0; $i-=16) { if ($i > 16) { $ctx .= substr ($final,0,16); } else { $ctx .= substr ($final,0,$i); } } $i = strlen ($pw); while ($i > 0) { if ($i & 1) $ctx .= chr (0); else $ctx .= $pw[0]; $i = $i >> 1; } $final = hex2bin (md5 ($ctx)); for ($i=0;$i<1000;$i++) { $ctx1 = ""; if ($i & 1) { $ctx1 .= $pw; } else { $ctx1 .= substr ($final,0,16); } if ($i % 3) $ctx1 .= $salt; if ($i % 7) $ctx1 .= $pw; if ($i & 1) { $ctx1 .= substr ($final,0,16); } else { $ctx1 .= $pw; } $final = hex2bin (md5 ($ctx1)); } $passwd = ""; $passwd .= to64 (((ord ($final[0]) << 16) | (ord ($final[6]) << 8) | (ord ($final[12]))), 4); $passwd .= to64 (((ord ($final[1]) << 16) | (ord ($final[7]) << 8) | (ord ($final[13]))), 4); $passwd .= to64 (((ord ($final[2]) << 16) | (ord ($final[8]) << 8) | (ord ($final[14]))), 4); $passwd .= to64 (((ord ($final[3]) << 16) | (ord ($final[9]) << 8) | (ord ($final[15]))), 4); $passwd .= to64 (((ord ($final[4]) << 16) | (ord ($final[10]) << 8) | (ord ($final[5]))), 4); $passwd .= to64 (ord ($final[11]), 2); return "$magic$salt\$$passwd"; } // // sourceforge.net/projects/postfixadmin/ // to64 // function to64 ($v, $n) { $ITOA64 = "./0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz"; $ret = ""; while (($n - 1) >= 0) { $n--; $ret .= $ITOA64[$v & 0x3f]; $v = $v >> 6; } return $ret; } // Check arguments if ((!empty($_POST['email'])) && (!empty($_POST['password'])) && (!empty($_POST['new']))) { list($v_account, $v_domain) = explode('@', $_POST['email']); $v_domain = escapeshellarg($v_domain); $v_account = escapeshellarg($v_account); $password = $_POST['password']; $new = escapeshellarg($_POST['new']); // Get domain owner exec (VESTA_CMD."v-search-domain-owner ".$v_domain." 'mail'", $output, $return_var); if ($return_var == 0) { $v_user = $output[0]; } unset($output); // Get current md5 hash if (!empty($v_user)) { exec (VESTA_CMD."v-get-mail-account-value '".$v_user."' ".$v_domain." ".$v_account." 'md5'", $output, $return_var); if ($return_var == 0) { $v_hash = $output[0]; } } unset($output); // Compare hashes if (!empty($v_hash)) { $salt = explode('$', $v_hash); $n_hash = md5crypt($password, $salt[2]); $n_hash = '{MD5}'.$n_hash; // Change password if ( $v_hash == $n_hash ) { exec (VESTA_CMD."v-change-mail-account-password '".$v_user."' ".$v_domain." ".$v_account." ".$new, $output, $return_var); if ($return_var == 0) { echo "ok"; exit; } } } } echo 'error'; exit;