gpt4 book ai didi

PHP登录: does not respond well

转载 作者:行者123 更新时间:2023-11-29 07:53:05 27 4
gpt4 key购买 nike

这是一个简单的用户登录。我只是想了解这个概念。让我解释一下我的代码问题。这是我的表单:

<form action = "check_login.php" action = "POST">
User:<input type="text" name="user"><br/>
Password:<input type="password" name="password"><br/>
<input type="submit" name="submit" value="Sign In">
</form>

check_login.php:

    <?php
error_reporting(E_ALL);
$username = $_POST['user'];
$password = $_POST['password'];

if($username && $password) {
$host = 'localhost';
$user = 'root';

$con = mysql_connect($host, $user, '') or die("Couldn't Connect");
mysql_select_db('first_site');

$sql = "SELECT * FROM user WHERE user_name= '$username' and user_password ='$password'";
$query = mysql_query($sql, $con);

$count = mysql_num_rows($query);
echo $count;

}
else {
die "Enter username and password";
}

我维护了一个数据库first_site和表user。该表有 3 列:id、user_name 和 user_password。

如果我输入用户名和密码,$count 变量应该保存值 1,但它恰好保存 0。我一无所知。帮助!!

最佳答案

代码本身是危险的,你没有使其安全以防止注入(inject)'

 <?php
error_reporting(E_ALL);
// Escaped For SQL Injection Prevention
$username = mysql_real_escape_string($_POST['user']);
$password = mysql_real_escape_string($_POST['password']);

if($username && $password) {
$host = 'localhost';
$user = 'root';

$con = mysql_connect($host, $user, '') or die("Couldn't Connect");
mysql_select_db('first_site');

$sql = "SELECT user_name FROM user WHERE user_name= '$username' and user_password ='$password'";
$query = mysql_query($sql, $con);

// If Exists
if( $query ) {
$count = mysql_num_rows($query);
echo $count;
}
else {

die(mysql_error());

}

}
else {
die ("Enter username and password");
}

同时将形式更改为

<form action = "check_login.php" method = "POST">
User:<input type="text" name="user"><br/>
Password:<input type="password" name="password"><br/>
<input type="submit" name="submit" value="Sign In">

尝试上面的方法,如果有的话,它应该会提示我们一个 mysql 错误,它也比原来的更安全。

关于PHP登录: does not respond well,我们在Stack Overflow上找到一个类似的问题: https://stackoverflow.com/questions/25910451/

27 4 0
Copyright 2021 - 2024 cfsdn All Rights Reserved 蜀ICP备2022000587号
广告合作:1813099741@qq.com 6ren.com