checkuserlogin.asp

来自「易和阳光购物商城 v1.3 | 功能简介 增加了防注入文件」· ASP 代码 · 共 56 行

ASP
56
字号

<!--#include file="Include/Iheeo_Conn.asp"-->
<!--#include file="Include/md5.asp" -->
<meta http-equiv="Content-Type" content="text/html; charset=gb2312">
<%dim username,userpassword,comeurl,verifycode
username=replace(trim(request("username")),"'","")
userpassword2=replace(trim(request("userpassword")),"'","")
userpassword=md5(userpassword2,16)
verifycode=replace(trim(request("verifycode")),"'","")
if username="" or userpassword="" then
response.write "<script LANGUAGE='javascript'>alert('您的用户名或密码有误!');history.go(-1);</script>"
response.end
end if

if cstr(session("getcode"))<>cstr(trim(request("verifycode"))) then
response.Write "<script LANGUAGE='javascript'>alert('请输入正确的验证码!');history.go(-1);</script>"
response.end
end if

set rs=server.CreateObject("adodb.recordset")
rs.Open "select * from bjx_User where username='"&username&"' and userpassword='"&userpassword&"' " ,conn,1,3
if not(rs.bof and rs.eof) then
if userpassword=rs("userpassword") then
response.Cookies("bjx")("username")=trim(request("username"))
response.Cookies("bjx")("reglx")=rs("reglx")
response.Cookies("bjx")("jifen")=rs("jifen")
response.Cookies("bjx")("jiaoyijine")=rs("jiaoyijine")

rs("lastlogin")=now()
rs("logins")=rs("logins")+1
rs("userlastip")=Request.ServerVariables("REMOTE_ADDR")
rs.Update
rs.Close
set rs=nothing
Session("GetCode")="1234"
response.write "<IFRAME SRC=bbs/login.asp?action=chk&username="&username&"&password="&userpassword2&"&codestr=1234&CookieDate=0 width=0 height=0 frameborder=no border=0 MARGINWIDTH=0 MARGINHEIGHT=0 SCROLLING=no></IFRAME>"
username=trim(request("username"))
conn.execute("delete from BJX_action where username='"&username&"' and zhuangtai=7")
conn.execute("delete from BJX_action_jp where username='"&username&"' and zhuangtai=7")
if request("linkaddress")="" then
backlink=request.servervariables("http_referer")
else
backlink=request("linkaddress")
end if
%>
正在登录,请稍等,正在为你转向......
<meta  http-equiv="refresh"  content="3;url=<%=backlink%>"> 
<%
else
response.write "<script LANGUAGE='javascript'>alert('对不起,您的用户名或密码有误!');history.go(-1);</script>"
end if
else
response.write "<script LANGUAGE='javascript'>alert('对不起!您的用户名或密码有误!');history.go(-1);</script>"
end if

%>

⌨️ 快捷键说明

复制代码Ctrl + C
搜索代码Ctrl + F
全屏模式F11
增大字号Ctrl + =
减小字号Ctrl + -
显示快捷键?