Advertisement
Guest User

Untitled

a guest
Jul 27th, 2017
64
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.40 KB | None | 0 0
  1. <?php
  2. $host="localhost"; // Host name
  3. $username="XXXX"; // Mysql username
  4. $password="XXXX"; // Mysql password
  5. $db_name="XXXX"; // Database name
  6. $tbl_name="members"; // Table name
  7.  
  8. // Connect to server and select databse.
  9. mysql_connect("$host", "$username", "$password")or die("cannot connect");
  10. mysql_select_db("$db_name")or die("cannot select DB");
  11.  
  12. // username and password sent from form
  13. $salt = "456as4s54gfjio3u43";
  14. $myusername=$_POST['myusername'];
  15. $mypassword=MD5(MD5($_POST['mypassword'] . $salt));
  16.  
  17. // To protect MySQL injection (more detail about MySQL injection)
  18. $myusername = stripslashes($myusername);
  19. $mypassword = stripslashes($mypassword);
  20. $myusername = mysql_real_escape_string($myusername);
  21. $mypassword = mysql_real_escape_string($mypassword);
  22.  
  23. $sql="SELECT * FROM $tbl_name WHERE username='$myusername' and password='$mypassword'";
  24. $result=mysql_query($sql);
  25. $row = mysql_fetch_array($result);
  26. // Mysql_num_row is counting table row
  27. $count=mysql_num_rows($result);
  28. // If result matched $myusername and $mypassword, table row must be 1 row
  29.  
  30. if($count==1){
  31. // Register $myusername, $mypassword and redirect to file "login_success.php"
  32. session_start();
  33. $_SESSION['userid'] = $row['id'];
  34. $_SESSION['loggedin'] = true;
  35. header("location:./cms");
  36. }
  37. else {
  38. header("location:index.php?error=1");
  39. }
  40. ?>
  41. <doctype>
  42. <html>
  43. <head>
  44. <title>
  45. </title>
  46. </head>
  47. <body>
  48. </body>
  49. </html>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement