<html>
<body>
<p><H1>SQL INJECTION DEMO</H1></p>
<?php
    if(isset($_GET['login']))
    {
        $username = $_GET['username'];
        $password = $_GET['password'];
        $con = mysqli_connect('localhost','connect','secret','sample');
	//$con = mysql_connect('localhost', 'connecttt', 'secret'));
	if(!$con) {
	      echo "Connection failed to the host mysql server.";
	      exit;
	} // if
        $result = mysqli_query($con, "SELECT * FROM `users` WHERE username='$username' AND password='$password'");
        if(mysqli_num_rows($result) == 0)
            echo 'Invalid username or password';
        else
            echo '<h1>Logged in</h1><p>A Secret for you....</p>';
    }
    else
    {
?>
        <form action="<?=$_SERVER['PHP_SELF']?>" method="get">
            Username: <input type="text" name="username"/><br />
            Password: <input type="password" name="password"/><br />
            <input type="submit" name="login" value="Login"/>
        </form>
<?php
    }
?>
</body>
</html>

