content: hash($_SESSION['challenge']); } $authenticated = $encrypted_pw==$password; } else { require "./oath.php"; $oath = new oath; $authenticated = $oath->check_key(base64_decode($user_record['oath_key']),$_REQUEST['oath_response']); } if($authenticated) { login($user_record['username'],session_id()); $_SESSION['user'] = $user_record; if($config['log']['login'] == 'true') { log_event('login'); } $_SESSION['logged_in'] = true; if(!empty($_REQUEST['url'])) { header("Location: {$_REQUEST['url']}"); } else { header("Location: {$_SERVER['HTTP_REFERER']}"); } exit; } else { if($config['log']['failed'] == 'true') { log_event('failure'); } $error = "Login failed"; } } require_once "rKeyGen.php"; $_SESSION['challenge'] = rKeyGen(16); $bottom = ""; if(strrchr($_SERVER['PATH_INFO'],'/')=='/login.php') { echo "\n"; echo "\n"; echo "\n"; echo "\t\n"; echo "\t\tLogin\n"; echo "\t\t\n"; echo "\t\n"; echo "\t\n"; $bottom = "\n"; } ?> Login THIS CONNECTION IS NOT SECURE. You do not have Javascript enabled. Javascript is necessary to encrypt your password for submission. You may continue at your own risk. {$error}";?> Login Token Password