<?php
// login.php
@session_start();
define('USERNAME', 'root');
define('PASSWORD', 'toor');
if (@$_SESSION['IS_LOGGED_IN']) {
header("Location: main.php");
}
if (isset($_GET['username'], $_GET['password'])) {
if (USERNAME == $_GET['username'] && PASSWORD == $_GET['password']) {
$_SESSION['IS_LOGGED_IN'] = true;
header("Location: main.php");
} else {
die('Incorrect login.');
}
}
?>
<?php
// main.php
if (!@$_SESSION['IS_LOGGED_IN']) {
header("Location: login.php");
exit;
}
echo 's00per secret text.';
?>
Written in the browser.