Advertisement
Guest User

Untitled

a guest
May 30th, 2017
74
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.61 KB | None | 0 0
  1. <html>
  2. <body>
  3. <?php
  4. require_once("Config.php");
  5. /*
  6. Second modification.
  7. Please, for the love of all things nice, use tab spacing for indenting, not
  8. regular old spaces.
  9. */
  10. ob_start();
  11. if(!isset($_SESSION['ID'])){
  12. echo '<form action="logintest.php" method="post">
  13. Username:<input type="text" name="user" /><br />
  14. Password:<input type="password" name="pass" /><br />
  15. <input type="Submit" value="Login" />
  16. </form><br />'; //No need for 3 elots of echo. Speed issues, tiny, but they add up in long code.
  17. }
  18. $user = mysql_real_escape_string($_POST["user"]); // Just the simplest of *many* filters.
  19. $pass = md5($_POST["pass"]); // Make DataBase correspond, means you don't need any filtering, either.
  20. $result = mysql_query("SELECT Password FROM login WHERE Username = '$user'") or die('No such user');
  21. $row = mysql_fetch_assoc($result);
  22. $passtest = $row["Password"];
  23. if($row == false){
  24. echo "Incorrect Username or password<br />" ; // Don't want to be giving too much away, do we now?
  25. }
  26. else if($pass == $passtest){
  27. $login=true;
  28. echo "Logged In successfully"; // You won't see this...
  29. $query = mysql_query("SELECT * from login WHERE Username = '$user'") or die(mysql_error);
  30. $row = mysql_fetch_assoc($query);
  31. $status = $row["Status"];
  32. if($status == 1){
  33. // echo "<br />You are admin"; This won't even be seen!
  34. header("Location:admin.php");
  35. $_SESSION['ID'] = 1;
  36. }else{
  37. $_SESSION['ID'] = 0;
  38. header("Location:admin.php");
  39. }
  40. }else{
  41. echo "Incorrect Username or password<br />" ; // This is the reason for above.
  42. }
  43. mysql_close($con); // This should go in a config, too.
  44. ?>
  45. </body>
  46. </html>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement