removed pycrypto leaving only strxor for speeding up pbkdf2
This commit is contained in:
+6
-14
@@ -40,19 +40,12 @@
|
|||||||
:copyright: (c) Copyright 2011 by Armin Ronacher.
|
:copyright: (c) Copyright 2011 by Armin Ronacher.
|
||||||
:license: BSD, see LICENSE for more details.
|
:license: BSD, see LICENSE for more details.
|
||||||
"""
|
"""
|
||||||
#import hmac
|
import hmac
|
||||||
#import hashlib
|
|
||||||
try:
|
try:
|
||||||
# Use PyCrypto (if available).
|
from hashlib import sha1
|
||||||
from Crypto.Hash import HMAC as hmac, SHA as sha1
|
|
||||||
except ImportError:
|
except ImportError:
|
||||||
# PyCrypto not available. Use the Python standard library.
|
# hashlib not available. Use the old sha module.
|
||||||
import hmac
|
import sha as sha1
|
||||||
try:
|
|
||||||
from hashlib import sha1
|
|
||||||
except ImportError:
|
|
||||||
# hashlib not available. Use the old sha module.
|
|
||||||
import sha as sha1
|
|
||||||
|
|
||||||
from struct import Struct
|
from struct import Struct
|
||||||
from operator import xor
|
from operator import xor
|
||||||
@@ -121,9 +114,8 @@ def test():
|
|||||||
check('pass\x00word', 'sa\x00lt', 4096, 16,
|
check('pass\x00word', 'sa\x00lt', 4096, 16,
|
||||||
'56fa6aa75548099dcc37d7f03425e0c3')
|
'56fa6aa75548099dcc37d7f03425e0c3')
|
||||||
# This one is from the RFC but it just takes for ages
|
# This one is from the RFC but it just takes for ages
|
||||||
##check('password', 'salt', 16777216, 20,
|
check('password', 'salt', 16777216, 20,
|
||||||
## 'eefe3d61cd4da4e4e9945b3d6ba2158c2634e984')
|
'eefe3d61cd4da4e4e9945b3d6ba2158c2634e984')
|
||||||
|
|
||||||
# From Crypt-PBKDF2
|
# From Crypt-PBKDF2
|
||||||
check('password', 'ATHENA.MIT.EDUraeburn', 1, 16,
|
check('password', 'ATHENA.MIT.EDUraeburn', 1, 16,
|
||||||
'cdedb5281bb2f801565a1122b2563515')
|
'cdedb5281bb2f801565a1122b2563515')
|
||||||
|
|||||||
+10
-15
@@ -11,8 +11,8 @@ This file specifically includes utilities for security.
|
|||||||
|
|
||||||
import threading
|
import threading
|
||||||
import struct
|
import struct
|
||||||
import hashlib
|
#import hashlib
|
||||||
import hmac
|
#import hmac
|
||||||
import uuid
|
import uuid
|
||||||
import random
|
import random
|
||||||
import time
|
import time
|
||||||
@@ -23,6 +23,7 @@ import logging
|
|||||||
import socket
|
import socket
|
||||||
import base64
|
import base64
|
||||||
import zlib
|
import zlib
|
||||||
|
from types import ModuleType
|
||||||
|
|
||||||
_struct_2_long_long = struct.Struct('=QQ')
|
_struct_2_long_long = struct.Struct('=QQ')
|
||||||
|
|
||||||
@@ -33,21 +34,15 @@ if python_version == 2:
|
|||||||
else:
|
else:
|
||||||
import pickle
|
import pickle
|
||||||
|
|
||||||
try:
|
from hashlib import md5, sha1, sha224, sha256, sha384, sha512
|
||||||
from Crypto.Hash import MD5 as md5, \
|
|
||||||
SHA as sha1, \
|
|
||||||
SHA224 as sha224, \
|
|
||||||
SHA256 as sha256, \
|
|
||||||
SHA384 as sha384, \
|
|
||||||
SHA512 as sha512
|
|
||||||
except ImportError:
|
|
||||||
from hashlib import md5, sha1, sha224, sha256, sha384, sha512
|
|
||||||
|
|
||||||
try:
|
try:
|
||||||
from Crypto.Cipher import AES
|
from Crypto.Cipher import AES
|
||||||
except ImportError:
|
except ImportError:
|
||||||
import contrib.aes as AES
|
import contrib.aes as AES
|
||||||
|
|
||||||
|
import hmac
|
||||||
|
|
||||||
try:
|
try:
|
||||||
from contrib.pbkdf2 import pbkdf2_hex
|
from contrib.pbkdf2 import pbkdf2_hex
|
||||||
HAVE_PBKDF2 = True
|
HAVE_PBKDF2 = True
|
||||||
@@ -80,7 +75,7 @@ def compare(a, b):
|
|||||||
|
|
||||||
def md5_hash(text):
|
def md5_hash(text):
|
||||||
""" Generate a md5 hash with the given text """
|
""" Generate a md5 hash with the given text """
|
||||||
return md5.new(text).hexdigest()
|
return md5(text).hexdigest()
|
||||||
|
|
||||||
|
|
||||||
def simple_hash(text, key='', salt='', digest_alg='md5'):
|
def simple_hash(text, key='', salt='', digest_alg='md5'):
|
||||||
@@ -100,7 +95,7 @@ def simple_hash(text, key='', salt='', digest_alg='md5'):
|
|||||||
digest_alg = get_digest(digest_alg)
|
digest_alg = get_digest(digest_alg)
|
||||||
h = hmac.new(key + salt, text, digest_alg)
|
h = hmac.new(key + salt, text, digest_alg)
|
||||||
else: # compatible with third party systems
|
else: # compatible with third party systems
|
||||||
h = hashlib.new(digest_alg)
|
h = get_digest(digest_alg)()
|
||||||
h.update(text + salt)
|
h.update(text + salt)
|
||||||
return h.hexdigest()
|
return h.hexdigest()
|
||||||
|
|
||||||
@@ -143,7 +138,7 @@ def pad(s, n=32, padchar=' '):
|
|||||||
|
|
||||||
def secure_dumps(data, encryption_key, hash_key=None, compression_level=None):
|
def secure_dumps(data, encryption_key, hash_key=None, compression_level=None):
|
||||||
if not hash_key:
|
if not hash_key:
|
||||||
hash_key = hashlib.sha1(encryption_key).hexdigest()
|
hash_key = sha1(encryption_key).hexdigest()
|
||||||
dump = pickle.dumps(data)
|
dump = pickle.dumps(data)
|
||||||
if compression_level:
|
if compression_level:
|
||||||
dump = zlib.compress(dump, compression_level)
|
dump = zlib.compress(dump, compression_level)
|
||||||
@@ -158,7 +153,7 @@ def secure_loads(data, encryption_key, hash_key=None, compression_level=None):
|
|||||||
if not ':' in data:
|
if not ':' in data:
|
||||||
return None
|
return None
|
||||||
if not hash_key:
|
if not hash_key:
|
||||||
hash_key = hashlib.sha1(encryption_key).hexdigest()
|
hash_key = sha1(encryption_key).hexdigest()
|
||||||
signature, encrypted_data = data.split(':', 1)
|
signature, encrypted_data = data.split(':', 1)
|
||||||
actual_signature = hmac.new(hash_key, encrypted_data).hexdigest()
|
actual_signature = hmac.new(hash_key, encrypted_data).hexdigest()
|
||||||
if not compare(signature, actual_signature):
|
if not compare(signature, actual_signature):
|
||||||
|
|||||||
Reference in New Issue
Block a user