Guest User

Untitled

a guest
Nov 4th, 2017
104
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.81 KB | None | 0 0
  1. $user = $_POST['user']; //sql injection protection
  2. $user = trim($user);
  3. $user = strip_tags($user);
  4. $user = htmlspecialchars($user);
  5.  
  6. $pass = $_POST['pass'];
  7. $pass = trim($pass);
  8. $pass = strip_tags($pass);
  9. $pass = htmlspecialchars($pass);
  10. $pass = hash('sha512', $pass);
  11.  
  12. $sql = "SELECT id, user, pass FROM kerb_users WHERE user='".$user."' AND pass='".$pass."'";
  13. $query = mysqli_query($con, $sql);
  14.  
  15. if($row = mysqli_fetch_array($sql)) {
  16. $_SESSION['id'] = $row['id'];
  17. $_SESSION['user'] = $row["user"];
  18. header("Location: ./index.php");
  19. } else {
  20. echo "Incorrect credentials, <a href='javascript:history.back();'>try again.</a>";
  21. }
  22. }
  23. }else {
  24. header("Location: index.php");
  25. }
Add Comment
Please, Sign In to add comment