Jump to content


  • Posts

  • Joined

  • Last visited

  • Days Won


Posts posted by davidannis

  1. If what you want is the date to role over at midnight I think you mean:

      if($time1[1] == "PM")
    if ($hours==12){
         $date = date_create();//default is now I think
         date_modify($date, '+1 day'); // adds 1 day if it is midnight
         $time1[0] = date_format($date, 'Y-m-d') . ((int)($hours) + 12) . $minutes . "00";
        $time1[0] = date("Ymd") . ((int)($hours) + 12) . $minutes . "00";

    not sure why it wouldn't roll over on its own.

  2. Warning: mysql_real_escape_string() expects parameter 2 to be resource, string given in E:\Inetpub\wwwroot\php\home\includes\login.php on line 4

    That's because the syntax is different between mysql_real_escape_string http://nz2.php.net/manual/en/function.mysql-real-escape-string.php and mysqli_real_escape_string


    string mysql_real_escape_string ( string $unescaped_string [, resource $link_identifier = NULL ] )




    string mysqli_real_escape_string ( mysqli $link , string $escapestr )

    notice that the link is first in one and last in the other. If this is a class assignment and will never go live, you can probably dispense with the security (though its bad practice) and just forget about sanitizing data.




    Oh and also, when I enter an unregistered username and password, the error doesn't display? Is there anyway to show that too?

    		$result = mysql_query($query) or die(mysql_error());
    		$number_users = mysqli_num_rows($result );
    if ($number_users==0){echo ' no such user';}
    		$row = mysql_fetch_array($result);
    		if ($row['user_password'] == $_POST['lipassword'] && $row['user_password']!='') {
    			$_SESSION['loggedin'] = true;
    			$_SESSION['id'] = $row['user_id'];		
    			$_SESSION['username'] = $_POST['liusername'];
    		} else {
    			echo 'username and password don't match';
    			$_SESSION['loggedin'] = false;
    			$_SESSION['id'] = 0;
  3. First, use mysqli, not mysql which is deprecated (no longer going to be supported, updated)

    To clean up input data use mysqli_real_escape_string();

    To check whether a user exists, make sure that a row gets returned:

    	if (isset($_POST['lisubmit'])){
    		$liusername=mysqli_real_escape_string($dblink,$_POST['liusername']);// Note I'm using mysqli here. Can't mix and match. You need to change the rest of your code to do the same or change my function to mysql.
    		$query = "SELECT user_id, user_password FROM user WHERE user_username = '$liusername'";  // Select details from user table
    		$result = mysql_query($query) or die(mysql_error());
    		$row = mysql_fetch_array($result);
    		if ($row['user_password'] == $_POST['lipassword'] && $row['user_password']!='') {
    			$_SESSION['loggedin'] = true;
    			$_SESSION['id'] = $row['user_id'];		
    			$_SESSION['username'] = $_POST['liusername'];
    		} else {
    			$_SESSION['loggedin'] = false;
    			$_SESSION['id'] = 0;

    There are a lot of ways to check that the user exists. If not, $ row will be empty. I did a not so elegant check by adding a check to make sure that the password returned in $ row was not blank but you could use mysqli_num_rows() for a more elegant check that a row is being returned.

  4. I'm not sure that I understand the question, but I think what you want is:

    echo '<ul class=...."';//note outside while loop
    while($company = mysql_fetch_array($query)) {
    echo "<li> <a href=\"#\" >" . $company['t1'] ." </li></a>\n";
    echo '</ul>';//note outside while loop
  5. The line

    $QueryResult = @mysql_query($SQLstring, $DBConnect); 

    suppresses error messages from the query http://www.php.net/manual/en/language.operators.errorcontrol.php As a general rule suppressing errors is not a good idea so get rid of the @

    Then, the next line gives an error because $QueryResult contains false.

    To see the error when the query fails try:

    $QueryResult = mysql_query($SQLstring, $DBConnect) or die (mysql_error($DBConnect)); 

    http://www.php.net/manual/en/function.mysql-error.php which will print the error that caused your query to fail then stop.

  6. Some questions take time to get answered. The answer is yes, someone can make your site load malware if they can control the URL in your IMG tag.


    Embedded HTML Tags
    Several HTML tags possess attributes that initiate Web browser HTTP requests automatically upon page load. An
    example is the IMG (image) tag and SRC attribute. The SRC attribute is used to specify the URL location of image files
    for display in Web pages. When your browser loads Web pages with IMG tags, the images are automatically requested
    and appear within the browser. But, the SRC attribute can also be used to reference URLs, from any Web server, not
    only those containing images.
    For instance, if we performed a Google search for “WhiteHat Security” we’d end up with the following URL:
    This URL could be easily substituted inside the IMG SRC attribute, thereby forcing your Web browser to perform that
    exact same Google search.
    <img src=”
    Obviously forcing a Web browser to send a Google search request is more or less harmless. However, the same
    process of URL construction can be used to automatically make a Web browser transfer bank account funds, post
    inflammatory comments, or even hack a website. The point is that this one mechanism of forcing a Web browser to
    connect to another website enables XSS worm propagation


    source: https://www.whitehatsec.com/assets/WP5CSS0607.pdf

  7. Why are you calling the mail function twice?


    It looks to me like the first call is to send the email to the actual user and the second has a hardcoded address to send a notification that a report was sent to the developer/site owner. I'm assuming that was for debugging. I'm guessing that is not the source of his problem.

  8. A few things: You can use swiftmailer. Your pdf should be in $data. The password stuff at the top of the script could stay the same.


    Try removing the @ that is in front of the mail. The @ suppresses any error messages that the mail produces.


    The $i_boundary is used to tell the mail client where one part of the email (the message) stops and another (the pdf) starts. Looking at the output it looks right to me but looks like the email is not being sent with the headers for each section and the boundaries recognized. I'm not sure why. Any idea what changes were made when it stopped working?

  9. For whatever help it provides, I use the PEAR Mail modules to send pdf attachments. They are out of date, but here's my code (without the actual longwinded message):

    include 'Mail.php';
    include 'Mail/mime.php' ;
    $text = "Your message here";
    $html = "<html><body><p>Your message here</p></body></html>";
    $crlf = "\n";
    $hdrs = array(
                  'From'    => 'david@yourdomain.com',
                  'Subject' => 'Your Subject'
    $mime = new Mail_mime(array('eol' => $crlf));
    $mime->addAttachment($file, 'application/pdf','valuation.pdf',FALSE);
    $body = $mime->get();
    $hdrs = $mime->headers($hdrs);
    $mail =& Mail::factory('mail');
    $mail->send($recipients, $hdrs, $body);
  10. I am trying to replace the last character in a Japanese word with another. substr_replace did not work - I figured because it was multibyte so I tried using only multibyte functions, but it is still not working. Here's the code I'm trying

    <meta charset="utf-8">
    //substr_replace($word, 'ひ',-1);
    $length=mb_strlen ( $word);
    $word = mb_substr ( $word , $start ,$length).'ひ'; 
    echo $word;

    Which results in くたく��ひ

    I am probably just using the multi_byte functions wrong but can't see how.

  11. The source XML is huge but here's a sample:

                <gloss>there (place physically distant from both speaker and listener)</gloss>
                <gloss>over there</gloss>
                <gloss>that place</gloss>
                <gloss>that far (something psychologically distant from both speaker and listener)</gloss>
                <gloss>that much</gloss>
                <gloss>that point</gloss>
                    <upd_detl>Entry created</upd_detl>
                    <upd_detl>Entry amended</upd_detl>
                <gloss>lightly (flavored food, applied makeup)</gloss>

    What is the total number of devices that were checked out during a certain timeframe? This is the information that I am trying to pull from my database.

    Do you want the total number checked out by everyone? by a particular user? Where is number of checkouts stored in your database? We need column names. During what timeframe? What database columns have dates?

  13. Then try:

       function test($textboxnumber)
            switch ($textboxnumber) {
            case 1:
            $response = "hello";
            $response= "goodbye";
            case 10:
             $response = 'response 10';
             $response="oops, I don't know hat to say";
            return $response;

    and call your function with the texbox number.

    <input type="textbox" name="xx"  value="<?php $textboxnumber=2 ; echo test($textboxnumber); ?>" />
  14. I am trying to get the names of the children nodes in XML


    Here is the code:

            foreach ($pos->children() as $child) {
                echo "I never get here";
                echo $child->getName() . "\n";
            echo "but the node has children---<br>";

    which I modeled on the code from http://www.php.net/manual/en/simplexmlelement.getname.php


    and here is a sample of the output:

    SimpleXMLElement Object
        [n] => SimpleXMLElement Object
    but the node has children---
    SimpleXMLElement Object
        [int] => SimpleXMLElement Object
    but the node has children---
    SimpleXMLElement Object
        [n] => SimpleXMLElement Object

    Why can't I go through the chldren with foreach?

  15. I am trying to get a large (~60MB) XML file into a database and it is giving me fits. A sample record from the XML file looks like this:

                <gloss>making arbitrary decisions which benefit oneself</gloss>
                <gloss>self-approved plan</gloss>

    So, I can have 1 or more <k_ele> elements and within each I can have 1 or more <ke_pri> elements. I need to decide what to do with the record based on the the content of ke_pri elements. Same issue with <r_ele> elements. So, I read the XML with SimpleXML and then because I don't know if each r_ele and re_pri is an object over which I need to iterate or a variable I have ugly code that looks like this:

    if (is_object($r_ele)) {
        foreach ($r_ele as $reading_element) {
            $re_pri = $reading_element->re_pri;
            if (is_object($re_pri)) {
                foreach ($re_pri as $value) {
                    switch ($value) {
                        // decide what to do here
            } else {
                switch ($re_pri) {
                    // decide what to do here
    } else {
        $re_pri = $reading_element->re_pri;
        if (is_object($re_pri)) {
            foreach ($re_pri as $value) {
                switch ($value) {
                    // decide what to do here
        } else {
            switch ($re_pri) {
                // decide what to do here

    I know that there must be a more elegant way to do this and would love suggestions of how I can improve my code.

  16. While on vacation I had a lot of downtime and my handy Nexus 7. I got tired of studying Japanese vocabulary and realized that my problem was that I needed to learn more grammar to go with my growing vocabulary. Being a glutton for punishment, I decided that the best way to learn grammar was to create a program that would teach it. So, I began writing and now my little program can spit out some grammatically correct sentences in both languages. Next step is to make it quiz me on the grammar and vocabulary. Which brings me to my big question. I would like to use a spaced repetition system to maximize retention. I've Googled a bit and learned some things. The Leitner System seems pretty easy to understand but I'm guessing that there are better algorithms around. Ideally I'd like PHP/MySql code that I could integrate with my app (My preference is procedural because I am less comfortable with OO), second choice is pseudocode that I could turn into code, third choice is a clear description of a better algorithm than Leitner. So, can anybody point me to code or examples? Does anyone have experience with flashcard algorithms and can make suggestions on a different method or tweaks to Leitner?




  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.