using System; using System.Configuration; using System.Data; using System.Linq; using System.Web; using System.Web.Security; using System.Web.UI; using System.Web.UI.HtmlControls; using System.Web.UI.WebControls; using System.Web.UI.WebControls.WebParts; using System.Xml.Linq; using System.Data.SqlClient; public partial class _Default : System.Web.UI.Page { protected void Page_Load(object sender, EventArgs e) { if (!IsPostBack) { ViewState["Loginerrors"] = 0; } } private bool validate(String Uname, String Pwd) { bool val = false; SqlConnection con = new SqlConnection(ConfigurationSettings.AppSettings["sqlcon"].ToString()); string qry = "Select Uname, Pwd FROM login"; SqlCommand cmd = new SqlCommand(qry, con); SqlDataReader dr; con.Open(); dr = cmd.ExecuteReader(); while (dr.Read()) { if ((Uname == dr["Uname"].ToString()) & (Pwd == dr["Pwd"].ToString())) { val = true; } dr.Close(); return val; } return val; } protected void Login1_Authenticate(object sender, EventArgs e) { if (validate(Login1.UserName,Login1.Password)) { Login1.Visible = false; Label1.Text = "Success"; } else { Label1.Text = "Failed"; } } } Is this code efficient for login