Guest User

Untitled

a guest
Nov 26th, 2017
106
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.82 KB | None | 0 0
  1. <?php
  2. mysql_connect("localhost","root","Blhbbccm4650");
  3. mysql_select_db("forums") or die(mysql_error());
  4. function antisql($dirty){
  5. if (get_magic_quotes_gpc()) {
  6. $clean = mysql_real_escape_string(stripslashes($dirty));
  7. }else{
  8. $clean = mysql_real_escape_string($dirty);
  9. }
  10. return $clean;
  11. }
  12. $username = $_POST['username'];
  13. $username = antisql($username);
  14. $password = $_POST['password'];
  15. $password = antisql($password);
  16.  
  17. $salt = mysql_fetch_array(mysql_query("SELECT salt FROM user WHERE username='$username'"));
  18. $salt = $salt['0'];
  19. $hash = md5(md5($password) . $salt);
  20. $password_hash = mysql_fetch_array(mysql_query("SELECT password FROM user WHERE username='$username'"));
  21. $password_hash = $password_hash['0'];
  22.  
  23. if($hash == $password_hash){
  24. echo "yes";
  25. $_SESSION['nulluser'] = $username;
  26. }
  27. ?>
Add Comment
Please, Sign In to add comment