[php]
<?php
include "Header.php";
error_reporting(0);
$connect = mysql_connect("nottelling","nottelling","nottelling");
if (!$connect)
{
die('Could not connect: ' . mysql_error());
}
mysql_select_db("Mydatabase", $connect);
if (isset($_REQUEST['attempt']))
{
$username = mysql_real_escape_string(strip_tags(stripslashes($_POST['username'])));
$password = mysql_real_escape_string(strip_tags(stripslashes(sha1($_POST['password']))));
$username1 = $_GET['username'];
$query = mysql_query("SELECT username FROM Users WHERE username = '$username' AND password = '$password'") or die (mysql_error());
$total = mysql_num_rows($query);
if ($total > 0)
{
session_start();
mysql_query("UPDATE Users
SET Online=1
WHERE username='$username' AND password='$password'");
$_SESSION['username'] = $username1;
header('location: dashboard.php');
$result = mysql_query("SELECT * FROM Users");
$row = mysql_fetch_assoc($result());
$_SESSION['ban'] = $row['ban'] or die (mysql_error());
$_SESSION['user_level'] = $row['user_level']or die (mysql_error());
}
else
{
echo "
![]()
There Was An Error Please Try Again!
";
}
}
?>
Please Login
<?php
if(isset($_SESSION['username']))
{
echo "You are already logged in!";
}
else
{
// Not logged in
echo '
Username:
Password:
Login!
';
}
?>
<?php
include “Footer.php”;
?>
[/php]