Member Avatar for සශික

hey guys I'm doing lms project. I created login page and php file. I can't find where I stucked.
Here explanation of login form :

  • Check whether given username and password correct or not..
  • If correct then check user type...
  • redirect to different pages according to user's faculty...

here my php code :

   $db=mysql_connect("localhost","root","") or die("error : ".mysql_error());

        $query = mysql_query("select * from lms.user");

        while($row = mysql_fetch_assoc($query)){

                else if($row['u_type']=="user"){
                    if($row['faculty']=="School of Computing")
                    else if($row['faculty']=="School of Business")
                    else if($row['faculty']=="School of Engineering")
            else if(($row['user_name']!=$username)&&($row['password']!=$password))

this is the structure of datatable :

database name is lms
table name is user
field names are user_name,password,index_no,faculty,email,u_type

guys help me .....
Thank you !

Recommended Answers

All 2 Replies

When I see a login like that I cringe. The basic problem is that the password is stored in the clear rather than a hash salted result. Here's priors about this.'+store+passwords+in+databases

In those discussions you'll find many examples. Add the keyword PHP to get more specific.

In other words, you dug a hole and I shouldn't hand you a shovel.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.