Guest User

Untitled

a guest
Jan 4th, 2018
139
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.46 KB | None | 0 0
  1. /* I hope you can help,
  2. this is what i have for my login form, and now my passwords have been hashed, and i've been told to add: */
  3.  
  4. "
  5. $passToCheck = 'something';
  6. $correctMD5 = (retrieve hash from db)
  7. if($salt.$passToCheck.$pepper == $correctMD5)
  8. {
  9. //valid login
  10. } else {
  11. //login failure
  12. }
  13. "
  14. // but i don't know where about to put it, can you help me,
  15.  
  16.  
  17. <?php // login.php
  18. include_once 'header.php';
  19. echo "<h3>Member Log in</h3>";
  20. $error = $user = $pass = "";
  21.  
  22. if (isset($_POST['user']))
  23. {
  24. $user = sanitizeString($_POST['user']);
  25. $pass = sanitizeString($_POST['pass']);
  26. $passToCheck = '$pass';
  27.  
  28.  
  29.  
  30.  
  31. if ($user == "" || $pass == "")
  32. {
  33. $error = "Not all fields were entered<br />";
  34. }
  35. else
  36. {
  37. $query = "SELECT user,pass FROM members
  38. WHERE user='$user' AND pass='$pass'";
  39.  
  40.  
  41.  
  42.  
  43. if (mysql_num_rows(queryMysql($query)) == 0)
  44. {
  45. $error = "Username/Password invalid<br />";
  46. }
  47. else
  48. {
  49. $_SESSION['user'] = $user;
  50. $_SESSION['pass'] = $pass;
  51. die("You are now logged in. Please
  52. <a href='members.php?view=$user'>click here</a>.");
  53. }
  54. }
  55. }
  56.  
  57. echo <<<_END
  58. <form method='post' action='login.php'>$error
  59. Username <input type='text' maxlength='16' name='user'
  60. value='$user' /><br />
  61. Password <input type='password' maxlength='16' name='pass'
  62. value='$pass' /><br />
  63. &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;
  64. <input type='submit' value='Login' />
  65. </form>
  66. _END;
  67. ?>
Add Comment
Please, Sign In to add comment