+ Reply to Thread
Results 1 to 9 of 9

Thread: Advanced Mysql / PHP database backed login script

  1. #1
    Member prydie's Avatar
    Join Date
    Mar 2008
    Posts
    64

    Advanced Mysql / PHP database backed login script

    I conformed to popular demand and did a version 1.2 of my login script. Its new features include md5 encryption and the use of a database instead of variables stored in the script.

    Advanced Mysql / PHP database backed login script at Pryde Design

    Anyway hope it helps digg // subscribe if you liked it as usual and yeah ehmm thats about it lol.

    Hope you like it

    - Andrew


  2. #2
    Design Guru tommylogic's Avatar
    Join Date
    Apr 2007
    Location
    Virtually Everywhere
    Posts
    6,352
    ummm.. Toon, you give me sh*t about writing 2 page tutorials that directly relate to questions that people actually ask here. Hmmmmph, I better not hear another peep from you on that, brother

  3. #3
    Netvibes is an Addiction™ Toon's Avatar
    Join Date
    Jan 2007
    Location
    Sheffield, UK
    Posts
    23,622
    Blog Entries
    12
    Yeah but linking to them from here is too easy, it will never make your site popular you both have to realize the web is full of the same tutorials, what makes yours and your site better than the rest?

  4. #4
    Dalek Lover Arkady's Avatar
    Join Date
    Apr 2007
    Location
    Glasgow
    Posts
    2,732
    It looks to me, like you have laid your self wide open to an SQL injection attack. I would suggest you rethink your approach.

  5. #5
    Member prydie's Avatar
    Join Date
    Mar 2008
    Posts
    64
    Were do you suggest that there is sql injection? There is only one query and that has addslashes on the only user inputed variable.
    Last edited by prydie; 28-03-2008 at 04:20 PM.

  6. #6
    Dalek Lover Arkady's Avatar
    Join Date
    Apr 2007
    Location
    Glasgow
    Posts
    2,732
    Quote Originally Posted by prydie View Post
    Were do you suggest that there is sql injection? There is only one query and that has addslashes on the only user inputed variable.
    I'm sorry , but the addslashes class doesn't afford you any protection against SQL injection attacks. You have to detect malicious user input pro-actively using advanced error rejection exception techniques, or regular expression string rejection constructs.

  7. #7
    Member prydie's Avatar
    Join Date
    Mar 2008
    Posts
    64
    I advocate high security coding but I was trying to write a simple script for beginners to learn from. I suppose mysql_real_escape_string() could have been used but add slashes gives us the security we need here. I can't see any way to inject it but you are welcome to try. I will send it across to one of my mates in the security field and see what they think but I am confident that there is no means of exploiting the script.
    Last edited by prydie; 28-03-2008 at 10:47 PM.

  8. #8
    Knows Your Body Better Than You Do Acuity's Avatar
    Join Date
    Feb 2008
    Location
    London
    Posts
    1,369
    any chance of seeing your version with the member registration bro?

  9. #9
    Member prydie's Avatar
    Join Date
    Mar 2008
    Posts
    64
    I will be posting it soon. I have got registration going but need to make sure that its all working properly and is totally secure.

    Thanks for the interest

    I will post a thread about version 1.3 when I release it.

    - Andrew

+ Reply to Thread

Similar Threads

  1. WordPress Database Error MySQL Server has Gone Away
    By Graphic Design Blog in forum Graphic Design Blog
    Replies: 0
    Last Post: 02-05-2008, 06:02 AM
  2. PHP Login Script / form
    By prydie in forum Programming Forum
    Replies: 0
    Last Post: 26-03-2008, 10:37 PM
  3. How to Create an Advanced CSS Menu
    By Graphic Design Links in forum Graphic Design Links
    Replies: 0
    Last Post: 30-10-2007, 02:00 PM
  4. PHP Login Tutorial
    By Harry in forum Graphic Design Tutorials
    Replies: 0
    Last Post: 21-09-2007, 07:10 PM
  5. login help plzzzzzzzz
    By rr_designz in forum Programming Forum
    Replies: 2
    Last Post: 21-05-2007, 02:27 AM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts


The Graphics Forum Web Design Stuff Free Decent Downloads Free Quality Wallpapers Graphics Forum Free Vista Themes
The Top The Best Images Tech Talk 247 Logo Design - $149 Affordable Stock Vector Illustrations Creativecurio - Design Blog Graphic Design Advertising

Check the forum often for the latest design announcements. Everything from graphic design and web design, to films and music. Estetica is a great place for people to get together and help each other out.



Web Hosting - UK Web Hosting services for business or personal website hosting needs.

Dedicated Servers - A full range of Managed Dedicated Server solutions suitable for all your requirements.

Graphic Design Blog | Web Design Forum | Graphic Design and Print Forum | Graphic Design Links | Advertise On This Site

Web Design UK | Vision.To Design | Leaflet Printing | Estetica Design Forum's Privacy Policy

Flyer Printing | Photography Blog | Design Forum Links | Logo Design | Graphic Design Social Network | Logo Design

Graphic Design Tutorials | Logo Designer | UK Logo Design Studio | Land for sale | Vector Art Blog | Leaflet Printing

Free Web Hosting | Custom Logo Design - $149 Only | Affordable Print Design Templates | Small Business Logo Design | Company Logo Design

Logo Design Service | Logo Design Firm | Logo Design Reseller | Custom Logo Design | Letterhead Printing | Flyer Printing | Business Card Printing

Printing | Leaflet Printing | Online Backup | T-Shirt Printing | Personalised Mugs | Canvas Printing | Free Web Hosting Comparison Site