<?php
ob_start();
$host="localhost"; // Host name
$username="root"; // Mysql username
$password=""; // Mysql password
$db_name="intranet"; // Database name
$tbl_name="employee"; // Table name
// Connect to server and select databse.
mysql_connect("$host", "$username", "$password")or die("cannot connect");
mysql_select_db("$db_name")or die("cannot select DB");
// Define $myusername and $mypassword
$salt = '~Z`!@#$%I^&*()_-+Q=}]{[\|"><';
$myusername = $_POST['txtunamea'];
$mypassword = $_POST['txtpassa'];
$encryptpass = hash('sha512', $mypassword . $salt);
//$sql = "SELECT * FROM $tbl_name WHERE uname = '$myusername' AND upass = '$mypassword')";
$sql= "SELECT * FROM employee WHERE uname='$username' and pswrd='$encryptpass'";
$result=mysql_query($sql);
$count=mysql_num_rows($result);
if($count==1){
echo "correct Username or Password";
}
else {
echo "$mypassword<br />";
echo $encryptpass;
echo $count;
echo "Wrong Username or Password";
}
ob_end_flush();
?>
a thanks wouldnt be bad but here it is
remember, google is your friend
Code:<?php ob_start(); $host="localhost"; // Host name $username="root"; // Mysql username $password=""; // Mysql password $db_name="intranet"; // Database name $tbl_name="employee"; // Table name // Connect to server and select databse. mysql_connect("$host", "$username", "$password")or die("cannot connect"); mysql_select_db("$db_name")or die("cannot select DB"); // Define $myusername and $mypassword $salt = '~Z`!@#$%I^&*()_-+Q=}]{[\|"><'; $myusername = $_POST['txtunamea']; $mypassword = $_POST['txtpassa']; $encryptpass = hash('sha512', $mypassword . $salt); //$sql = "SELECT * FROM $tbl_name WHERE uname = '$myusername' AND upass = '$mypassword')"; $sql= "SELECT * FROM employee WHERE uname='$username' and pswrd='$encryptpass'"; $result=mysql_query($sql); $count=mysql_num_rows($result); if($count==1){ echo "correct Username or Password"; } else { echo "$mypassword<br />"; echo $encryptpass; echo $count; echo "Wrong Username or Password"; } ob_end_flush(); ?>