/
Registration.aspx.cs
356 lines (317 loc) · 12 KB
/
Registration.aspx.cs
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
using System;
using System.Collections.Generic;
using System.Linq;
using System.Web;
using System.Web.UI;
using System.Web.UI.WebControls;
using System.IO;
using System.Net;
using System.Net.Mail;
using System.Data;
using System.Configuration;
using MySql.Data.MySqlClient;
using System.Web.Security;
using System.Web.UI.WebControls.WebParts;
using System.Web.UI.HtmlControls;
using System.Text;
using System.Security.Cryptography;
public partial class Registration : System.Web.UI.Page
{
MySql.Data.MySqlClient.MySqlConnection con;
MySql.Data.MySqlClient.MySqlCommand cmd;
string querystr;
protected void Page_Load(object sender, EventArgs e)
{
}
protected void sumbt_Click(object sender, EventArgs e)
{
if (Page.IsValid)
{
//registerUser(); before modifying code
registerUserWithSlowHash();//new code
}
}
//new code from crackstation
private void registerUserWithSlowHash()
{
try
{
string connString = System.Configuration.ConfigurationManager.ConnectionStrings["MywebConnection"].ToString();
con = new MySql.Data.MySqlClient.MySqlConnection(connString);
con.Open();
querystr = "";
querystr = "INSERT INTO mydatabase.registertable(Username,DOB,Mobile,slowHashSalt)" +
"VALUES(?username,?datebirth,?mob,?slowhashsalt)";
cmd = new MySqlCommand(querystr, con);
cmd.Parameters.AddWithValue("?username", Username.Text);
cmd.Parameters.AddWithValue("?datebirth", dob.Text);
cmd.Parameters.AddWithValue("?mob", mob.Text);
string saltHashReturned = PasswordStorage.CreateHash(passwd.Text);
int commaIndex = saltHashReturned.IndexOf(":");
string extractedString = saltHashReturned.Substring(0, commaIndex);
commaIndex = saltHashReturned.IndexOf(":");
extractedString = saltHashReturned.Substring(commaIndex + 1);
commaIndex = extractedString.IndexOf(":");
string salt = extractedString.Substring(0, commaIndex);
commaIndex = extractedString.IndexOf(":");
extractedString = extractedString.Substring(commaIndex + 1);
string hash = extractedString;
//from the first : to the second : is the salt
//from the second : to the end is the hash
cmd.Parameters.AddWithValue("?slowhashsalt", saltHashReturned);
cmd.ExecuteReader();
con.Close();
//ClientScript.RegisterStartupScript(Page.GetType(), "validation", "<script language='javascript'>alert('You have been Succesfully Registered! Click O.K to navigate to Homepage.');window.location.replace('Default.aspx');</script>");
cmd.Dispose();
clearfields();
ClientScript.RegisterStartupScript(Page.GetType(), "validation", "<script language='javascript' >alertMX('Registered Succesfully! Click OK');</script>");
//ClientScript.RegisterStartupScript(Page.GetType(), "validation", "<script language='javascript' >myalert('Test', 'This is a test modal dialog');</script>");
}
catch (MySqlException reg)
{
Console.WriteLine("{0}+MySql Exceptions", reg);
}
finally
{
if (!(con == null))
{
con.Dispose();
}
}
}
private void clearfields()
{
Username.Text = "";
dob.Text = "";
mob.Text = "";
}
/* private void registerUser()
{
string connString = System.Configuration.ConfigurationManager.ConnectionStrings["MywebConnection"].ToString();
con = new MySql.Data.MySqlClient.MySqlConnection(connString);
con.Open();
querystr = "";
DateTime dt = Convert.ToDateTime(dob.Text);
string st = dt.ToString("yyyy-MM-dd");
querystr = "INSERT INTO mydatabase.registertable(Username,DOB,Mobile,Password)" +
"VALUES(?username,?datebirth,?mob,?password)";
//querystr = "INSERT INTO mydatabase.registertable(Username,DOB,Mobile,Password)"+
// "VALUES('" + Username.Text + "','" + dob.Text + "','" + mob.Text + "','" + passwd.Text + "')";
cmd = new MySqlCommand(querystr, con);
cmd.Parameters.AddWithValue("?username", Username.Text);
cmd.Parameters.AddWithValue("?datebirth", dob.Text);
cmd.Parameters.AddWithValue("?mob", mob.Text);
cmd.Parameters.AddWithValue("?password", passwd.Text);
cmd.ExecuteReader();
con.Close();
ClientScript.RegisterStartupScript(Page.GetType(), "validation", "<script language='javascript'>dialog('You have been Succesfully Registered! Click O.K to navigate to Homepage.');window.location.replace('Default.aspx');</script>");
}
*/
//code for SHA algorithm
class InvalidHashException : Exception
{
public InvalidHashException() { }
public InvalidHashException(string message)
: base(message) { }
public InvalidHashException(string message, Exception inner)
: base(message, inner) { }
}
class CannotPerformOperationException : Exception
{
public CannotPerformOperationException() { }
public CannotPerformOperationException(string message)
: base(message) { }
public CannotPerformOperationException(string message, Exception inner)
: base(message, inner) { }
}
class PasswordStorage
{
// These constants may be changed without breaking existing hashes.
public const int SALT_BYTES = 24;
public const int HASH_BYTES = 18;
public const int PBKDF2_ITERATIONS = 64000;
// These constants define the encoding and may not be changed.
public const int HASH_SECTIONS = 5;
public const int HASH_ALGORITHM_INDEX = 0;
public const int ITERATION_INDEX = 1;
public const int HASH_SIZE_INDEX = 2;
public const int SALT_INDEX = 3;
public const int PBKDF2_INDEX = 4;
public static string CreateHash(string password)
{
// Generate a random salt
byte[] salt = new byte[SALT_BYTES];
try
{
using (RNGCryptoServiceProvider csprng = new RNGCryptoServiceProvider())
{
csprng.GetBytes(salt);
}
}
catch (CryptographicException ex)
{
throw new CannotPerformOperationException(
"Random number generator not available.",
ex
);
}
catch (ArgumentNullException ex)
{
throw new CannotPerformOperationException(
"Invalid argument given to random number generator.",
ex
);
}
byte[] hash = PBKDF2(password, salt, PBKDF2_ITERATIONS, HASH_BYTES);
// format: algorithm:iterations:hashSize:salt:hash
String parts = "sha1:" +
PBKDF2_ITERATIONS +
":" +
hash.Length +
":" +
Convert.ToBase64String(salt) +
":" +
Convert.ToBase64String(hash);
return parts;
}
public static bool VerifyPassword(string password, string goodHash)
{
char[] delimiter = { ':' };
string[] split = goodHash.Split(delimiter);
if (split.Length != HASH_SECTIONS)
{
throw new InvalidHashException(
"Fields are missing from the password hash."
);
}
// We only support SHA1 with C#.
if (split[HASH_ALGORITHM_INDEX] != "sha1")
{
throw new CannotPerformOperationException(
"Unsupported hash type."
);
}
int iterations = 0;
try
{
iterations = Int32.Parse(split[ITERATION_INDEX]);
}
catch (ArgumentNullException ex)
{
throw new CannotPerformOperationException(
"Invalid argument given to Int32.Parse",
ex
);
}
catch (FormatException ex)
{
throw new InvalidHashException(
"Could not parse the iteration count as an integer.",
ex
);
}
catch (OverflowException ex)
{
throw new InvalidHashException(
"The iteration count is too large to be represented.",
ex
);
}
if (iterations < 1)
{
throw new InvalidHashException(
"Invalid number of iterations. Must be >= 1."
);
}
byte[] salt = null;
try
{
salt = Convert.FromBase64String(split[SALT_INDEX]);
}
catch (ArgumentNullException ex)
{
throw new CannotPerformOperationException(
"Invalid argument given to Convert.FromBase64String",
ex
);
}
catch (FormatException ex)
{
throw new InvalidHashException(
"Base64 decoding of salt failed.",
ex
);
}
byte[] hash = null;
try
{
hash = Convert.FromBase64String(split[PBKDF2_INDEX]);
}
catch (ArgumentNullException ex)
{
throw new CannotPerformOperationException(
"Invalid argument given to Convert.FromBase64String",
ex
);
}
catch (FormatException ex)
{
throw new InvalidHashException(
"Base64 decoding of pbkdf2 output failed.",
ex
);
}
int storedHashSize = 0;
try
{
storedHashSize = Int32.Parse(split[HASH_SIZE_INDEX]);
}
catch (ArgumentNullException ex)
{
throw new CannotPerformOperationException(
"Invalid argument given to Int32.Parse",
ex
);
}
catch (FormatException ex)
{
throw new InvalidHashException(
"Could not parse the hash size as an integer.",
ex
);
}
catch (OverflowException ex)
{
throw new InvalidHashException(
"The hash size is too large to be represented.",
ex
);
}
if (storedHashSize != hash.Length)
{
throw new InvalidHashException(
"Hash length doesn't match stored hash length."
);
}
byte[] testHash = PBKDF2(password, salt, iterations, hash.Length);
return SlowEquals(hash, testHash);
}
private static bool SlowEquals(byte[] a, byte[] b)
{
uint diff = (uint)a.Length ^ (uint)b.Length;
for (int i = 0; i < a.Length && i < b.Length; i++)
{
diff |= (uint)(a[i] ^ b[i]);
}
return diff == 0;
}
private static byte[] PBKDF2(string password, byte[] salt, int iterations, int outputBytes)
{
using (Rfc2898DeriveBytes pbkdf2 = new Rfc2898DeriveBytes(password, salt))
{
pbkdf2.IterationCount = iterations;
return pbkdf2.GetBytes(outputBytes);
}
}
}
}