PageRenderTime 53ms CodeModel.GetById 21ms RepoModel.GetById 0ms app.codeStats 0ms

/php5-3/core/tools/secure/crypt/Hash.class.php

https://bitbucket.org/ronaldobrandini/framework
PHP | 814 lines | 472 code | 68 blank | 274 comment | 27 complexity | d66bf58278daefc836ba3af0fabbc210 MD5 | raw file
Possible License(s): MPL-2.0-no-copyleft-exception
  1. <?php
  2. namespace core\tools\secure\crypt;
  3. /**
  4. * Pure-PHP implementations of keyed-hash message authentication codes (HMACs) and various cryptographic hashing functions.
  5. *
  6. * Uses hash() or mhash() if available and an internal implementation, otherwise. Currently supports the following:
  7. *
  8. * md2, md5, md5-96, sha1, sha1-96, sha256, sha384, and sha512
  9. *
  10. * If {@link Hash::setKey() setKey()} is called, {@link Hash::hash() hash()} will return the HMAC as opposed to
  11. * the hash. If no valid algorithm is provided, sha1 will be used.
  12. *
  13. * PHP versions 4 and 5
  14. *
  15. * {@internal The variable names are the same as those in
  16. * {@link http://tools.ietf.org/html/rfc2104#section-2 RFC2104}.}}
  17. *
  18. * Here's a short example of how to use this library:
  19. * <code>
  20. * <?php
  21. * include 'Crypt/Hash.php';
  22. *
  23. * $hash = new Hash('sha1');
  24. *
  25. * $hash->setKey('abcdefg');
  26. *
  27. * echo base64_encode($hash->hash('abcdefg'));
  28. * ?>
  29. * </code>
  30. *
  31. * LICENSE: Permission is hereby granted, free of charge, to any person obtaining a copy
  32. * of this software and associated documentation files (the "Software"), to deal
  33. * in the Software without restriction, including without limitation the rights
  34. * to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
  35. * copies of the Software, and to permit persons to whom the Software is
  36. * furnished to do so, subject to the following conditions:
  37. *
  38. * The above copyright notice and this permission notice shall be included in
  39. * all copies or substantial portions of the Software.
  40. *
  41. * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
  42. * IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
  43. * FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
  44. * AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
  45. * LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
  46. * OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN
  47. * THE SOFTWARE.
  48. *
  49. * @category Crypt
  50. * @package Hash
  51. * @author Jim Wigginton <terrafrost@php.net>
  52. * @copyright MMVII Jim Wigginton
  53. * @license http://www.opensource.org/licenses/mit-license.html MIT License
  54. * @link http://phpseclib.sourceforge.net
  55. */
  56. /* * #@+
  57. * @access private
  58. * @see Hash::Hash()
  59. */
  60. /**
  61. * Pure-PHP implementations of keyed-hash message authentication codes (HMACs) and various cryptographic hashing functions.
  62. *
  63. * @package Hash
  64. * @author Jim Wigginton <terrafrost@php.net>
  65. * @access public
  66. */
  67. class Hash{
  68. /**
  69. * Hash Parameter
  70. *
  71. * @see Hash::setHash()
  72. * @var Integer
  73. * @access private
  74. */
  75. private $hashParam;
  76. /**
  77. * Byte-length of compression blocks / key (Internal HMAC)
  78. *
  79. * @see Hash::setAlgorithm()
  80. * @var Integer
  81. * @access private
  82. */
  83. private $b;
  84. /**
  85. * Byte-length of hash output (Internal HMAC)
  86. *
  87. * @see Hash::setHash()
  88. * @var Integer
  89. * @access private
  90. */
  91. private $l = false;
  92. /**
  93. * Hash Algorithm
  94. *
  95. * @see Hash::setHash()
  96. * @var String
  97. * @access private
  98. */
  99. private $hash;
  100. /**
  101. * Key
  102. *
  103. * @see Hash::setKey()
  104. * @var String
  105. * @access private
  106. */
  107. private $key = false;
  108. /**
  109. * Outer XOR (Internal HMAC)
  110. *
  111. * @see Hash::setKey()
  112. * @var String
  113. * @access private
  114. */
  115. private $opad;
  116. /**
  117. * Inner XOR (Internal HMAC)
  118. *
  119. * @see Hash::setKey()
  120. * @var String
  121. * @access private
  122. */
  123. private $ipad;
  124. /**
  125. * Default Constructor.
  126. *
  127. * @param optional String $hash
  128. * @return Hash
  129. * @access public
  130. */
  131. public function __construct($hash = 'sha1'){
  132. if(!defined('CRYPT_HASH_MODE')){
  133. switch(true){
  134. case extension_loaded('hash'):
  135. define('CRYPT_HASH_MODE', CRYPT_HASH_MODE_HASH);
  136. break;
  137. case extension_loaded('mhash'):
  138. define('CRYPT_HASH_MODE', CRYPT_HASH_MODE_MHASH);
  139. break;
  140. default:
  141. define('CRYPT_HASH_MODE', CRYPT_HASH_MODE_INTERNAL);
  142. }
  143. }
  144. $this->setHash($hash);
  145. }
  146. /**
  147. * Sets the key for HMACs
  148. *
  149. * Keys can be of any length.
  150. *
  151. * @access public
  152. * @param optional String $key
  153. */
  154. public function setKey($key = false){
  155. $this->key = $key;
  156. }
  157. /**
  158. * Gets the hash function.
  159. *
  160. * As set by the constructor or by the setHash() method.
  161. *
  162. * @access public
  163. * @return String
  164. */
  165. public function getHash(){
  166. return $this->hashParam;
  167. }
  168. /**
  169. * Sets the hash function.
  170. *
  171. * @access public
  172. * @param String $hash
  173. */
  174. public function setHash($hash){
  175. $this->hashParam = $hash = strtolower($hash);
  176. switch($hash){
  177. case 'md5-96':
  178. case 'sha1-96':
  179. $this->l = 12; // 96 / 8 = 12
  180. break;
  181. case 'md2':
  182. case 'md5':
  183. $this->l = 16;
  184. break;
  185. case 'sha1':
  186. $this->l = 20;
  187. break;
  188. case 'sha256':
  189. $this->l = 32;
  190. break;
  191. case 'sha384':
  192. $this->l = 48;
  193. break;
  194. case 'sha512':
  195. $this->l = 64;
  196. }
  197. switch($hash){
  198. case 'md2':
  199. $mode = CRYPT_HASH_MODE == CRYPT_HASH_MODE_HASH && in_array('md2', hash_algos()) ?
  200. CRYPT_HASH_MODE_HASH : CRYPT_HASH_MODE_INTERNAL;
  201. break;
  202. case 'sha384':
  203. case 'sha512':
  204. $mode = CRYPT_HASH_MODE == CRYPT_HASH_MODE_MHASH ? CRYPT_HASH_MODE_INTERNAL : CRYPT_HASH_MODE;
  205. break;
  206. default:
  207. $mode = CRYPT_HASH_MODE;
  208. }
  209. switch($mode){
  210. case CRYPT_HASH_MODE_MHASH:
  211. switch($hash){
  212. case 'md5':
  213. case 'md5-96':
  214. $this->hash = MHASH_MD5;
  215. break;
  216. case 'sha256':
  217. $this->hash = MHASH_SHA256;
  218. break;
  219. case 'sha1':
  220. case 'sha1-96':
  221. default:
  222. $this->hash = MHASH_SHA1;
  223. }
  224. return;
  225. case CRYPT_HASH_MODE_HASH:
  226. switch($hash){
  227. case 'md5':
  228. case 'md5-96':
  229. $this->hash = 'md5';
  230. return;
  231. case 'md2':
  232. case 'sha256':
  233. case 'sha384':
  234. case 'sha512':
  235. $this->hash = $hash;
  236. return;
  237. case 'sha1':
  238. case 'sha1-96':
  239. default:
  240. $this->hash = 'sha1';
  241. }
  242. return;
  243. }
  244. switch($hash){
  245. case 'md2':
  246. $this->b = 16;
  247. $this->hash = array($this, '_md2');
  248. break;
  249. case 'md5':
  250. case 'md5-96':
  251. $this->b = 64;
  252. $this->hash = array($this, '_md5');
  253. break;
  254. case 'sha256':
  255. $this->b = 64;
  256. $this->hash = array($this, '_sha256');
  257. break;
  258. case 'sha384':
  259. case 'sha512':
  260. $this->b = 128;
  261. $this->hash = array($this, '_sha512');
  262. break;
  263. case 'sha1':
  264. case 'sha1-96':
  265. default:
  266. $this->b = 64;
  267. $this->hash = array($this, '_sha1');
  268. }
  269. $this->ipad = str_repeat(chr(0x36), $this->b);
  270. $this->opad = str_repeat(chr(0x5C), $this->b);
  271. }
  272. /**
  273. * Compute the HMAC.
  274. *
  275. * @access public
  276. * @param String $text
  277. * @return String
  278. */
  279. public function hash($text){
  280. $mode = is_array($this->hash) ? CRYPT_HASH_MODE_INTERNAL : CRYPT_HASH_MODE;
  281. if(!empty($this->key) || is_string($this->key)){
  282. switch($mode){
  283. case CRYPT_HASH_MODE_MHASH:
  284. $output = mhash($this->hash, $text, $this->key);
  285. break;
  286. case CRYPT_HASH_MODE_HASH:
  287. $output = hash_hmac($this->hash, $text, $this->key, true);
  288. break;
  289. case CRYPT_HASH_MODE_INTERNAL:
  290. /* "Applications that use keys longer than B bytes will first hash the key using H and then use the
  291. resultant L byte string as the actual key to HMAC."
  292. -- http://tools.ietf.org/html/rfc2104#section-2 */
  293. $key = strlen($this->key) > $this->b ? call_user_func($this->hash, $this->key) : $this->key;
  294. $key = str_pad($key, $this->b, chr(0)); // step 1
  295. $temp = $this->ipad ^ $key; // step 2
  296. $temp .= $text; // step 3
  297. $temp = call_user_func($this->hash, $temp); // step 4
  298. $output = $this->opad ^ $key; // step 5
  299. $output.= $temp; // step 6
  300. $output = call_user_func($this->hash, $output); // step 7
  301. }
  302. }else{
  303. switch($mode){
  304. case CRYPT_HASH_MODE_MHASH:
  305. $output = mhash($this->hash, $text);
  306. break;
  307. case CRYPT_HASH_MODE_HASH:
  308. $output = hash($this->hash, $text, true);
  309. break;
  310. case CRYPT_HASH_MODE_INTERNAL:
  311. $output = call_user_func($this->hash, $text);
  312. }
  313. }
  314. return substr($output, 0, $this->l);
  315. }
  316. /**
  317. * Returns the hash length (in bytes)
  318. *
  319. * @access public
  320. * @return Integer
  321. */
  322. public function getLength(){
  323. return $this->l;
  324. }
  325. /**
  326. * Wrapper for MD5
  327. *
  328. * @access private
  329. * @param String $m
  330. */
  331. private function _md5($m){
  332. return pack('H*', md5($m));
  333. }
  334. /**
  335. * Wrapper for SHA1
  336. *
  337. * @access private
  338. * @param String $m
  339. */
  340. private function _sha1($m){
  341. return pack('H*', sha1($m));
  342. }
  343. /**
  344. * Pure-PHP implementation of MD2
  345. *
  346. * See {@link http://tools.ietf.org/html/rfc1319 RFC1319}.
  347. *
  348. * @access private
  349. * @param String $m
  350. */
  351. private function _md2($m){
  352. static $s = array(
  353. 41, 46, 67, 201, 162, 216, 124, 1, 61, 54, 84, 161, 236, 240, 6,
  354. 19, 98, 167, 5, 243, 192, 199, 115, 140, 152, 147, 43, 217, 188,
  355. 76, 130, 202, 30, 155, 87, 60, 253, 212, 224, 22, 103, 66, 111, 24,
  356. 138, 23, 229, 18, 190, 78, 196, 214, 218, 158, 222, 73, 160, 251,
  357. 245, 142, 187, 47, 238, 122, 169, 104, 121, 145, 21, 178, 7, 63,
  358. 148, 194, 16, 137, 11, 34, 95, 33, 128, 127, 93, 154, 90, 144, 50,
  359. 39, 53, 62, 204, 231, 191, 247, 151, 3, 255, 25, 48, 179, 72, 165,
  360. 181, 209, 215, 94, 146, 42, 172, 86, 170, 198, 79, 184, 56, 210,
  361. 150, 164, 125, 182, 118, 252, 107, 226, 156, 116, 4, 241, 69, 157,
  362. 112, 89, 100, 113, 135, 32, 134, 91, 207, 101, 230, 45, 168, 2, 27,
  363. 96, 37, 173, 174, 176, 185, 246, 28, 70, 97, 105, 52, 64, 126, 15,
  364. 85, 71, 163, 35, 221, 81, 175, 58, 195, 92, 249, 206, 186, 197,
  365. 234, 38, 44, 83, 13, 110, 133, 40, 132, 9, 211, 223, 205, 244, 65,
  366. 129, 77, 82, 106, 220, 55, 200, 108, 193, 171, 250, 36, 225, 123,
  367. 8, 12, 189, 177, 74, 120, 136, 149, 139, 227, 99, 232, 109, 233,
  368. 203, 213, 254, 59, 0, 29, 57, 242, 239, 183, 14, 102, 88, 208, 228,
  369. 166, 119, 114, 248, 235, 117, 75, 10, 49, 68, 80, 180, 143, 237,
  370. 31, 26, 219, 153, 141, 51, 159, 17, 131, 20
  371. );
  372. // Step 1. Append Padding Bytes
  373. $pad = 16 - (strlen($m) & 0xF);
  374. $m.= str_repeat(chr($pad), $pad);
  375. $length = strlen($m);
  376. // Step 2. Append Checksum
  377. $c = str_repeat(chr(0), 16);
  378. $l = chr(0);
  379. for($i = 0; $i < $length; $i+= 16){
  380. for($j = 0; $j < 16; $j++){
  381. // RFC1319 incorrectly states that C[j] should be set to S[c xor L]
  382. //$c[$j] = chr($s[ord($m[$i + $j] ^ $l)]);
  383. // per <http://www.rfc-editor.org/errata_search.php?rfc=1319>, however, C[j] should be set to S[c xor L] xor C[j]
  384. $c[$j] = chr($s[ord($m[$i + $j] ^ $l)] ^ ord($c[$j]));
  385. $l = $c[$j];
  386. }
  387. }
  388. $m.= $c;
  389. $length+= 16;
  390. // Step 3. Initialize MD Buffer
  391. $x = str_repeat(chr(0), 48);
  392. // Step 4. Process Message in 16-Byte Blocks
  393. for($i = 0; $i < $length; $i+= 16){
  394. for($j = 0; $j < 16; $j++){
  395. $x[$j + 16] = $m[$i + $j];
  396. $x[$j + 32] = $x[$j + 16] ^ $x[$j];
  397. }
  398. $t = chr(0);
  399. for($j = 0; $j < 18; $j++){
  400. for($k = 0; $k < 48; $k++){
  401. $x[$k] = $t = $x[$k] ^ chr($s[ord($t)]);
  402. //$t = $x[$k] = $x[$k] ^ chr($s[ord($t)]);
  403. }
  404. $t = chr(ord($t) + $j);
  405. }
  406. }
  407. // Step 5. Output
  408. return substr($x, 0, 16);
  409. }
  410. /**
  411. * Pure-PHP implementation of SHA256
  412. *
  413. * See {@link http://en.wikipedia.org/wiki/SHA_hash_functions#SHA-256_.28a_SHA-2_variant.29_pseudocode SHA-256 (a SHA-2 variant) pseudocode - Wikipedia}.
  414. *
  415. * @access private
  416. * @param String $m
  417. */
  418. private function _sha256($m){
  419. if(extension_loaded('suhosin')){
  420. return pack('H*', sha256($m));
  421. }
  422. // Initialize variables
  423. $hash = array(
  424. 0x6a09e667, 0xbb67ae85, 0x3c6ef372, 0xa54ff53a, 0x510e527f, 0x9b05688c, 0x1f83d9ab, 0x5be0cd19
  425. );
  426. // Initialize table of round constants
  427. // (first 32 bits of the fractional parts of the cube roots of the first 64 primes 2..311)
  428. static $k = array(
  429. 0x428a2f98, 0x71374491, 0xb5c0fbcf, 0xe9b5dba5, 0x3956c25b, 0x59f111f1, 0x923f82a4, 0xab1c5ed5,
  430. 0xd807aa98, 0x12835b01, 0x243185be, 0x550c7dc3, 0x72be5d74, 0x80deb1fe, 0x9bdc06a7, 0xc19bf174,
  431. 0xe49b69c1, 0xefbe4786, 0x0fc19dc6, 0x240ca1cc, 0x2de92c6f, 0x4a7484aa, 0x5cb0a9dc, 0x76f988da,
  432. 0x983e5152, 0xa831c66d, 0xb00327c8, 0xbf597fc7, 0xc6e00bf3, 0xd5a79147, 0x06ca6351, 0x14292967,
  433. 0x27b70a85, 0x2e1b2138, 0x4d2c6dfc, 0x53380d13, 0x650a7354, 0x766a0abb, 0x81c2c92e, 0x92722c85,
  434. 0xa2bfe8a1, 0xa81a664b, 0xc24b8b70, 0xc76c51a3, 0xd192e819, 0xd6990624, 0xf40e3585, 0x106aa070,
  435. 0x19a4c116, 0x1e376c08, 0x2748774c, 0x34b0bcb5, 0x391c0cb3, 0x4ed8aa4a, 0x5b9cca4f, 0x682e6ff3,
  436. 0x748f82ee, 0x78a5636f, 0x84c87814, 0x8cc70208, 0x90befffa, 0xa4506ceb, 0xbef9a3f7, 0xc67178f2
  437. );
  438. // Pre-processing
  439. $length = strlen($m);
  440. // to round to nearest 56 mod 64, we'll add 64 - (length + (64 - 56)) % 64
  441. $m.= str_repeat(chr(0), 64 - (($length + 8) & 0x3F));
  442. $m[$length] = chr(0x80);
  443. // we don't support hashing strings 512MB long
  444. $m.= pack('N2', 0, $length << 3);
  445. // Process the message in successive 512-bit chunks
  446. $chunks = str_split($m, 64);
  447. foreach($chunks as $chunk){
  448. $w = array();
  449. for($i = 0; $i < 16; $i++){
  450. extract(unpack('Ntemp', $this->_string_shift($chunk, 4)));
  451. $w[] = $temp;
  452. }
  453. // Extend the sixteen 32-bit words into sixty-four 32-bit words
  454. for($i = 16; $i < 64; $i++){
  455. $s0 = $this->_rightRotate($w[$i - 15], 7) ^
  456. $this->_rightRotate($w[$i - 15], 18) ^
  457. $this->_rightShift($w[$i - 15], 3);
  458. $s1 = $this->_rightRotate($w[$i - 2], 17) ^
  459. $this->_rightRotate($w[$i - 2], 19) ^
  460. $this->_rightShift($w[$i - 2], 10);
  461. $w[$i] = $this->_add($w[$i - 16], $s0, $w[$i - 7], $s1);
  462. }
  463. // Initialize hash value for this chunk
  464. list($a, $b, $c, $d, $e, $f, $g, $h) = $hash;
  465. // Main loop
  466. for($i = 0; $i < 64; $i++){
  467. $s0 = $this->_rightRotate($a, 2) ^
  468. $this->_rightRotate($a, 13) ^
  469. $this->_rightRotate($a, 22);
  470. $maj = ($a & $b) ^
  471. ($a & $c) ^
  472. ($b & $c);
  473. $t2 = $this->_add($s0, $maj);
  474. $s1 = $this->_rightRotate($e, 6) ^
  475. $this->_rightRotate($e, 11) ^
  476. $this->_rightRotate($e, 25);
  477. $ch = ($e & $f) ^
  478. ($this->_not($e) & $g);
  479. $t1 = $this->_add($h, $s1, $ch, $k[$i], $w[$i]);
  480. $h = $g;
  481. $g = $f;
  482. $f = $e;
  483. $e = $this->_add($d, $t1);
  484. $d = $c;
  485. $c = $b;
  486. $b = $a;
  487. $a = $this->_add($t1, $t2);
  488. }
  489. // Add this chunk's hash to result so far
  490. $hash = array(
  491. $this->_add($hash[0], $a),
  492. $this->_add($hash[1], $b),
  493. $this->_add($hash[2], $c),
  494. $this->_add($hash[3], $d),
  495. $this->_add($hash[4], $e),
  496. $this->_add($hash[5], $f),
  497. $this->_add($hash[6], $g),
  498. $this->_add($hash[7], $h)
  499. );
  500. }
  501. // Produce the final hash value (big-endian)
  502. return pack('N8', $hash[0], $hash[1], $hash[2], $hash[3], $hash[4], $hash[5], $hash[6], $hash[7]);
  503. }
  504. /**
  505. * Pure-PHP implementation of SHA384 and SHA512
  506. *
  507. * @access private
  508. * @param String $m
  509. */
  510. private function _sha512($m){
  511. if(!class_exists('Math_BigInteger')){
  512. include_once 'Math/BigInteger.php';
  513. }
  514. static $init384, $init512, $k;
  515. if(!isset($k)){
  516. // Initialize variables
  517. $init384 = array(// initial values for SHA384
  518. 'cbbb9d5dc1059ed8', '629a292a367cd507', '9159015a3070dd17', '152fecd8f70e5939',
  519. '67332667ffc00b31', '8eb44a8768581511', 'db0c2e0d64f98fa7', '47b5481dbefa4fa4'
  520. );
  521. $init512 = array(// initial values for SHA512
  522. '6a09e667f3bcc908', 'bb67ae8584caa73b', '3c6ef372fe94f82b', 'a54ff53a5f1d36f1',
  523. '510e527fade682d1', '9b05688c2b3e6c1f', '1f83d9abfb41bd6b', '5be0cd19137e2179'
  524. );
  525. for($i = 0; $i < 8; $i++){
  526. $init384[$i] = new Math_BigInteger($init384[$i], 16);
  527. $init384[$i]->setPrecision(64);
  528. $init512[$i] = new Math_BigInteger($init512[$i], 16);
  529. $init512[$i]->setPrecision(64);
  530. }
  531. // Initialize table of round constants
  532. // (first 64 bits of the fractional parts of the cube roots of the first 80 primes 2..409)
  533. $k = array(
  534. '428a2f98d728ae22', '7137449123ef65cd', 'b5c0fbcfec4d3b2f', 'e9b5dba58189dbbc',
  535. '3956c25bf348b538', '59f111f1b605d019', '923f82a4af194f9b', 'ab1c5ed5da6d8118',
  536. 'd807aa98a3030242', '12835b0145706fbe', '243185be4ee4b28c', '550c7dc3d5ffb4e2',
  537. '72be5d74f27b896f', '80deb1fe3b1696b1', '9bdc06a725c71235', 'c19bf174cf692694',
  538. 'e49b69c19ef14ad2', 'efbe4786384f25e3', '0fc19dc68b8cd5b5', '240ca1cc77ac9c65',
  539. '2de92c6f592b0275', '4a7484aa6ea6e483', '5cb0a9dcbd41fbd4', '76f988da831153b5',
  540. '983e5152ee66dfab', 'a831c66d2db43210', 'b00327c898fb213f', 'bf597fc7beef0ee4',
  541. 'c6e00bf33da88fc2', 'd5a79147930aa725', '06ca6351e003826f', '142929670a0e6e70',
  542. '27b70a8546d22ffc', '2e1b21385c26c926', '4d2c6dfc5ac42aed', '53380d139d95b3df',
  543. '650a73548baf63de', '766a0abb3c77b2a8', '81c2c92e47edaee6', '92722c851482353b',
  544. 'a2bfe8a14cf10364', 'a81a664bbc423001', 'c24b8b70d0f89791', 'c76c51a30654be30',
  545. 'd192e819d6ef5218', 'd69906245565a910', 'f40e35855771202a', '106aa07032bbd1b8',
  546. '19a4c116b8d2d0c8', '1e376c085141ab53', '2748774cdf8eeb99', '34b0bcb5e19b48a8',
  547. '391c0cb3c5c95a63', '4ed8aa4ae3418acb', '5b9cca4f7763e373', '682e6ff3d6b2b8a3',
  548. '748f82ee5defb2fc', '78a5636f43172f60', '84c87814a1f0ab72', '8cc702081a6439ec',
  549. '90befffa23631e28', 'a4506cebde82bde9', 'bef9a3f7b2c67915', 'c67178f2e372532b',
  550. 'ca273eceea26619c', 'd186b8c721c0c207', 'eada7dd6cde0eb1e', 'f57d4f7fee6ed178',
  551. '06f067aa72176fba', '0a637dc5a2c898a6', '113f9804bef90dae', '1b710b35131c471b',
  552. '28db77f523047d84', '32caab7b40c72493', '3c9ebe0a15c9bebc', '431d67c49c100d4c',
  553. '4cc5d4becb3e42b6', '597f299cfc657e2a', '5fcb6fab3ad6faec', '6c44198c4a475817'
  554. );
  555. for($i = 0; $i < 80; $i++){
  556. $k[$i] = new Math_BigInteger($k[$i], 16);
  557. }
  558. }
  559. $hash = $this->l == 48 ? $init384 : $init512;
  560. // Pre-processing
  561. $length = strlen($m);
  562. // to round to nearest 112 mod 128, we'll add 128 - (length + (128 - 112)) % 128
  563. $m.= str_repeat(chr(0), 128 - (($length + 16) & 0x7F));
  564. $m[$length] = chr(0x80);
  565. // we don't support hashing strings 512MB long
  566. $m.= pack('N4', 0, 0, 0, $length << 3);
  567. // Process the message in successive 1024-bit chunks
  568. $chunks = str_split($m, 128);
  569. foreach($chunks as $chunk){
  570. $w = array();
  571. for($i = 0; $i < 16; $i++){
  572. $temp = new Math_BigInteger($this->_string_shift($chunk, 8), 256);
  573. $temp->setPrecision(64);
  574. $w[] = $temp;
  575. }
  576. // Extend the sixteen 32-bit words into eighty 32-bit words
  577. for($i = 16; $i < 80; $i++){
  578. $temp = array(
  579. $w[$i - 15]->bitwise_rightRotate(1),
  580. $w[$i - 15]->bitwise_rightRotate(8),
  581. $w[$i - 15]->bitwise_rightShift(7)
  582. );
  583. $s0 = $temp[0]->bitwise_xor($temp[1]);
  584. $s0 = $s0->bitwise_xor($temp[2]);
  585. $temp = array(
  586. $w[$i - 2]->bitwise_rightRotate(19),
  587. $w[$i - 2]->bitwise_rightRotate(61),
  588. $w[$i - 2]->bitwise_rightShift(6)
  589. );
  590. $s1 = $temp[0]->bitwise_xor($temp[1]);
  591. $s1 = $s1->bitwise_xor($temp[2]);
  592. $w[$i] = $w[$i - 16]->copy();
  593. $w[$i] = $w[$i]->add($s0);
  594. $w[$i] = $w[$i]->add($w[$i - 7]);
  595. $w[$i] = $w[$i]->add($s1);
  596. }
  597. // Initialize hash value for this chunk
  598. $a = $hash[0]->copy();
  599. $b = $hash[1]->copy();
  600. $c = $hash[2]->copy();
  601. $d = $hash[3]->copy();
  602. $e = $hash[4]->copy();
  603. $f = $hash[5]->copy();
  604. $g = $hash[6]->copy();
  605. $h = $hash[7]->copy();
  606. // Main loop
  607. for($i = 0; $i < 80; $i++){
  608. $temp = array(
  609. $a->bitwise_rightRotate(28),
  610. $a->bitwise_rightRotate(34),
  611. $a->bitwise_rightRotate(39)
  612. );
  613. $s0 = $temp[0]->bitwise_xor($temp[1]);
  614. $s0 = $s0->bitwise_xor($temp[2]);
  615. $temp = array(
  616. $a->bitwise_and($b),
  617. $a->bitwise_and($c),
  618. $b->bitwise_and($c)
  619. );
  620. $maj = $temp[0]->bitwise_xor($temp[1]);
  621. $maj = $maj->bitwise_xor($temp[2]);
  622. $t2 = $s0->add($maj);
  623. $temp = array(
  624. $e->bitwise_rightRotate(14),
  625. $e->bitwise_rightRotate(18),
  626. $e->bitwise_rightRotate(41)
  627. );
  628. $s1 = $temp[0]->bitwise_xor($temp[1]);
  629. $s1 = $s1->bitwise_xor($temp[2]);
  630. $temp = array(
  631. $e->bitwise_and($f),
  632. $g->bitwise_and($e->bitwise_not())
  633. );
  634. $ch = $temp[0]->bitwise_xor($temp[1]);
  635. $t1 = $h->add($s1);
  636. $t1 = $t1->add($ch);
  637. $t1 = $t1->add($k[$i]);
  638. $t1 = $t1->add($w[$i]);
  639. $h = $g->copy();
  640. $g = $f->copy();
  641. $f = $e->copy();
  642. $e = $d->add($t1);
  643. $d = $c->copy();
  644. $c = $b->copy();
  645. $b = $a->copy();
  646. $a = $t1->add($t2);
  647. }
  648. // Add this chunk's hash to result so far
  649. $hash = array(
  650. $hash[0]->add($a),
  651. $hash[1]->add($b),
  652. $hash[2]->add($c),
  653. $hash[3]->add($d),
  654. $hash[4]->add($e),
  655. $hash[5]->add($f),
  656. $hash[6]->add($g),
  657. $hash[7]->add($h)
  658. );
  659. }
  660. // Produce the final hash value (big-endian)
  661. // (Hash::hash() trims the output for hashes but not for HMACs. as such, we trim the output here)
  662. $temp = $hash[0]->toBytes() . $hash[1]->toBytes() . $hash[2]->toBytes() . $hash[3]->toBytes() .
  663. $hash[4]->toBytes() . $hash[5]->toBytes();
  664. if($this->l != 48){
  665. $temp.= $hash[6]->toBytes() . $hash[7]->toBytes();
  666. }
  667. return $temp;
  668. }
  669. /**
  670. * Right Rotate
  671. *
  672. * @access private
  673. * @param Integer $int
  674. * @param Integer $amt
  675. * @see _sha256()
  676. * @return Integer
  677. */
  678. private function _rightRotate($int, $amt){
  679. $invamt = 32 - $amt;
  680. $mask = (1 << $invamt) - 1;
  681. return (($int << $invamt) & 0xFFFFFFFF) | (($int >> $amt) & $mask);
  682. }
  683. /**
  684. * Right Shift
  685. *
  686. * @access private
  687. * @param Integer $int
  688. * @param Integer $amt
  689. * @see _sha256()
  690. * @return Integer
  691. */
  692. private function _rightShift($int, $amt){
  693. $mask = (1 << (32 - $amt)) - 1;
  694. return ($int >> $amt) & $mask;
  695. }
  696. /**
  697. * Not
  698. *
  699. * @access private
  700. * @param Integer $int
  701. * @see _sha256()
  702. * @return Integer
  703. */
  704. private function _not($int){
  705. return ~$int & 0xFFFFFFFF;
  706. }
  707. /**
  708. * Add
  709. *
  710. * _sha256() adds multiple unsigned 32-bit integers. Since PHP doesn't support unsigned integers and since the
  711. * possibility of overflow exists, care has to be taken. Math_BigInteger() could be used but this should be faster.
  712. *
  713. * @param Integer $...
  714. * @return Integer
  715. * @see _sha256()
  716. * @access private
  717. */
  718. private function _add(){
  719. static $mod;
  720. if(!isset($mod)){
  721. $mod = pow(2, 32);
  722. }
  723. $result = 0;
  724. $arguments = func_get_args();
  725. foreach($arguments as $argument){
  726. $result+= $argument < 0 ? ($argument & 0x7FFFFFFF) + 0x80000000 : $argument;
  727. }
  728. return fmod($result, $mod);
  729. }
  730. /**
  731. * String Shift
  732. *
  733. * Inspired by array_shift
  734. *
  735. * @param String $string
  736. * @param optional Integer $index
  737. * @return String
  738. * @access private
  739. */
  740. private function _string_shift(&$string, $index = 1){
  741. $substr = substr($string, 0, $index);
  742. $string = substr($string, $index);
  743. return $substr;
  744. }
  745. }