This works (tested):
<?php
session_start();
mysql_connect('localhost', 'user', 'pass');
mysql_select_db('dbname');
if (isset($_POST['username']) && isset($_POST['password'])) {
$username = $_POST['username'];
$password = sha1($_POST['password']);
if (!empty($username) && !empty($password)) {
$query\_run = mysql\_query("SELECT id, password FROM users WHERE username = '$username' AND password = '$password' LIMIT 1");
if (mysql\_num\_rows($query\_run) == 0) {
echo 'Invalid username / password combination';
} else {
echo 'Ok.';
}
} else {
echo 'You must supply a username and password.';
}
}
?>
Username:
" />
Password:
" />