Just before a minute I sent a message with an attachement.. but the attachement was
canceled by the list!!
Any way.. these are the codes of the pages :
Login.php :
<?php
$link = mysql_connect("localhost", "Database username", "Database password")
or die("Could
not connect: " . mysql_error());
mysql_select_db("Database name", $link);
$UserName = $_GET['UserName'];
$Password = $_GET['Password'];
$Serial = $_GET['Serial'];
$UserName = mysql_escape_string($UserName);
$Password = mysql_escape_string($Password);
$Serial = mysql_escape_string($Serial);
$user = escape_function($user);
$query1 = "select Serial from accounts where UserName='$UserName' and
Password='$Password'";
$query2 = "SELECT Random FROM accounts";
$Random = 'Random'
$result = mysql_query($query1) or die("Query error: " . mysql_error());
$row = mysql_fetch_row($result) or die("Incorrect credentials, Please
contact the E-Learning Administraion...: " . mysql_error());
$RightSerial = htmlspecialchars($row[0]);
$UserSent = $Serial . $Random;
$ServerReply = $RightSerial . $Random;
$md5a = md5($UserSent);
$md5b = md5($ServerReply);
mysql_close($link);
if($md5a == $md5b){
print<<<END
<HTML>
<BODY>
You was accepted by the server..
</BODY></HTML>
END;
}else{
print<<<END
<HTML>
<BODY>
Sorry, you was blocked by the server for one of the following reasons :
1- You are not using the same PC that you registered from.
2- You are trying to hack the System.
If you are sure that you are using the same PC.. then contact the E-Learning System
Administrator.
</BODY></HTML>
END;
}
Activate.php :
<?php
function dbConnect()
{
//define the database connection information
$dbHost = "localhost";
$dbUser = "Database username";
$dbPass = "Database password";
$dbName = "database name";
//connect to the mysql server
$link = @mysql_connect($dbHost, $dbUser, $dbPass);
//return success or failure of connection
if(!$link)
{
//report error
echo "Could not connect to server";
exit;
}
//select the database
if([EMAIL PROTECTED]($dbName))
{
//report error
echo "Could not select database";
exit;
}
}
$query=mysql_query("UPDATE `accounts` SET Activation='ACTIVATED' WHERE
UserName='".$_POST['UserName']."' LIMIT 1");
if (mysql_affected_rows($query)==1)
{
echo $_POST['UserName']." has been activated";
}
?>
Deactivate.php
<?php
function dbConnect()
{
//define the database connection information
$dbHost = "localhost";
$dbUser = "Database username";
$dbPass = "Database password";
$dbName = "Database name";
//connect to the mysql server
$link = @mysql_connect($dbHost, $dbUser, $dbPass);
//return success or failure of connection
if(!$link)
{
//report error
echo "Could not connect to server";
exit;
}
//select the database
if([EMAIL PROTECTED]($dbName))
{
//report error
echo "Could not select database";
exit;
}
}
$query=mysql_query("UPDATE `accounts` SET Activation='DEACTIVATED' WHERE
UserName='".$_POST['UserName']."' LIMIT 1");
if (mysql_affected_rows($query)==1)
{
echo $_POST['UserName']." has been Deactivated";
}
?>
Activate.htm
<HTML>
<HEAD>
<SCRIPT>
function selectit() {
document.forms["Activation"].elements["UserName"].focus();
}
</SCRIPT>
</HEAD>
<BODY>
<form NAME="Activation" ACTION="Activate.php" METHOD="POST">
<B>User Name to Activate:
<input TYPE="TEXT" SIZE="17" MAXLENGTH="16" NAME="UserName"><input TYPE="submit"
NAME="Activate" VALUE="Activate" ACTION="Activate.php" METHOD="POST"><br>
</B>
</FORM>
</BODY></HTML>
Deactivate.htm
<HTML>
<HEAD>
<SCRIPT>
function selectit() {
document.forms["Activation"].elements["UserName"].focus();
}
</SCRIPT>
</HEAD>
<BODY>
<form NAME="Activation" ACTION="Deactivate.php" METHOD="POST">
<B>User Name to Deactivate:
<input TYPE="TEXT" SIZE="17" MAXLENGTH="16" NAME="UserName"><input TYPE="submit"
NAME="Deactivate" VALUE="Deactivate" ACTION="Deactivate.php" METHOD="POST"><br>
</B>
</FORM>
</BODY></HTML>
Waiting your help.. up to now I don't know why it is error..
Regards..