mysql_connect($server, $user, $password) or die(mysql_error()); //Connect to MySQL Server
mysql_select_db($my_db) or die(mysql_error()); //Select MySQL Database

if (isset($_POST['submit'])) {
		$user=mysql_real_escape_string($_POST['username']); //Escapes String Characters in Username
		$pass=md5($_POST['password']); //Encrypts Password
		$sql = "SELECT * FROM users WHERE username='{$user}' && password='{$pass}'"; // SQL Quary
		$result= mysql_num_rows(mysql_query($sql));
		if ($result == 1) {
			$_SESSION['logged'] = true;
         		$_SESSION['username'] = $user;
        		$_SESSION['password'] = md5($_POST['password']);
		 		echo 'Login Successful';
		else {
	 		$_SESSION['logged'] = false;
			echo '<p>Incorrect Login please try again</p>';

