Advertisement
Guest User

Untitled

a guest
May 11th, 2017
85
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
PHP 0.86 KB | None | 0 0
  1.     if(isset($_POST['login'])) {
  2.     $username = mysql_real_escape_string($_POST['username']);
  3.     $password = mysql_real_escape_string($_POST['password']);
  4.     $enc_password = hash('sha512', $password);
  5.     $q = "SELECT id, username, password, flag FROM user WHERE username='".mysql_real_escape_string($_POST['username'])."' AND password='".mysql_real_escape_string($enc_password)."'";
  6.         $res = mysql_query($q) or die(mysql_error());
  7.        
  8.         if(mysql_num_rows($res) < 1 && !empty($_POST['username']) && !empty($enc_password)) {
  9.             header('Location: user.php?loginerror=');
  10.             exit;
  11.         }
  12.        
  13.         while($row = mysql_fetch_array($res)) {
  14.        
  15.         $_SESSION['id']     = mysql_real_escape_string($row['id']);
  16.         $_SESSION['user']   = mysql_real_escape_string($row['username']);
  17.         $_SESSION['flag']   = mysql_real_escape_string($row['flag']);
  18.        
  19.             header('Location: user.php');
  20.             exit;
  21.         }
  22.     }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement