Guest User

laddu_1

a guest
Sep 14th, 2017
34
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
PHP 2.49 KB | None | 0 0
  1. <?php
  2. $usernameVal=$_REQUEST['username'];
  3. //$passwordVAl=$_REQUEST["password"];
  4.  
  5. $servername = "localhost";
  6. $username = "root";
  7. $password = "";
  8. $dbname = "usertest_db";
  9.  
  10. // Create connection
  11. $conn = new mysqli($servername, $username, $password, $dbname);
  12. // Check connection
  13. if ($conn->connect_error) {
  14.     die("Connection failed: " . $conn->connect_error);
  15. }
  16. else
  17. {
  18.  
  19.      $escapedPW = mysqli_real_escape_string($conn,$_REQUEST['password']);
  20.  
  21.      //save this user and pass as cookie if remeber checked start
  22.       if (isset($_REQUEST['remember']))
  23.    $escapedRemember = mysqli_real_escape_string($conn,$_REQUEST['remember']);
  24.  
  25.  $cookie_time = 60 * 60 * 24 * 30; // 30 days
  26.   $cookie_time_Onset=$cookie_time+ time();
  27.   if (isset($escapedRemember)) {
  28.     /*
  29.      * Set Cookie from here for one hour
  30.      * */
  31.     setcookie("username", $usernameVal, $cookie_time_Onset);
  32.     setcookie("password", $escapedPW, $cookie_time_Onset);  
  33.  
  34.   } else {
  35.  
  36.       $cookie_time_fromOffset=time() -$cookie_time;
  37. setcookie("username", '',$cookie_time_fromOffset );
  38.     setcookie("password", '', $cookie_time_fromOffset);  
  39.  
  40.   }
  41.   //save this user and pass as cookie if remember checked end
  42.      
  43. //now check user and pass verification
  44.  $query = "select * from user where username = '$usernameVal';";
  45.  
  46.      $resultSet = mysqli_query($conn,$query);
  47.  
  48.                            if(@mysqli_num_rows($resultSet) > 0){
  49.                            //check noraml user salt and pass
  50.                            //echo "noraml";
  51.                            
  52.  $saltQuery = "select salt from user where username = '$usernameVal';";
  53. $result = mysqli_query($conn,$saltQuery);
  54. $row = mysqli_fetch_assoc($result);
  55. $salt = $row['salt'];
  56.  
  57. $saltedPW =  $escapedPW . $salt;
  58.  
  59. $hashedPW = hash('sha256', $saltedPW);
  60.  
  61.  $query = "select * from user where username = '$usernameVal'
  62. and password = '$hashedPW' ";
  63.                        
  64.                             $resultSet = mysqli_query($conn,$query);
  65.                               if(@mysqli_num_rows($resultSet) > 0){
  66.                                $row = mysqli_fetch_assoc($resultSet);
  67.                                echo "your username and  password is corrent";
  68.                                session_start();
  69.                                $_SESSION["user_id"]=$row["user_id"];
  70.                                $_SESSION["user_name"]=$row["username"];
  71. //header("location:index.php");
  72. }
  73. else
  74. {
  75. echo "your username or password is incorrect";
  76. }
  77.  
  78. }
  79.      
  80. }
  81. ?>
Add Comment
Please, Sign In to add comment