Share Pastebin
Guest
Public paste!

Untitled

By: a guest | Mar 21st, 2010 | Syntax: PHP | Size: 0.40 KB | Hits: 55 | Expires: Never
Copy text to clipboard
  1. $username = mysql_real_escape_string($_POST['username']);
  2.         $unhashedpassword = mysql_real_escape_string($_POST['password']);
  3.         $hashedpassword = sha1($unhashedpassword);
  4.        
  5.         $query = "SELECT * FROM staff
  6.                 WHERE liUsername = '" . $username . "' AND
  7.                         ((liPassword = '" . $hashedpassword . "' AND UsedNewPassword = '1') ||
  8.                          (liPassword = '" . $unhashedpassword ."' AND UsedNewPassword = '0')) LIMIT 1