Advertisement
Guest User

Untitled

a guest
Jun 13th, 2016
84
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.32 KB | None | 0 0
  1. <?php
  2. session_start();
  3. require_once('./inc/mysql_connection.php');
  4. if(isset($_POST['uname']) && isset($_POST['pword'])){
  5. $username=$_POST['uname'];
  6. $password=$_POST['pword'];
  7. $qry="SELECT * FROM tbl_users WHERE username='$username';";
  8. $result=mysql_query($qry);
  9. $max = 5;
  10. if($result){
  11. if(mysql_num_rows($result)==1){
  12. $row = mysql_fetch_array($result);
  13. session_regenerate_id();
  14. $_SESSION['loginID'] = $row['id'];
  15. $_SESSION['username'] =$row['username'];
  16. $retries = $row['retries'];
  17.  
  18.  
  19. if($retries < 5){
  20. if($password == $row['pwd']){
  21. mysql_query("UPDATE tbl_users SET retries = 0 WHERE username = 'admin'");
  22. header("location:home.php");
  23. }
  24. else{
  25.  
  26. $_SESSION['errmsg'] = "Incorrect Password! <br /> Retries left: ". ($max - ($retries + 1));
  27. header('location:login.php');
  28. mysql_query("UPDATE tbl_users SET retries = retries + 1 WHERE username = 'admin'");
  29. }
  30. }else{
  31. $_SESSION['errmsg'] = "Account Locked!<br /> Maximum retries has been reached!";
  32. header('location:login.php');
  33.  
  34. }
  35.  
  36. }else{
  37. $_SESSION['errmsg'] = "User does not exist!";
  38. header('location:login.php');
  39. }
  40.  
  41. }else{
  42. die(mysql_error());
  43. }
  44.  
  45. }else{
  46. header('localhost:login.php');
  47. }
  48.  
  49.  
  50. ?>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement