登录模块设计

 

//Info.mdf是数据库名,其中Name、Password是T_admin表中字段 ,第三种登录方式最好!!!!


            string name = txtName.Text.Trim();
            string pwd = txtPwd.Text.Trim();
            using (SqlConnection conn = new SqlConnection(@"Data source=.\SQLEXPRESS;AttachDBFilename=|DataDirectory|\Info.mdf;Integrated Security=True;User Instance=True"))
            {
                conn.Open();
                using (SqlCommand cmd = conn.CreateCommand())
                {
   //+++++++++++登录代码++++++++++++
                }
            }

 


//第一种登录方式 
      cmd.CommandText = "select * from T_admin where Name='" + name + "'";
                    using (SqlDataReader reader = cmd.ExecuteReader())
                    {
                        if (reader.Read())
                        {
                            string dbpwd = reader.GetString(reader.GetOrdinal("Password"));
                            if (dbpwd == pwd)
                            {
                                MessageBox.Show("登录成功!");
                            }
                            else
                            {
                                MessageBox.Show("用户名或密码错误");
                            }
                        }
                        else
                        {
                            MessageBox.Show("用户名或密码错误");
                        }
                    }

 

 

//第二种登录方式     输入 1'or'1'='1 造成SQL漏洞攻击
                    cmd.CommandText = "select count(*) from T_admin where Name='" + name + "'and Password='" + pwd + "'";
                    int i = Convert.ToInt32(cmd.ExecuteScalar());
                    if (i > 0)
                    {
                        MessageBox.Show("登录成功!");
                    }
                    else
                    {
                        MessageBox.Show("用户名或密码错误");
                    }

 

 


//第三种登录方式
                    cmd.CommandText = "select count(*) from T_admin where Name=@name and Password=@pwd";
                    cmd.Parameters.Add(new SqlParameter("name", name));
                    cmd.Parameters.Add(new SqlParameter("pwd", pwd));
                    int i = Convert.ToInt32(cmd.ExecuteScalar());
                    if (i > 0)
                    {
                        MessageBox.Show("登录成功!");
                    }
                    else
                    {
                        MessageBox.Show("用户名或密码错误");
                    }

转载于:https://www.cnblogs.com/hbzzws/articles/2316795.html

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值