better-staridc-MNBT
1<?php
2include("../MPHX/common.php");
3mnbt_set_auth_cookie("user_token", "", time() - 604800);
4@header('Content-Type: text/html; charset=UTF-8');
5$egn=$_REQUEST['gn'];
6if($conf['yzme']=='true')exit("<script language='javascript'>alert('后台已经开启控制面板验证码登陆无法进行一键登录!');window.location.href='./login.php';</script>");
7?>
8<?php
9if($egn=='logine'){
10if(isset($_REQUEST['username']) && isset($_REQUEST['password'])){
11 $user=daddslashes($_REQUEST['username']);
12 $pass=daddslashes($_REQUEST['password']);
13 if(strpos($user,'"') || strpos($user,"'") || strpos($user,',') || strpos($user,'/') || strpos($user,"\\"))exit('{"code":"账号不能包含危险字符!"}');
14 $wedsv=$DB->get_row_prepare("SELECT * FROM MN_zj WHERE user=? limit 1", [$user]);
15 if($user==$wedsv['user'] && $pass==$wedsv['pass']) {
16 unset($_SESSION['authcode']);
17 $session=md5($user.$pass.$password_hash);
18 $token=authcode("{$user}\t{$session}", 'ENCODE', SYS_KEY);
19 mnbt_rotate_login_session();
20 mnbt_set_auth_cookie("user_token", $token, time() + 604800);
21 @header('Content-Type: text/html; charset=UTF-8');
22 header("Location:index.php");
23}else{
24 @header('Content-Type: text/html; charset=UTF-8');
25 exit('用户名或密码错误!');
26 }
27}
28}elseif($egn='xz'){
29header("Location:login.php");
30}else{
31exit('错误代码-404');}
32?>