if ($_POST['submit'])
{
$db_host = "localhost";
$db_username = "xxxx";
$db_password = "xxxx";
$database = "xxxx";
mysql_connect(localhost,$db_username,$db_password);
@mysql_select_db($database) or die( "Unable to select database");
$passwordbeforemd5 = $_POST['password'];
$username = $_POST['username'];
$password = md5($passwordbeforemd5);
//Check user exists in database
$sql = mysql_query("SELECT * FROM users WHERE username='$username' AND password='$password' LIMIT 1");
$login_check = mysql_num_rows($sql);
if ($login_check == "1") {
$_SESSION['logged_in'] = true;
include ("xxxx.php");
}
else {
echo "we could not log you in";
}
}