?_SESSION[login2]=pwned&_SESSION[haslo2]=ssss
to otwiera mi sie strona i niby ze jest zalogowany dany user a jak to zabespieczyć ? oto cały kodzik
Index.php
<?php if($_SESSION['login2']==$login AND $_SESSION['haslo2']==$haslo) { echo '<table border="0" cellpadding="0" cellspacing="0" class="tabela"> <tr> <td width="100%" height="100%" align="center"> <form method="post" action="zaloguj.php" name="f"> <table border="0" cellpadding="0" cellspacing="0" width="220"> <tr> <td width="220" class="szz"><div class="nn">CmS Frogss</div></td> </tr> <tr> <td width="220" height="100%" class="bor" align="center"> <table border="0" cellpadding="0" cellspacing="0" width="216"> <tr> <td width="216" height="100%" class="bgs" align="center"><table border="0" cellpadding="0" cellspacing="0" width="180"> <tr> <td width="47" height="25" class="szz1" align="right"><p class="ll">Login:</p></td> <td width="133" height="25"><input class="input2" name="login" size="25"></td> </tr> <tr> <td width="47" height="25" class="szz1" align="right"><p class="ll">Hasło:</p></td> <td width="133" height="25"><input class="input2" name="haslo" size="25" type="password"></td> </tr> <tr> <td width="180" height="25" colspan="2" align="center" valign="bottom"><input type="submit" class="input2" value="Zaloguj się" name="zaloguj"><br /> </td> </tr> <tr> <td width="2" height="2" colspan="2" align="center" valign="bottom"></td> </tr> </table> </td> </tr> </table> </td> </tr> </table> </form> </td> </tr> </table> '; } else { echo '<table border="0" cellpadding="0" cellspacing="0" width="760" align="center"> <tr> <td width="15" height="31"><img src="theme/1.gif" width="15" height="31" alt=""></td> <td width="530" height="31" class="bm"><div class="menu_marg"> <span class="orr">Home</span><span class="menu_m">|</span> <a href="index.php" class="szz">Wersje językowe</a> <span class="menu_m">|</span><a href="index.php?cmd=1" class="szz">Newsy</a> <span class="menu_m">|</span><a href="index.php?cmd=admini" class="szz">Administratorzy</a> <span class="menu_m">|</span><a href="index.php?cmd=2" class="szz">Podstrony</a> <span class="menu_m">|</span><a href="index.php?cmd=9" class="szz">Konfiguracja</a> <span class="menu_m">|</span><a href="index.php?cmd=inne" class="szz">Dodatki</a> </p></td><td width="200" height="31" class="bm" align="right"><div class="menu_marg"> <span class="szz">Zalogowany: </span><span class="orr">'.$zaloguj_login.'</span><span class="menu_m">| </span><a href="wyloguj.php" class="szz">Wyloguj</a></div></td>'; } ?>
Zaloguj.php
<?php include ('../config.php'); ?> <?php $login = $_POST[login]; $query = "SELECT * FROM admin WHERE login1='$login';"; if ($ile_user > 0) { $query2 = "SELECT * FROM admin WHERE login1='$login' AND haslo1='$haslo';"; if ($ile_user2 > 0) { #setcookie ("login1_c", $login,time()+3600); /* traci ważność za godzinę */ #setcookie ("haslo1_c", $haslo,time()+3600); /* traci ważność za godzinę */ $_SESSION['login1'] = $login; $_SESSION['haslo1'] = $haslo; } else { } } else { } ?>