The code are show as below :
<?PHP
$ID = $POST['ID'];
$Password = $POST['Password'];
$ip = $_SERVER["REMOTE_ADDR"];
if (!ID || !$Password) {
echo "<script language=\"javascript1.2\" type=\"text/javascript\">
function refresh() {
var url = \"index.php\";
window.location.href = url;
}
alert(\"User ID or Password is empty, Please retry\");
refresh();
</script>";
} else {
// Connect to database
$db = mysqli_connect("101.101.1.1", "root", "");
mysqli_select_db($db, "iso") or die("Unable to connect to server");
// Check ID
$query_id = "select * from sysuser where id='$ID'";
$result = mysqli_query($db, $query_id) or die("Server error");
if (mysqli_num_rows($result) < 1) {
echo "<script language=\"javascript1.2\" type=\"text/javascript\">
function refresh() {
var url = \"index.php\";
window.location.href = url;
}
alert(\"User ID not found, please retry\");
refresh();
</script>";
} else {
if ($data = mysqli_fetch_array($result)) {
$passwd = $data['password'];
$login = $data['login'];
$level = $data['level'];
$dept = $data['dept'];
}
// Check user online status
if ($passwd == $Password) {
if ($login == "T") {
echo "<script language=\"javascript1.2\" type=\"text/javascript\">
function refresh() {
var url = \"index.php\";
window.location.href = url;
}
alert(\"This User is already login, please logout first or contact administrator\");
refresh();
</script>";
} else {
$data = mysqli_query($db, "update sysuser set login = 'T', ip = '$ip' where id = '$ID'");
if (!$data) {
echo "<script language=\"javascript1.2\" type=\"text/javascript\">
function refresh() {
var url = \"index.php\";
window.location.href = url;
}
alert(\"Login failure, Please retry or contact administrator\");
refresh();
</script>";
} else {
$cookie_data = $_COOKIE['cookie_data'];
if (!isset($cookie_data)) {
$C_ID = $ID;
$atime = strftime('%H:%M:%S');
$value = $C_ID.'&'.$atime.'&'.$ltime.'&'.$level.'&'.$dept;
setcookie ("cookie_data",$value, time() + 60*60); //set cookie
} else {
$cookie_info = explode("&", $cookie_data);
$C_ID = $cookie_info[0];
$atime = $cookie_info[1];
$ltime = $cookie_info[2];
$level = $cookie_data[3];
$value = $C_ID.'&'.$ltime;
setcookie ("cookie_data",$value, time() + 60*60*24);
}
header("Location: index.php?user=$ID&dept=$dept");
}
}
} else {
echo "<script language=\"javascript1.2\" type=\"text/javascript\">
function refresh() {
var url = \"index.php\";
window.location.href = url;
}
alert(\"Password wrong, please retry\");
refresh();
</script>";
}
}
}
?>
i'm using the internal server to public our company internal website.