hallo ik had graag dit stukje willen beveiligen tegen sql injection maar ik kom er ni uit wat of waar ik alles moet zetten
PHP
$dbres = mysql_query("SELECT login,actief FROM `users` WHERE `login`='{$_POST['login']}' AND `pass`=MD5('{$_POST['pass']}')");
$info = mysql_fetch_object($dbres);$db1 = mysql_query("SELECT login FROM `users` WHERE login = '{$_POST['login']}' and actief = 0");
$db2 = mysql_query("SELECT login FROM `users` WHERE login = '{$_POST['login']}'");
$db3 = mysql_query("SELECT login FROM `users` WHERE login = '{$_POST['login']}' AND `pass`=MD5('{$_POST['pass']}')");if(mysql_num_rows($db1) > 0 ){
if(mysql_num_rows($dbinlog) == 0 ){
mysql_query("INSERT INTO inlogsysteem (`tijd`,`ip`,`aantal`) values(NOW(),'{$_SERVER['REMOTE_ADDR']}','1')");
$pogingen = 2;
}
elseif($infoinlog->aantal == 1){
mysql_query("UPDATE inlogsysteem SET `aantal`=`aantal` +'1' WHERE `ip` = '{$_SERVER['REMOTE_ADDR']}'");
$pogingen = 1;
}
elseif($infoinlog->aantal == 2){
mysql_query("UPDATE inlogsysteem SET `aantal`=`aantal` +'1' WHERE `ip` = '{$_SERVER['REMOTE_ADDR']}'");
$pogingen = 0;
}
Toon Meer