$submit = $_POST['submit'];
$logout = $_POST['logout'];
$username = sanitize($_POST['Name']);
$password = sanitize($_POST['Password']);
$rawInput = sanitize($_POST["password"]);
$hashedInput = hash("md5", $rawInput);
if($submit)
{
if(!strcmp($password, $hashedInput))
{
if($username && $password)
{
$query = mysql_query("SELECT * FROM `players` WHERE `Name` = '$username' AND `Password` = '$password'");
if(mysql_num_rows($query) == 1)
{
while($row = mysql_fetch_assoc($query))
{
$dbusername = $row['Name'];
$dbpassword = $row['Password'];
}
if($username == $dbusername && $password == $dbpassword)
{
setcookie("Name", $dbusername, time()+60*60*24*365*20);
$_SESSION['Name'] = $dbusername;
header('Location: index.php');
}
else echo "<script>alert('You have to enter password!');</script>";
}
}
}
}
$query = mysql_query("SELECT * FROM `players` WHERE `Name` = '$username' AND password = md5('$password')"
PHP код:
|
$dbpassword = $row['Password'];
//password = md5($password);
if($submit)
{
if($username && $password)
{
$query = mysql_query("SELECT * FROM `players` WHERE `Name` = '$username' AND `Password` = '$password'");
if(mysql_num_rows($query) == 1)
{
while($row = mysql_fetch_assoc($query))
{
$dbusername = $row['Name'];
$dbpassword = $row['Password'];
//$dbpassword = md5($dbpassword);
}
if($username == $dbusername && $password == $dbpassword)
{
setcookie("Name", $dbusername, time()+60*60*24*365*20);
$_SESSION['Name'] = $dbusername;
header('Location: index.php');
}
else echo "<script>alert('You have to enter password!');</script>";
}
}
}