Advertisement
Guest User

Untitled

a guest
Jan 9th, 2017
96
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.39 KB | None | 0 0
  1. <?php
  2. require_once "connect.php";
  3.  
  4. $link = @new mysqli($host,$db_user,$db_password,$db_name);
  5.  
  6. foreach ($_POST as $k=>$v) {$_POST[$k] = mysqli_real_escape_string($link, $v);}
  7. foreach ($_SERVER as $k=>$v) {$_SERVER[$k] = mysqli_real_escape_string($link, $v);}
  8. if($link->connect_errno == 0){
  9. if (isset($_POST['login'])){
  10.  
  11. $q = mysqli_fetch_assoc( mysqli_query($link, "select count(*) cnt, id_user, id_user_type, user_name, user_surname, id_user_type from user where login='{$_POST['login']}' and password ='{$_POST['haslo']}'"));
  12. if ($q['cnt']){
  13. $id = md5(rand(-10000,10000) . microtime()) . md5(crc32(microtime()) . $_SERVER['REMOTE_ADDR']);
  14. $token = rand(-1000,1000);
  15. mysqli_query($link, "delete from session where ID_user = '$q[id_user]';");
  16. mysqli_query($link, "
  17. insert into session (ID_user, id_user_type, id, ip, web,imie,nazwisko,time,token) values
  18. ('$q[id_user]','$q[id_user_type]','$id','$_SERVER[REMOTE_ADDR]','$_SERVER[HTTP_USER_AGENT]','$q[user_name]','$q[user_surname]', CURRENT_TIMESTAMP, '$token')");
  19. if (! mysqli_errno($link)){
  20. setcookie("id", $id);
  21. setcookie("token", $token);
  22. header("location:index.php");
  23. } else {echo "błąd podczas logowania!";}
  24.  
  25. } else {
  26. header("location: index.php");
  27. setcookie("login_error", true);
  28. }
  29. }else{
  30. header("location: index.php");
  31. }
  32. }
  33. ?>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement