
Untitled
By: a guest on
May 4th, 2012 | syntax:
None | size: 1.32 KB | hits: 11 | expires: Never
<?PHP
//=================================================>
if (isset($_POST[USERNAME]) && $_POST[LOGIN] == 1) {
$username = $_POST[USERNAME];
$password = $_POST[PASSWORD];
}
else {
$username = $_SESSION[username];
$password = $_SESSION[password];
}
//===================================>
$SQL = "SELECT * from USERS
WHERE USERNAME = '$username' $authcommands";
$result = @mysql_query( $SQL );
$row = @mysql_fetch_array( $result );
//=============================================>
if ($username == $row[USERNAME])
$usercheck = tru;
if ($password == $row[PASSWORD])
$passcheck = tru;
if (empty($username))
$passcheck = fail;
if ($usercheck == tru && $passcheck == tru)
$login = pass;
else
$login = fail;
//===================>
if ($login == pass) {
$_SESSION['username'] = "$row[USERNAME]";
$_SESSION['password'] = "$row[PASSWORD]";
$_SESSION['isadmin'] = "$row[STATUS]";
$_SESSION['cid'] = "$row[ID]";
}
if ($login == fail) {
if (empty($_POST)) {
}
else
include "user_notfound.php";
if ($_REQUEST[login_form]) die("RFI Blocked.");
require "$login_form"; if ($authcommands != $nil) die();
}
?>