§
    HŠtjœ?  ã                   ó0  — d Z ddlmZmZ ddlmZ ddlZ ej        e¦  «        Z	ddl
mZ ddlmZmZmZmZ ddlmZ ddlmZmZmZmZmZmZ ddlmc mZ g d	¢Zd
Z G d„ dej         ej!        ¦  «        Z" G d„ de"¦  «        Z# G d„ dej$        ¦  «        Z%dS )z1
passlib.handlers.cisco -- Cisco password hashes
é    )ÚhexlifyÚ	unhexlify)Úmd5N)Úwarn)Úright_pad_stringÚ
to_unicodeÚrepeat_stringÚto_bytes)Úh64)ÚunicodeÚuÚjoin_byte_valuesÚjoin_byte_elemsÚiter_byte_valuesÚuascii_to_str)Ú	cisco_pixÚ	cisco_asaÚcisco_type7s    ÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿc                   ó>   — e Zd ZdZd ZdZdZdZdZe	j
        ZdZd„ ZdS )r   aš  
    This class implements the password hash used by older Cisco PIX firewalls,
    and follows the :ref:`password-hash-api`.
    It does a single round of hashing, and relies on the username
    as the salt.

    This class only allows passwords <= 16 bytes, anything larger
    will result in a :exc:`~passlib.exc.PasswordSizeError` if passed to :meth:`~cisco_pix.hash`,
    and be silently rejected if passed to :meth:`~cisco_pix.verify`.

    The :meth:`~passlib.ifc.PasswordHash.hash`,
    :meth:`~passlib.ifc.PasswordHash.genhash`, and
    :meth:`~passlib.ifc.PasswordHash.verify` methods
    all support the following extra keyword:

    :param str user:
        String containing name of user account this password is associated with.

        This is *required* in order to correctly hash passwords associated
        with a user account on the Cisco device, as it is used to salt
        the hash.

        Conversely, this *must* be omitted or set to ``""`` in order to correctly
        hash passwords which don't have an associated user account
        (such as the "enable" password).

    .. versionadded:: 1.6

    .. versionchanged:: 1.7.1

        Passwords > 16 bytes are now rejected / throw error instead of being silently truncated,
        to match Cisco behavior.  A number of :ref:`bugs <passlib-asa96-bug>` were fixed
        which caused prior releases to generate unverifiable hashes in certain cases.
    é   TFc                 ó  — | j         }t          |t          ¦  «        r|                     d¦  «        }d}t	          |¦  «        | j        k    rH| j        r7d| j        | j        fz  }t          j	         
                    | j        |¬¦  «        ‚|t          z   }| j        }|rRt          |t          ¦  «        r|                     d¦  «        }|rt	          |¦  «        dk     r|t          |d¦  «        z  }|rt	          |¦  «        dk    rd}nd}t          ||¦  «        }|r||z  }t          |¦  «                             ¦   «         }t#          d	„ t%          |¦  «        D ¦   «         ¦  «        }t'          j        |¦  «                             d
¦  «        S )a7  
        This function implements the "encrypted" hash format used by Cisco
        PIX & ASA. It's behavior has been confirmed for ASA 9.6,
        but is presumed correct for PIX & other ASA releases,
        as it fits with known test vectors, and existing literature.

        While nearly the same, the PIX & ASA hashes have slight differences,
        so this function performs differently based on the _is_asa class flag.
        Noteable changes from PIX to ASA include password size limit
        increased from 16 -> 32, and other internal changes.
        úutf-8Nz.Password too long (%s allows at most %d bytes))Úmsgé   é   r   é    c              3   ó0   K  — | ]\  }}|d z   dz  ¯|V — ŒdS )é   é   N© )Ú.0ÚiÚcs      úT/var/www/html/CA-Chatbot/venv/lib/python3.11/site-packages/passlib/handlers/cisco.pyú	<genexpr>z+cisco_pix._calc_checksum.<locals>.<genexpr>Þ   s3   è è € Ð PÐ P¡t q¨!ÀQÈÁUÈaÁKÐ P Ð PÐ PÐ PÐ PÐ PÐ Pó    Úascii)Ú_is_asaÚ
isinstancer   ÚencodeÚlenÚtruncate_sizeÚuse_defaultsÚnameÚuhÚexcÚPasswordSizeErrorÚ_DUMMY_BYTESÚuserr	   r   r   Údigestr   Ú	enumerater   Úencode_bytesÚdecode)ÚselfÚsecretÚasaÚspoil_digestr   r3   Úpad_sizer4   s           r$   Ú_calc_checksumzcisco_pix._calc_checksumg   sž  € ð Œlˆõ �f�gÑ&Ô&ð 	,Ø—]’] 7Ñ+Ô+ˆFð, ˆÝˆv‰;Œ;˜Ô+Ò+Ð+ØÔ ð 5àFØ”y $Ô"4Ð5ñ6�å”f×.Ò.¨tÔ/AÀsÐ.ÑKÔKÐKð  &­Ñ4�ð. ŒyˆØð 	1Ý˜$¥Ñ(Ô(ð ,Ø—{’{ 7Ñ+Ô+�Øð 1�#˜f™+œ+¨Ò*Ð*Ø�-¨¨aÑ0Ô0Ñ0�ð ð 	•3�v‘;”; Ò#Ð#ØˆHˆHàˆHÝ! &¨(Ñ3Ô3ˆð
 ð 	#à�lÑ"ˆFÝ�V‘”×#Ò#Ñ%Ô%ˆõ !Ð PÐ P­y¸Ñ/@Ô/@Ð PÑ PÔ PÑPÔPˆõ
 Ô Ñ'Ô'×.Ò.¨wÑ7Ô7Ð7r&   N)Ú__name__Ú
__module__Ú__qualname__Ú__doc__r.   r,   Útruncate_errorÚtruncate_verify_rejectÚchecksum_sizer/   ÚHASH64_CHARSÚchecksum_charsr(   r=   r    r&   r$   r   r   $   sa   € € € € € ð!ð !ðR €Dà€Mð €NØ!Ðð
 €MØ”_€Nð €Gð
|8ð |8ð |8ð |8ð |8r&   r   c                   ó   — e Zd ZdZd ZdZdZdS )r   aä  
    This class implements the password hash used by Cisco ASA/PIX 7.0 and newer (2005).
    Aside from a different internal algorithm, it's use and format is identical
    to the older :class:`cisco_pix` class.

    For passwords less than 13 characters, this should be identical to :class:`!cisco_pix`,
    but will generate a different hash for most larger inputs
    (See the `Format & Algorithm`_ section for the details).

    This class only allows passwords <= 32 bytes, anything larger
    will result in a :exc:`~passlib.exc.PasswordSizeError` if passed to :meth:`~cisco_asa.hash`,
    and be silently rejected if passed to :meth:`~cisco_asa.verify`.

    .. versionadded:: 1.7

    .. versionchanged:: 1.7.1

        Passwords > 32 bytes are now rejected / throw error instead of being silently truncated,
        to match Cisco behavior.  A number of :ref:`bugs <passlib-asa96-bug>` were fixed
        which caused prior releases to generate unverifiable hashes in certain cases.
    r   TN)r>   r?   r@   rA   r.   r,   r(   r    r&   r$   r   r   ù   s-   € € € € € ðð ð8 €Dð
 €Mð
 €G€G€Gr&   r   c                   óò   ‡ — e Zd ZdZd ZdZej        ZdZ	dZ
edˆ fd„	¦   «         Zed„ ¦   «         Zdˆ fd„	Zedd
„¦   «         Zed„ ¦   «         Zd„ Zd„ Zedd„¦   «         Z ed¦  «        Zed„ ¦   «         Zˆ xZS )r   a+  
    This class implements the "Type 7" password encoding used by Cisco IOS,
    and follows the :ref:`password-hash-api`.
    It has a simple 4-5 bit salt, but is nonetheless a reversible encoding
    instead of a real hash.

    The :meth:`~passlib.ifc.PasswordHash.using` method accepts the following optional keywords:

    :type salt: int
    :param salt:
        This may be an optional salt integer drawn from ``range(0,16)``.
        If omitted, one will be chosen at random.

    :type relaxed: bool
    :param relaxed:
        By default, providing an invalid value for one of the other
        keywords will result in a :exc:`ValueError`. If ``relaxed=True``,
        and the error can be corrected, a :exc:`~passlib.exc.PasslibHashWarning`
        will be issued instead. Correctable errors include
        ``salt`` values that are out of range.

    Note that while this class outputs digests in upper-case hexadecimal,
    it will accept lower-case as well.

    This class also provides the following additional method:

    .. automethod:: decode
    ©Úsaltr   é4   Nc                 óÐ   •‡—  t          t          | ¦  «        j        di |¤Ž}‰�A|                     ‰|                     d¦  «        ¬¦  «        Št          ˆfd„¦  «        |_        |S )NÚrelaxed)rM   c                  ó   •— ‰ S ©Nr    rI   s   €r$   ú<lambda>z#cisco_type7.using.<locals>.<lambda>f  s   ø€ ¸€ r&   r    )Úsuperr   ÚusingÚ
_norm_saltÚgetÚstaticmethodÚ_generate_salt)ÚclsrJ   ÚkwdsÚsubclsÚ	__class__s    `  €r$   rR   zcisco_type7.usinga  sk   øø€ à.••{ CÑ(Ô(Ô.Ð6Ð6°Ð6Ð6ˆØÐØ×$Ò$ T°4·8²8¸IÑ3FÔ3FÐ$ÑGÔGˆDÝ$0°°°°Ñ$>Ô$>ˆFÔ!Øˆr&   c                 ó  — t          |dd¦  «        }t          |¦  «        dk     rt          j                             | ¦  «        ‚t          |d d…         ¦  «        } | ||dd …                              ¦   «         ¬¦  «        S )Nr'   Úhashé   )rJ   Úchecksum)r   r+   r/   r0   ÚInvalidHashErrorÚintÚupper)rW   r\   rJ   s      r$   Úfrom_stringzcisco_type7.from_stringi  sr   € å˜$ ¨Ñ0Ô0ˆÝˆt‰9Œ9�qŠ=ˆ=Ý”&×)Ò)¨#Ñ.Ô.Ð.Ý�4˜˜˜”8‰}Œ}ˆØˆs˜ t¨A¨B¨B¤x§~¢~Ñ'7Ô'7Ð8Ñ8Ô8Ð8r&   c                 ó(  •—  t          t          | ¦  «        j        di |¤Ž |�|                      |¦  «        }nQ| j        r;|                      ¦   «         }|                      |¦  «        |k    sJ d|›�¦   «         ‚nt          d¦  «        ‚|| _        d S )Nzgenerated invalid salt: zno salt specifiedr    )rQ   r   Ú__init__rS   r-   rV   Ú	TypeErrorrJ   )r8   rJ   rX   rZ   s      €r$   rd   zcisco_type7.__init__q  s§   ø€ Ø)��k˜4Ñ Ô Ô)Ð1Ð1¨DÐ1Ð1Ð1ØÐØ—?’? 4Ñ(Ô(ˆDˆDØÔð 	1Ø×&Ò&Ñ(Ô(ˆDØ—?’? 4Ñ(Ô(¨DÒ0Ð0Ð0Ð0ÐRVÐRVÐ2XÑ0Ô0Ð0Ð0åÐ/Ñ0Ô0Ð0ØˆŒ	ˆ	ˆ	r&   Fc                 ó  — t          |t          ¦  «        s!t          j                             |dd¦  «        ‚d|cxk    r| j        k    rn n|S d}|r)t          |t          j        ¦  «         |dk     rdn| j        S t          |¦  «        ‚)z�
        validate & normalize salt value.
        .. note::
            the salt for this algorithm is an integer 0-52, not a string
        ÚintegerrJ   r   z"salt/offset must be in 0..52 range)	r)   r`   r/   r0   ÚExpectedTypeErrorÚmax_salt_valuer   ÚPasslibHashWarningÚ
ValueError)rW   rJ   rM   r   s       r$   rS   zcisco_type7._norm_salt|  sœ   € õ ˜$¥Ñ$Ô$ð 	DÝ”&×*Ò*¨4°¸FÑCÔCÐCØ�Ð*Ð*Ò*Ð*˜Ô*Ò*Ð*Ð*Ð*Ð*ØˆKØ2ˆØð 	"Ý�•bÔ+Ñ,Ô,Ð,Ø˜qš˜�1�1 cÔ&8Ð8å˜S‘/”/Ð!r&   c                  óB   — t           j                             dd¦  «        S )Nr   é   )r/   ÚrngÚrandintr    r&   r$   rV   zcisco_type7._generate_saltŽ  s   € åŒv�~Š~˜a Ñ$Ô$Ð$r&   c                 ó>   — d| j         t          | j        ¦  «        fz  S )Nz%02d%s)rJ   r   r^   )r8   s    r$   Ú	to_stringzcisco_type7.to_string’  s   € Ø˜4œ9¥m°D´MÑ&BÔ&BÐCÑCÐCr&   c                 óð   — t          |t          ¦  «        r|                     d¦  «        }t          |                      || j        ¦  «        ¦  «                             d¦  «                             ¦   «         S )Nr   r'   )r)   r   r*   r   Ú_cipherrJ   r7   ra   )r8   r9   s     r$   r=   zcisco_type7._calc_checksum•  s_   € õ �f�gÑ&Ô&ð 	,Ø—]’] 7Ñ+Ô+ˆFÝ�t—|’| F¨D¬IÑ6Ô6Ñ7Ô7×>Ò>¸wÑGÔG×MÒMÑOÔOÐOr&   r   c                 óâ   — |                       |¦  «        }t          |j                             d¦  «        ¦  «        }|                     ||j        ¦  «        }|r|                     |¦  «        n|S )zÈdecode hash, returning original password.

        :arg hash: encoded password
        :param encoding: optional encoding to use (defaults to ``UTF-8``).
        :returns: password as unicode
        r'   )rb   r   r^   r*   rs   rJ   r7   )rW   r\   Úencodingr8   ÚtmpÚraws         r$   r7   zcisco_type7.decodeœ  sc   € ð �Š˜tÑ$Ô$ˆÝ˜œ×,Ò,¨WÑ5Ô5Ñ6Ô6ˆØ�lŠl˜3 ¤	Ñ*Ô*ˆØ'/Ð8ˆs�zŠz˜(Ñ#Ô#Ð#°SÐ8r&   z5dsfd;kfoA,.iyewrkldJKDHSUBsgvca69834ncxv9873254k;fg87c                 ó¢   ‡‡‡— | j         Št          ‰¦  «        Št          ˆˆˆfd„t          t	          |¦  «        ¦  «        D ¦   «         ¦  «        S )z1xor static key against data - encrypts & decryptsc              3   óZ   •K  — | ]%\  }}|t          ‰‰|z   ‰z           ¦  «        z  V — Œ&d S rO   )Úord)r!   ÚidxÚvalueÚkeyÚkey_sizerJ   s      €€€r$   r%   z&cisco_type7._cipher.<locals>.<genexpr>±  sV   øè è € ð  
ð  
á��Uð •C˜˜T C™Z¨8Ñ3Ô4Ñ5Ô5Ñ5ð 
ð  
ð  
ð  
ð  
ð  
r&   )Ú_keyr+   r   r5   r   )rW   ÚdatarJ   r}   r~   s     `@@r$   rs   zcisco_type7._cipher¬  sl   øøø€ ð ŒhˆÝ�s‘8”8ˆÝð  
ð  
ð  
ð  
ð  
ð  
å'Õ(8¸Ñ(>Ô(>Ñ?Ô?ð 
ñ  
ô  
ñ 
ô 
ð 	
r&   rO   )F)r   )r>   r?   r@   rA   r.   Úsetting_kwdsr/   ÚUPPER_HEX_CHARSrF   Úmin_salt_valueri   ÚclassmethodrR   rb   rd   rS   rU   rV   rq   r=   r7   r   r   rs   Ú__classcell__)rZ   s   @r$   r   r   )  sY  ø€ € € € € ðð ðF €DØ€Lð
 Ô'€Nð €NØ€Nð
 ðð ð ð ð ñ „[ðð ð9ð 9ñ „[ð9ð	ð 	ð 	ð 	ð 	ð 	ð ð"ð "ð "ñ „[ð"ð" ð%ð %ñ „\ð%ðDð Dð DðPð Pð Pð ð
9ð 
9ð 
9ñ „[ð
9ð ˆ1ÐDÑEÔE€Dàð
ð 
ñ „[ð
ð 
ð 
ð 
ð 
r&   r   )&rA   Úbinasciir   r   Úhashlibr   ÚloggingÚ	getLoggerr>   ÚlogÚwarningsr   Úpasslib.utilsr   r   r	   r
   Úpasslib.utils.binaryr   Úpasslib.utils.compatr   r   r   r   r   r   Úpasslib.utils.handlersÚutilsÚhandlersr/   Ú__all__r2   ÚHasUserContextÚStaticHandlerr   r   ÚGenericHandlerr   r    r&   r$   ú<module>r–      sË  ððð ð (Ð 'Ð 'Ð 'Ð 'Ð 'Ð 'Ð 'Ø Ð Ð Ð Ð Ð Ø €€€Ð'�gÔ'¨Ñ1Ô1�Ø Ð Ð Ð Ð Ð ð PÐ OÐ OÐ OÐ OÐ OÐ OÐ OÐ OÐ OÐ OÐ OØ $Ð $Ð $Ð $Ð $Ð $ð>ð >ð >ð >ð >ð >ð >ð >ð >ð >ð >ð >ð >ð >ð >ð >à #Ð #Ð #Ð #Ð #Ð #Ð #Ð #Ð #ðð ð €ð €ð
8ð 8ð 8ð 8ð 8�Ô! 2Ô#3ñ 8ô 8ð 8ðj'ð 'ð 'ð 'ð '�	ñ 'ô 'ð 'ð`K
ð K
ð K
ð K
ð K
�"Ô#ñ K
ô K
ð K
ð K
ð K
r&   