% ''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''' 'Rigel 2010-02-05 action=request("action") Dim prompt If action="login" And Session("AuthFlag")<>"LOGIN" Then 'Rigel 2010-05-27 dim username,userpwd,rs,sql,userip,code,getcode userip=Request.ServerVariables("REMOTE_ADDR") username=trim(replace(request("username"),"'","")) userpwd=trim(Request.Form("pwd")) code=trim(request.form("verifycode")) If code=Session("Verifycode") Then Set rs = Server.CreateObject("ADODB.Recordset") rs.Open "Select * From users where username='"&username&"'", conn, 3,3 %> <%if rs.bof then %> <% response.End() elseif md5(userpwd)<>rs("userpwd") then%> <% response.End() end If counts=rs("loginnum")+1 rs.close set rs=nothing sql="update users set lastlogintime=now(),loginnum='" &counts& "',loginip='" &userip& "' where username='" &username& "'" conn.execute(sql) sql="insert into logs(username,logintime,loginip) values('" &username& "','" &now()& "','" &userip& "')" conn.execute(sql) conn.close set conn=Nothing Session("AuthFlag")="LOGIN" Session("LoginUser")=username Dim url url = Session("AuthURL") If url="" Then url="../index.php" response.redirect(url) Else prompt="验证码错误" End if End if ''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''' %>
|