Advertisement
Guest User

Untitled

a guest
Sep 24th, 2017
72
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.50 KB | None | 0 0
  1. <?php
  2. /**
  3. * @author aulto - professionalcode.net
  4. * @copyright 2010
  5. */
  6.  
  7. //session_start();
  8.  
  9. function cleanuserinput($dirty)
  10. {
  11. if (get_magic_quotes_gpc())
  12. {
  13. $clean = mysql_real_escape_string(stripslashes($dirty));
  14. } else
  15. {
  16. $clean = mysql_real_escape_string($dirty);
  17. }
  18. return $clean;
  19. }
  20.  
  21. include 'conf_global.php';
  22.  
  23. //prefixo da sua tabela no IPB
  24. $prefix = 'ibf_';
  25.  
  26. if (isset($_POST['enviar']))
  27. {
  28. mysql_connect($INFO['sql_host'], $INFO['sql_user'], $INFO['sql_pass']);
  29. mysql_select_db($INFO['sql_database']);
  30. $user = cleanuserinput($_POST['user']);
  31. $pass = cleanuserinput($_POST['pass']);
  32. //echo 'Você inseriu o usuário ' . $user . ' e a senha ' . $pass . '!<br/>';
  33. $query1 = mysql_query("SELECT * FROM " . $prefix . "members WHERE name = '$user'") or
  34. die(mysql_error());
  35. $rs1 = mysql_fetch_object($query1);
  36. if (mysql_num_rows($query1) > 0)
  37. {
  38. $pSalt = $rs1->members_pass_salt;
  39. $finalPass = md5(md5($pSalt) . md5($pass));
  40. $query2 = mysql_query("SELECT * FROM " . $prefix . "members WHERE name like '$user' and members_pass_hash like '$finalPass'");
  41. $rs2 = mysql_fetch_object($query2);
  42. if (mysql_num_rows($query2) > 0)
  43. {
  44. //$_SESSION['logado_no_ipb'] = true;
  45. echo 'Logado com sucesso!';
  46. } else
  47. {
  48. echo 'Senha incorreta.';
  49. }
  50. } else
  51. {
  52. //echo 'Este login não existe!';
  53. }
  54. }
  55. ?>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement