Guest User

laddu_1

a guest
Sep 30th, 2017
62
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
PHP 2.55 KB | None | 0 0
  1. <?php
  2. //require 'config.php';
  3. //$usernameVal=$_REQUEST['email'];
  4. //$passwordVAl=$_REQUEST["password"];
  5.  
  6.  
  7. if(isset($_POST['login'])) {
  8.   $usernameVal=$_REQUEST['username'];
  9.   $escapedPW = $_REQUEST['password'];
  10.  
  11.  
  12.  
  13.  
  14.      //$escapedPW = mysqli_real_escape_string($con,$_REQUEST['password']);
  15.  
  16.      //save this user and pass as cookie if remeber checked start
  17.       if (isset($_REQUEST['remember']))
  18.    $escapedRemember = mysqli_real_escape_string($con,$_REQUEST['remember']);
  19.  
  20.  $cookie_time = 60 * 60 * 24 * 30; // 30 days
  21.   $cookie_time_Onset=$cookie_time+ time();
  22.   if (isset($escapedRemember)) {
  23.     /*
  24.      * Set Cookie from here for one hour
  25.      * */
  26.     setcookie("username", $usernameVal, $cookie_time_Onset);
  27.     setcookie("password", $escapedPW, $cookie_time_Onset);  
  28.  
  29.   } else { $cookie_time_fromOffset=time() -$cookie_time;
  30. setcookie("username", '',$cookie_time_fromOffset );
  31.     setcookie("password", '', $cookie_time_fromOffset);  
  32.  
  33.   }
  34.   //save this user and pass as cookie if remember checked end
  35.      
  36. //now check user and pass verification
  37.  $query = "select * from users where username = '$usernameVal'";
  38.  
  39.      $resultSet = mysqli_query($con,$query);
  40.  
  41.                            if(@mysqli_num_rows($resultSet) > 0){
  42.                            //check noraml user salt and pass
  43. $saltQuery = "select salt from users where username = '$usernameVal';";
  44. $result = mysqli_query($con,$saltQuery);
  45. $row = mysqli_fetch_assoc($result);
  46. $salt = $row['salt'];
  47.  
  48. $saltedPW =  $escapedPW . $salt;
  49.  
  50. $hashedPW = hash('sha256', $saltedPW);
  51.  
  52.  $query = "select * from users where username = '$usernameVal' and password = '$hashedPW' ";
  53.   $resultSet = mysqli_query($con,$query);
  54.                               if(@mysqli_num_rows($resultSet) > 0){
  55.                                $row = mysqli_fetch_assoc($resultSet);
  56.                                echo "your username and  password is corrent";
  57.                                $name=$row["firstname"];
  58.                                echo $name;
  59.                                //echo $firstname;
  60.                                //session_start();
  61.                               // $_SESSION["user_id"]=$row["user_id"];
  62.                                $_SESSION["username"]=$row["username"];
  63.                                $_SESSION["email"] =$row["email"];
  64.                                header("location:indexfb.php");
  65.                                exit();
  66. //header("location:index.php");
  67. }
  68. else
  69. {
  70. echo "your username or password is incorrect";
  71. }
  72.  
  73. }
  74.      
  75. }
  76. ?>
Add Comment
Please, Sign In to add comment