session_start();
include $_SERVER['DOCUMENT_ROOT']."/config/connect.php";
$_url = $_SERVER['HTTP_REFERER'];
if($mode=="login") {
// Query 巩阑 瘤沥
$u_passwd = str_replace("'", '', $u_passwd);
$u_id = str_replace("'", '', $u_id);
$u_passwd = substr($u_passwd, 0, 20);
$u_id = substr($u_id, 0, 20);
$u_passwd = trim($u_passwd);
$u_id = trim($u_id);
$sql ="select id, name, coin, cyber_coin, count , level,drop_reg from member_info where id='$u_id' and site='窜烹' and ( passwd=old_password('$u_passwd') or passwd=password('$u_passwd')) ";
$result = mysql_query($sql, $conn);
$row_result=mysql_fetch_array($result);
if($row_result['id']=="") {
if (!in_array($u_id, $g_except_login_dup_chk)) {
$tm_curr = time();
$sesskey=session_id();
$ip=$_SERVER['REMOTE_ADDR'];
$atime=time();
$expiry= $atime + SESSION_VALID_TIME;
}
echo "";
echo ("");
exit;
} else{
$user_login_id=$row_result[0];
$user_login_name=$row_result[1];
session_register('user_login_id');
session_register('user_login_name');
$time1=date('H:i');
$Year2=date('Y');
$Month2=date('m');
$Day2=date('d');
$last_visit1=$Year2."-".$Month2."-".$Day2." ".$time1;
$count1=$row_result[4]+1;
$l_upsql="update member_info set last_visit='$last_visit1', count='$count1' where id='$row_result[0]' and site='窜烹'";
$l_upparse=mysql_query($l_upsql, $conn);
if($row_result[5]==1){$le="瘤粮";}
elseif($row_result[5]==2){$le="啊练";}
elseif($row_result[5]==3){$le="VIP";}
else{$le="老馆";}
$login_info = "insert into ip_address(id, ip, login_time, name) values('".$user_login_id."', '".$_SERVER['REMOTE_ADDR']."', now(), '".$user_login_name."')";
mysql_query($login_info, $conn);
$cart_sql = "delete from cart where id='$user_login_id'";
mysql_query($cart_sql, $conn);
echo ("");
exit;
}
} elseif($mode=="logout") {
$q = "delete from session where id='$_SESSION[user_login_id]'";
@mysql_query($q);
unset($_SESSION['user_login_id']);
unset($_SESSION['user_login_name']);
echo ("");
exit;
}
?>
代码 就这样 用户密码是加密的 ..
请高手看看 又哪里错啦
很急
mysql 用户表 密码是 : 45ec14590e096a2c这种形式 是 用
mysql 的 password方法 储存的
展开