August 17, 201115 yr http://www.bkwebdesignandhosting.co.uk/project/ please check out that link sign up, and then go to log in, when you log in, you get an error, however, if you go back to homeepage you are loggd in ok! so must be something wrong with this <?php /* Created By Adam Khoury @ www.flashbuilding.com -----------------------June 20, 2008----------------------- */ if ($_POST['email']) { //Connect to the database through our include include_once "connect_to_mysql.php"; $email = stripslashes($_POST['email']); $email = strip_tags($email); $email = mysql_real_escape_string($email); $password = ereg_replace("[^A-Za-z0-9]", "", $_POST['password']); // filter everything but numbers and letters $password = md5($password); // Make query and then register all database data that - // cannot be changed by member into SESSION variables. // Data that you want member to be able to change - // should never be set into a SESSION variable. $sql = mysql_query("SELECT * FROM members WHERE email='$email' AND password='$password' AND emailactivated='1'"); $login_check = mysql_num_rows($sql); if($login_check > 0){ while($row = mysql_fetch_array($sql)){ // Get member ID into a session variable $id = $row["id"]; session_register('id'); $_SESSION['id'] = $id; // Get member username into a session variable $username = $row["username"]; session_register('username'); $_SESSION['username'] = $username; // Update last_log_date field for this member now mysql_query("UPDATE members SET lastlogin=now() WHERE id='$id'"); // Print success message here if all went well then exit the script header("location: index.php"); exit(); } // close while } else { // Print login failure message to the user and link them back to your login page print '<br /><br /><font color="#FF0000">No match in our records, try again </font><br /> <br /><a href="login.php">Click here</a> to go back to the login page.'; exit(); } }// close if post ?> help please +1s once this bit is done, i can code this into a template, then create an admin section for a client to check all the customers who have signed up and stuff. gunna be a wicked project for me once finished woo Edited August 17, 201115 yr by kingy da killa
August 17, 201115 yr pretty please help to use SESSION anything you need to start a session put session_start(); after your php opening tag right at the top of the page like <?php session_start(); the session_start(); must go before any other session statement and it must go before anything is echoed same with the header(); headers should be sent out before you echo anything
August 17, 201115 yr pretty please help Curious is this someone elses script? and also session_register is DEPRECATED as of php version 5.3.0 /* Created By Adam Khoury @ www.flashbuilding.com -----------------------June 20, 2008----------------------- Edited August 18, 201115 yr by webdesigner93
August 18, 201115 yr http://www.bkwebdesignandhosting.co.uk/project/ please check out that link sign up, and then go to log in, when you log in, you get an error, however, if you go back to homeepage you are loggd in ok! so must be something wrong with this <?php /* Created By Adam Khoury @ www.flashbuilding.com -----------------------June 20, 2008----------------------- */ if ($_POST['email']) { //Connect to the database through our include include_once "connect_to_mysql.php"; $email = stripslashes($_POST['email']); $email = strip_tags($email); $email = mysql_real_escape_string($email); $password = ereg_replace("[^A-Za-z0-9]", "", $_POST['password']); // filter everything but numbers and letters $password = md5($password); // Make query and then register all database data that - // cannot be changed by member into SESSION variables. // Data that you want member to be able to change - // should never be set into a SESSION variable. $sql = mysql_query("SELECT * FROM members WHERE email='$email' AND password='$password' AND emailactivated='1'"); $login_check = mysql_num_rows($sql); if($login_check > 0){ while($row = mysql_fetch_array($sql)){ // Get member ID into a session variable $id = $row["id"]; session_register('id'); $_SESSION['id'] = $id; // Get member username into a session variable $username = $row["username"]; session_register('username'); $_SESSION['username'] = $username; // Update last_log_date field for this member now mysql_query("UPDATE members SET lastlogin=now() WHERE id='$id'"); // Print success message here if all went well then exit the script header("location: index.php"); exit(); } // close while } else { // Print login failure message to the user and link them back to your login page print '<br /><br /><font color="#FF0000">No match in our records, try again </font><br /> <br /><a href="login.php">Click here</a> to go back to the login page.'; exit(); } }// close if post ?> help please +1s once this bit is done, i can code this into a template, then create an admin section for a client to check all the customers who have signed up and stuff. gunna be a wicked project for me once finished woo Just a side note, You posted this script on behalf of "www.flashbuilding.com", If you use this, I now know how to hijack the sessions. You created yourself another security risk posting the domain name and not only that, People on Google will also see.
August 18, 201115 yr Just a side note, You posted this script on behalf of "www.flashbuilding.com", If you use this, I now know how to hijack the sessions. You created yourself another security risk posting the domain name and not only that, People on Google will also see. www.flashbuilding.com is not his site
August 18, 201115 yr www.flashbuilding.com is not his site Good, At least we know the owner of that website is an utter idiot.
August 18, 201115 yr Good, At least we know the owner of that website is an utter idiot. Nah actually hes very smart lol that code does not run flashbuilding.com its part of the owners social network software called webintersect i'd talked to the guy a few times
Create an account or sign in to comment