Untitled
By: a guest | Mar 21st, 2010 | Syntax:
PHP | Size: 0.40 KB | Hits: 55 | Expires: Never
$username = mysql_real_escape_string($_POST['username']);
$unhashedpassword = mysql_real_escape_string($_POST['password']);
$hashedpassword = sha1($unhashedpassword);
$query = "SELECT * FROM staff
WHERE liUsername = '" . $username . "' AND
((liPassword = '" . $hashedpassword . "' AND UsedNewPassword = '1') ||
(liPassword = '" . $unhashedpassword ."' AND UsedNewPassword = '0')) LIMIT 1