Advertisement
Guest User

Untitled

a guest
Sep 4th, 2017
86
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 3.85 KB | None | 0 0
  1. <form action="main_login.php" method="post" style="text-align:right;">
  2. Username:
  3. <input type="text" name="username" value="" size=20 style="display:inline-block;margin-left:10px"required>
  4. <br>
  5. Password:
  6. <input type="password" name="password" value="" size=20 style="margin-left:12px"required>
  7. <br>
  8. <input type="submit" value="Log In" style="margin-left:75px"=>
  9. </form>
  10.  
  11. <?php
  12. session_start();
  13. $con = mysqli_connect("localhost", "root", "", "complaints");
  14. if (!$con) {
  15. die('Could not connect: ' . mysql_error());
  16. }
  17. $myusername=$_POST["username"];
  18. $mypassword=$_POST["password"];
  19. echo $myusername . "<br>";
  20. echo $mypassword . "<br>";
  21.  
  22.  
  23.  
  24. // MySQL injection
  25. $myusername = stripslashes($myusername);
  26. $mypassword = stripslashes($mypassword);
  27. $myusername = mysql_real_escape_string($myusername);
  28. $mypassword = mysql_real_escape_string($mypassword);
  29. $sql="SELECT * FROM register WHERE username='$myusername' and password='$mypassword'";
  30. $result=mysqli_query($con,$sql);
  31. // Mysql_num_row is counting table row
  32. $count=mysqli_num_rows($result);
  33. // If result matched $myusername and $mypassword, table row must be 1 row
  34. if($count==1){
  35. // Register $myusername, $mypassword and redirect to file "login_success.php"
  36. $_SESSION['username']=$myusername;
  37. $_SESSION['password']=$mypassword;
  38. header("location:login_success.php");
  39. }
  40. else {
  41. echo "Wrong Username or Password";
  42. }
  43. mysqli_close($con);
  44. ?>
  45.  
  46. <?php
  47. session_start();
  48. if ( isset( $_SESSION['username'] ) ){
  49. header("location:main_login.php");
  50. }
  51. ?>
  52.  
  53. <html>
  54. <body>
  55. Login Successful
  56. </body>
  57. </html>
  58.  
  59. $myusername=$_POST["username"];
  60. $mypassword=$_POST["password"];
  61.  
  62. $myusername=$_POST["username"];
  63. $mypassword=$_POST["password"];
  64.  
  65. $myusername = mysql_real_escape_string($myusername);
  66. $mypassword = mysql_real_escape_string($mypassword);
  67.  
  68. $myusername = mysqli_real_escape_string($con,$myusername);
  69. $mypassword = mysqli_real_escape_string($con,$mypassword);
  70.  
  71. $myusername = mysqli_real_escape_string($con,$_POST['username']);
  72. $mypassword = mysqli_real_escape_string($con,$_POST['password']);
  73.  
  74. header("location:login_success.php");
  75. exit;
  76.  
  77. $myusername=$_POST["username"];
  78. $mypassword=$_POST["password"];
  79. echo $myusername . "<br>";
  80. echo $mypassword . "<br>";
  81.  
  82. $myusername = stripslashes($_POST["username"]);
  83. $mypassword = stripslashes($_POST["password"]);
  84. $myusername = mysqli_real_escape_string($con,$_POST['username']);
  85. $mypassword = mysqli_real_escape_string($con,$_POST['password']);
  86.  
  87. <form action="main_login.php" method="post" style="text-align:right;">
  88. Username:
  89. <input type="text" name="username" value="" size=20 style="display:inline-block;margin-left:10px"required>
  90. <br>
  91. Password:
  92. <input type="text" name="password" value="" size=20 style="margin-left:12px"required>
  93. <br>
  94. <input type="submit" value="Log In" style="margin-left:75px"=>
  95. </form>
  96.  
  97. <?php
  98.  
  99. $DB_HOST = 'xxx';
  100. $DB_USER = 'xxx';
  101. $DB_PASS = 'xxx';
  102. $DB_NAME = 'xxx';
  103.  
  104. $conn = new mysqli($DB_HOST, $DB_USER, $DB_PASS, $DB_NAME);
  105. if($conn->connect_errno > 0) {
  106. die('Connection failed [' . $conn->connect_error . ']');
  107. }
  108.  
  109. $myusername = stripslashes($_POST["username"]);
  110. $mypassword = stripslashes($_POST["password"]);
  111. $myusername = mysqli_real_escape_string($conn,$_POST['username']);
  112. $mypassword = mysqli_real_escape_string($conn,$_POST['password']);
  113.  
  114.  
  115. echo $myusername; // echos
  116. echo "<br>";
  117. echo $mypassword; // echos
  118.  
  119.  
  120. $sql="SELECT * FROM register WHERE username='$myusername' and password='$mypassword'";
  121. $result=mysqli_query($conn,$sql);
  122.  
  123. $count=mysqli_num_rows($result);
  124.  
  125. if($count==1){
  126. echo "Yep";
  127. }
  128. else{
  129. echo "nope";
  130. }
  131.  
  132. <?php
  133. session_start();
  134.  
  135. <?php session_start();
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement