<?php
if(isset($_POST['submit']) && empty($_POST['nick']) && empty($_POST['pw'])) {
echo "Bitte alle Felder ausfüllen!";
} else if (isset($_POST['submit']) && isset($_POST['nick']) && isset($_POST['pw'])) {
$nick = trim(mysql_real_escape_string($_POST['nick']));
$password = sha1(trim($_POST['pw']));
$sql = "SELECT * FROM userstabelle WHERE username = '".$nick."' AND password = '".$password."';";
$result = mysql_query($sql) or die(mysql_error());
$row = mysql_fetch_assoc($result);
if ($row["username"] == $nick && $row["password"] == $password) {
echo 'Login erfolgreich.';
}
} else {
echo "Du hast falsche Daten angegeben!";
}
}
?>