Guest User

Untitled

a guest
Jun 8th, 2018
135
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
PHP 1.87 KB | None | 0 0
  1. <?php
  2. mysql_connect("localhost","root","");
  3. mysql_select_db("marktplaats");
  4. date_default_timezone_set("UTC");
  5. $time = strtotime('now');
  6. $expt = (strtotime('now'))+3600;
  7. //$_POST['key'] = "2cf1b5656a57e039943126394f1e76fa";
  8.  
  9. if(!isset($_POST['key'])){ // Uit te voeren bij login //
  10.     if(isset($_POST['user'])&&isset($_POST['pass'])){
  11.         $query = mysql_query("SELECT * FROM user WHERE USERNAME = '".$_POST['user']."' AND PASSWORD = '".$_POST['pass']."'")or die(mysql_error());
  12.         if($obj = mysql_fetch_object($query)){
  13.             $query = mysql_query("SELECT * FROM user WHERE USERNAME = '".$_POST['user']."' AND PASSWORD = '".$_POST['pass']."'")or die(mysql_error());
  14.             $obj = mysql_fetch_object($query);
  15.             $user = $_POST['user'];
  16.             $pass = $_POST['pass'];
  17.            
  18.             $key = md5(sha1($obj->ID.$obj->V_NAAM.$time));
  19.            
  20.             $authcheck = mysql_query("SELECT * FROM u_auth WHERE USER_ID = '".$obj->ID."'")or die(mysql_error());
  21.             if($authobj = mysql_fetch_object($authcheck)){
  22.                 $authquery = mysql_query("UPDATE u_auth SET u_auth.KEY = '".$key."', u_auth.EXP_TIME = '".$expt."' WHERE USER_ID = '".$obj->ID."'")or die(mysql_error());
  23.                 //$authquery = mysql_query("UPDATE u_auth SET EXP_TIME = '".$expt."' WHERE USER_ID = '".$obj->ID."'")or die(mysql_error());
  24.             }
  25.             else{
  26.                 $authquery = mysql_query("INSERT INTO u_auth VALUES ('".$obj->ID."', '".$key."', '".$expt."')")or die(mysql_error());
  27.             }
  28.             echo $key;
  29.         }
  30.         else{
  31.             echo "U_P_ERROR";
  32.         }
  33.        
  34.     }
  35.    
  36. }
  37. else{
  38.     $query = mysql_query("SELECT * FROM u_auth WHERE u_auth.KEY = '".$_POST['key']."'")or die(mysql_error());
  39.     if($authobj = mysql_fetch_object($query)){ // Als key = correct
  40.         if($time>=$authobj->EXP_TIME){//KEY NIET LEGIT
  41.             mysql_query("DELETE FROM u_auth WHERE u_auth.KEY = '".$_POST['key']."'")or die(mysql_error());
  42.             echo "K_ERROR";
  43.         }
  44.         else{
  45.             echo "TRUE";
  46.         }
  47.     }
  48.     else{
  49.         echo "K_ERROR";
  50.     }
  51. }
  52. ?>
Add Comment
Please, Sign In to add comment