Jump to content

anything wrong with this?


seany123

Recommended Posts

		$username = $_POST['username'];
	$password = md5($_POST['password']);

	$query = $db->execute("select * from `players` where `username`='". $username ."' & `password`='". $password ."'");
	if ($query->recordcount() <= 0)
	{
		$errormsg .= "You could not login! Please check your username/password!";
		$error = 1;
	}

 

anyone know who even though im putting the same password in correctly it dosnt wanna work?

 

 

edit:

 

i just echoed $password and its different to the one in my database!!! wtf

Link to comment
https://forums.phpfreaks.com/topic/190891-anything-wrong-with-this/
Share on other sites

Are you doing any type of encryption? If you are then it would need to be something like this

 

$query = "SELECT * FROM players WHERE username='$username' AND password=SHA('$password')";

 

That is not an encryption, in fact it is the absolute opposite. He's not even using SHA1 (although I would recommend it)

i was setting

 

$password = md5($_POST['password']);

 

the problem wasnt in the code i gave... in fact it was in the form... i had the value in password set to <?=$_POST['password']?>

 

thanks for the help anyway :)

 

 

anyway is md5 or sha1 better?

 

To put it simple, None. But SHA1 is slightly more secure, less rainbow hashes in the wild.

Archived

This topic is now archived and is closed to further replies.

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.