And please use code tags..
Regards
Dheeraj Joshi
Regards
Dheeraj Joshi
session_start();
$username = isset($_POST['username']) ? $_POST['username'] : NULL;
$password = isset($_POST['password']) ? $_POST['password'] : NULL;
$sql = "SELECT salt, pass_hash FROM users WHERE username = '%s'";
$sql = sprintf( $sql, mysql_real_escape_string($username) );
$result = mysql_query( $sql );
if (!mysql_num_rows($result)) {
/* incorrect username */
} else {
$row = mysql_fetch_row($result);
$pass_hash = pack( "H*", md5($password . $row[0]) );
if ( strcmp($pass_hash, $row[1]) === 0 ) {
$_SESSION['username'] = $username;
header("Location: account.php");
exit;
} else {
/* Incorrect password */
}
}
$pass_salt = md5 ( $pass . $salt, true );
$salt = md5(uniqid(mt_rand(), true), true);
Comment