$file_hash = sha1(GEN_PASS(mt_rand(128, 256)));
$file = PATH."inc/.secret/.".$file_hash;
+ // Count of chars to be taken from back of the string
+ $nums = mt_rand(40, 45);
+
+ // Generate secret key from a randomized string
+ $secretKey = substr(sha1(GEN_PASS(mt_rand(128, 256))), -$nums);
+
// File hash was never created
- $fp = @fopen($file, 'w') or mxchange_die("Cannot write secret key file!");
- if ($fp != false) {
- // Could write to secret file! So let's generate the secret key...
- // 1. Count of chars to be taken from back of the string
- $nums = mt_rand(40, 45);
- // 2. Generate secret key from a randomized string
- $secretKey = substr(sha1(GEN_PASS(mt_rand(128, 256))), -$nums);
- // 3. Write the key to the file
- fwrite($fp, $secretKey);
- // 4. Close file
- fclose($fp);
-
- // Change access rights for more security
- @chmod($file, 0644);
+ WRITE_FILE($file, $secretKey);
+ // Is the file there?
+ if (FILE_READABLE($file)) {
//* DEBUG: */ unlink($file);
//* DEBUG: */ $test = hexdec(get_session('u_hash')) / hexdec($secretKey);
//* DEBUG: */ $test = generateHash(str_replace('.', "", $test));
SQL_QUERY_ESC("UPDATE `"._MYSQL_PREFIX."_config` SET file_hash='%s' WHERE config=0 LIMIT 1",
array($file_hash), __FILE__, __LINE__);
+ // Generate FQFN for .htaccess file
+ $FQFN = PATH."inc/.secret/.htaccess";
+
// Is the .htaccess file there?
- if (!FILE_READABLE(PATH."inc/.secret/.htaccess")) {
+ if (!FILE_READABLE($FQFN)) {
// Also create .htaccess file
- $fp = @fopen(PATH."inc/.secret/.htaccess", 'w') or mxchange_die("Cannot write to .htaccess file!");
- if ($fp != false) {
- // Add deny line to file
- fwrite($fp, "Deny from all");
-
- // Close the file
- fclose($fp);
- } // END - if
+ WRITE_FILE($FQFN, "Deny from all\n");
} // END - if
// Also update configuration