<html> <head><title>Balkan Underground UCP</title></head> <body> <form action="login.php" method="post"> <table align="center"> <tr> <td align="center"> <b><font size="4" color="#000080">Balkan Underground UCP</font></b> </td> </tr> <tr align="center"> <td> <p><input type="text" name="User" size="20" /></p> <p><input type="password" name="Password" size="20" /></p> </td> </tr> <tr> <td align="center"> <p><input type="submit" /> <input type="reset" /> </p> </td> </tr> </table> </form> </body> </html>
<?php
$con = mysql_connect("localhost","testuser","*********");
mysql_select_db("testuser");
?>
<?php
include("connect.php");
session_start();
if (!$con)
{
die('Could not connect: ' . mysql_error());
}
if(isset($_SESSION["Username"]))
{
$user = $_SESSION["Username"];
$pass = $_SESSION["Password"];
}
else
{
$user = $_POST["User"];
$pass = $_POST["Password"];
$_SESSION['Username'] = $user;
$_SESSION['Password'] = $pass;
$escuser = mysql_real_escape_string($user);
$escpass = mysql_real_escape_string($pass);
}
$query = "SELECT * FROM users WHERE pUsername = '$escuser'";
$result = mysql_query($query);
$username_exist = mysql_num_rows($result);
if($username_exist == 0)
{
echo 'That profile does not exist! <br />';
echo '<a href="index.php">Idi nazad</a>';
unset($_SESSION['Username']);
unset($_SESSION['Password']);
die;
}
$row = mysql_fetch_row($result);
if($row[2] !== $escpass)
{
echo 'Password is not valid! <br />';
echo '<a href="index.php">Idi nazad</a>';
unset($_SESSION['Username']);
unset($_SESSION['Password']);
die;
}
$message = "Welcome $escuser!<br />";
echo $message;
echo "<br />";
echo "
<table border = 1>
<tr>
<td>Level</td>
<td>$row[7]</td>
</tr>
<tr>
<td>Expirience</td>
<td>$row[8]</td>
</tr>
<tr>
<td>Hours Played</td>
<td>$row[9]</td>
</tr>
<tr>
<td>Money</td>
<td>$$row[10]</td>
</tr>
<tr>
<td>Bank</td>
<td>$$row[11]</td>
</tr>
</table>";
?>
function sanitizeString($var){
$var = stripslashes($var);
$var = htmlentities($var);
$var = strip_tags($var);
return $var;
}
function sanitizeSQL($var){
$var = mysql_real_escape_string($var);
$var = sanitizeString($var);
return $var;
}
$Salt1 = "#$@#%#$!@$@#1234223233";
$Salt2 = "#*$(#@$&AJDSU#341224334";
$Hash = md5("$Salt1$password$Salt2");

|
Can you please post all files by compressing them in a .rar or .zip and upload and share? or you just want help in coding that for you created topic?
|
|
this is not released yet to be used by the public, i've opened this topic to get usefull info about better security than the one that has been implemented in the curent script
|