Jump to content

Recommended Posts

Hi all, on my website users have to register before they move on to the members area. But ive came across somthing i dont understand.


When the user registers nothing get inserted into the database when it should but it still allows them to login because the login details are right.


Anyone got a clue whats happend?


Thanks for you help.

Link to comment
Share on other sites

Ill show you my login script and register script:


Register script:

// allows you to use cookies
//gets the config page
if ($_POST[register]) {
// the above line checks to see if the html form has been submitted
$username = mysql_real_escape_string($_POST[username]);
$password = mysql_real_escape_string($_POST[pass]);
$cpassword = mysql_real_escape_string($_POST[cpass]);
$email = mysql_real_escape_string($_POST[emai1]);
//the above lines set variables with the user submitted information
if($username==NULL|$password==NULL|$cpassword==NULL|$email==NULL) {
//checks to make sure no fields were left blank
echo "A field was left blank.";
//none were left blank!  We continue...
if($password != $cpassword) {
// the passwords are not the same!  
echo "Passwords do not match";
// the passwords are the same!  we continue...
$password = md5(mysql_real_escape_string($password));
// encrypts the password
$checkname = mysql_query("SELECT username FROM users WHERE username='$username'");
$checkname= mysql_num_rows($checkname);
$checkemail = mysql_query("SELECT email FROM users WHERE email='$email'");
$checkemail = mysql_num_rows($checkemail);
if ($checkemail>0|$checkname>0) {
// oops...someone has already registered with that username or email!
echo "The username or email is already in use";
// noone is using that email or username!  We continue...
$username = htmlspecialchars(mysql_real_escape_string($username));
$password = htmlspecialchars(mysql_real_escape_string($password));
$email = htmlspecialchars(mysql_real_escape_string($email));
// the above lines make it so that there is no html in the user submitted information.
//Everything seems good, lets insert.
$query = mysql_query("INSERT INTO users (username, password, email) VALUES('$username','$password','$email')");
// inserts the information into the database.
echo "You have successfully registered!";
$query = mysql_query("INSERT INTO pmessages(touser, message, from, title, unread) VALUES('$username','Welcome to Great-Gaming.','Great-Gaming Staff','Welcome to GG','unread')");
// the form has not been submitted...so now we display it.
echo ("
<form method=\"POST\">
<table border=\"1px\" bordercolor=\"#000000\" cellpadding=\"0\" cellspacing=\"0\" bgcolor=\"#333333\">
<img src=\"images/banner.jpg\">
<td class='header'>
<center><b><code>Home, Lost Password And TOS</code></center></b>
<center>:: <a href='index.php'>Home</a> :: || :: <a href='lostpass.php'>Lost Password</a> :: || :: <a href='tos.php'>TOS</a> :: </center>
<td class='header'>
<center><input type=\"text\" size=\"15\" maxlength=\"25\" name=\"username\"></center>
<td class='header'>
<center><input type=\"password\" size=\"15\" maxlength=\"25\" name=\"pass\"></center>
<td class='header'>
<center><b>Confirm Password</b></center>
<center><input type=\"password\" size=\"15\" maxlength=\"25\" name=\"cpass\"></center>
<td class='header'>
<center><input type=\"text\" size=\"15\" maxlength=\"25\" name=\"emai1\"></center>
<center><input name=\"register\" type=\"submit\" value=\"Register\"></center>


Login script:

// allows you to use cookies.
if (!$logged[username])
if (!$_POST[login])
<center><form method=\"POST\">
<table border=\"1px\" bordercolor=\"#000000\" cellpadding=\"0\" cellspacing=\"0\" bgcolor=\"#333333\">
<img src=\"images/banner.jpg\">
<td class='header'>
<center><b><code>Register, Lost Password And TOS</code></center></b>
<center>:: <a href='Register.php'>Register</a> :: || :: <a href='lostpass.php'>Lost Password</a> :: || :: <a href='tos.php'>TOS</a> :: </center>
<td class='header'>
<td align=\"center\">
<input type=\"text\" size=\"15\" maxlength=\"25\" name=\"username\">
<td class='header'>
<td align=\"center\">
<input type=\"password\" size=\"15\" maxlength=\"25\" name=\"password\">
<td align=\"center\">
<input type=\"submit\" name=\"login\" value=\"Login\">
<td class='header'>
<center><b><code>Thanks For Playing!</center></b></code>
if ($_POST[login]) {
// the form has been submitted.  We continue...
$username= mysql_real_escape_string($_POST['username']);
$password = md5(mysql_real_escape_string($_POST[password]));
// the above lines set variables with the submitted information.  
$info = mysql_query("SELECT * FROM users WHERE username = '$username'") or die("MySQL Error " . mysql_error());
$data = mysql_fetch_array($info);
if($data[password] != $password) {
// the password was not the user's password!
echo ("<center><table width='70%'border='1px' bordercolor='#000000'>
<td bgcolor='#FF6600'>
<center><b>Somthing Is Wrong</b></center>
<center>You have either a incorrect <b>username</b> or <b>password</b>!</center>
$timestamp = time()+60; 
mysql_query("UPDATE users SET online='$timestamp' WHERE username='$username'");

// the password was right!
$query = mysql_query("SELECT * FROM users WHERE username = '$username'") or die("MySQL Error " . mysql_error());
$user = mysql_fetch_array($query);
// gets the user's information
setcookie("id", $user[id],time()+(60*60*24*5), "/", "");
setcookie("pass", $user[password],time()+(60*60*24*5), "/", "");
// the above lines set 2 cookies. 1 with the user's id and another with his/her password.  
echo ("<meta http-equiv=\"Refresh\" content=\"0; URL=*********/index2.php\"/>Thank You! You will be redirected");
// modify the above line...add in your site url instead of yoursite.com
echo "<meta http-equiv=\"Refresh\" content=\"0; URL=http://***********/index2.php\"/>";


Sorry about the length of them.

This thread is more than a year old. Please don't revive it unless you have something important to add.

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Reply to this topic...

×   Pasted as rich text.   Restore formatting

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.