |
$unpackstr .= ' x' |
$unpackstr .= ' x' |
} |
} |
$unpackstr .= ' A*'; |
|
|
|
my (undef, $label, $font, $data, $leftover) |
my ($label, $font, $data) = unpack $unpackstr, $field; |
= unpack $unpackstr, $field; |
my $leftover = substr $field, $offset; |
|
|
if ($label == 3) { |
if ($label == 3) { |
$data = _parse_keyring_date($data); |
$data = _parse_keyring_date($data); |
|
|
$data = _pack_keyring_date($data); |
$data = _pack_keyring_date($data); |
} |
} |
my $len = length $data; |
my $len = length $data; |
my $packstr = "S1 C1 C1 A*"; |
my $packstr = "n1 C1 C1 A*"; |
|
|
my $packed = pack $packstr, ($len, $label, $font, $data); |
my $packed = pack $packstr, ($len, $label, $font, $data); |
|
|
|
|
|
|
=back |
=back |
|
|
|
=head2 crypt |
|
|
|
Pass in the alias of the crypt to use, or the index. |
|
|
|
This is a function, not a method. |
|
|
|
my $c = Palm::Keyring::crypt($cipher); |
|
|
|
$c is now: |
|
|
|
$c = { |
|
alias => (None|DES_EDE3|AES128|AES256), |
|
name => (None|DES_EDE3|Rijndael), |
|
keylen => <key length of the ciphe>, |
|
blocksize => <block size of the cipher>, |
|
default_iter => <default iterations for the cipher>, |
|
}; |
|
|
|
|
=head2 Encrypt |
=head2 Encrypt |
|
|
$pdb->Encrypt($rec, $acct[, $password]); |
$pdb->Encrypt($rec, $acct[, $password[, $ivec]]); |
|
|
Encrypts an account into a record, either with the password previously |
Encrypts an account into a record, either with the password previously |
used, or with a password that is passed. |
used, or with a password that is passed. |
|
|
|
$ivec is the initialization vector to use to encrypt the record. This is |
|
not used by v4 databases. Normally this is not passed and is generated |
|
randomly. |
|
|
$rec is a record from $pdb->{records} or a new_Record(). |
$rec is a record from $pdb->{records} or a new_Record(). |
The v4 $acct is a hashref in the format below. |
The v4 $acct is a hashref in the format below. |