echo $res => Resource id #8non
echo $req => select * from administrator where login="Admin" and passwd="e3afed0047b08059d0fada10f400c1e5"non
<?php
session_start();//demarrage de la session
include ('config.php');
$log = isset($_POST['login']) ? addslashes(trim($_POST['login'])) : 'inconnu';
$mdp = isset($_POST['mdp']) ? addslashes(trim($_POST['mdp'])) : 'inconnu';
$connection = mysql_connect($host, $user, $pass) or die(mysql_error());
$req = "SELECT * FROM administration WHERE login='". $log ."' and mdp='". md5($mdp) .";";//avec hachage md5 pour le mdp
$res = mysql_query($req) or die ('Erreur:'.mysql_error());
if(mysql_num_row($res) > 0)//verif de l'existence de l'utilisateur
{
$_SESSION['log'] = $log;
$_SESSION['auth'] = "oui";
}
else
{
echo 'non';
}
?><?php
//....
$req = "SELECT * FROM administration WHERE login='". $log ."' and mdp=AES_ENCRYPT('". $mdp ."', 'cle_de_chiffrement');";//avec chiffrement SQL AES_ENCRYPT pour le mdp
//....
?>