KVSun / kvsun.com

Kern Valley Sun website
GNU General Public License v3.0
5 stars 10 forks source link

Checking Wordpress passwords fails #151

Closed shgysk8zer0 closed 7 years ago

shgysk8zer0 commented 7 years ago

Steps to reproduce

  1. Attempt to login as a user imported from Wordpress

Expected behavior

If credentials are correct, login should be successful

Actual behavior

Even with correct password, login is rejected

Screenshots and/or logs (see how to open the developer console in your browser)

Drag and drop file to upload and include in bug report

ErrorException: crypt(): Supplied salt is not valid for DES. Possible bug in provided salt format. in /var/www/html/shgysk8zer0/login/wp_pass.php:60
Stack trace:
#0 [internal function]: KVSun\Events\error_handler(8192, 'crypt(): Suppli...', '/var/www/html/s...', 60, Array)
#1 /var/www/html/shgysk8zer0/core/observer.php(44): call_user_func_array('KVSun\\Events\\er...', Array)
#2 /var/www/html/shgysk8zer0/core/subject.php(63): shgysk8zer0\Core\Observer->update(Object(shgysk8zer0\Core\Subject))
#3 /var/www/html/shgysk8zer0/core/listener.php(94): shgysk8zer0\Core\Subject->notify()
#4 /var/www/html/shgysk8zer0/core/listener.php(107): shgysk8zer0\Core\Listener->__call('error', Array)
#5 [internal function]: shgysk8zer0\Core\Listener::__callStatic('error', Array)
#6 /var/www/html/shgysk8zer0/login/wp_pass.php(60): crypt('************..', '**********...')
#7 /var/www/html/shgysk8zer0/login/traits/magic.php(29): shgysk8zer0\Login\User->CheckPassword('*****************..', '*****************...')
#8 /var/www/html/kvsun.com/components/handlers/form.php(268): shgysk8zer0\Login\User->__invoke('editor@kvsun.co...', '****************')
#9 /var/www/html/kvsun.com/api.php(87): require_once('/var/www/html/k...')
#10 {main}
shgysk8zer0 commented 7 years ago

Not sure about this code. Missing variable seems to be the problem.

$count_log2 = strpos($this->itoa64, $setting[3]);

$this->itoa64 isn't set.

shgysk8zer0 commented 7 years ago

Wordpress/class-phpass.php