This file is indexed.

/usr/bin/hash_password is in matrix-synapse 0.24.0+dfsg-1.

This file is owned by root:root, with mode 0o755.

The actual contents of the file can be viewed below.

 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
#!/usr/bin/python

import argparse

import sys

import bcrypt
import getpass

import yaml

bcrypt_rounds=12
password_pepper = ""

def prompt_for_pass():
    password = getpass.getpass("Password: ")

    if not password:
        raise Exception("Password cannot be blank.")

    confirm_password = getpass.getpass("Confirm password: ")

    if password != confirm_password:
        raise Exception("Passwords do not match.")

    return password

if __name__ == "__main__":
    parser = argparse.ArgumentParser(
        description="Calculate the hash of a new password, so that passwords"
                    " can be reset")
    parser.add_argument(
        "-p", "--password",
        default=None,
        help="New password for user. Will prompt if omitted.",
    )
    parser.add_argument(
        "-c", "--config",
        type=argparse.FileType('r'),
        help="Path to server config file. Used to read in bcrypt_rounds and password_pepper.",
    )

    args = parser.parse_args()
    if "config" in args and args.config:
        config = yaml.safe_load(args.config)
        bcrypt_rounds = config.get("bcrypt_rounds", bcrypt_rounds)
        password_config = config.get("password_config", {})
        password_pepper = password_config.get("pepper", password_pepper)
    password = args.password

    if not password:
        password = prompt_for_pass()

    print bcrypt.hashpw(password + password_pepper, bcrypt.gensalt(bcrypt_rounds))