[PHP] Check Existed Username

Joined
Dec 15, 2009
Messages
1,382
Reaction score
236
So here's what I did:

PHP:
elseif (mysql_num_rows(mysql_query("SELECT Username FROM members WHERE Username = '$reg_username'"))){
$msg1 = 'Username Not Available!<br />';
$user = 'denied';
$status= 'denied';
$reg_username = $_POST['reg_username'];}

It works actually however I frequently (not usually but most of the time) receive this error:

Code:
Warning: mysql_num_rows(): supplied argument is not a valid MySQL result resource in C:\AppServ\www\Class2c1\register-testing.php on line 51

Can anyone explain what's the meaning this particular issue?
 
From my understanding you cannot have mysql_num_rows following with a mysql_query inside the bracket. It must be as follows:

Code:
$query = mysql_query("SOMETHING"); // Your query for username check.

if (condition)
{
    // Do something.
}
elseif (mysql_num_rows($query) == 0)
{
    // Do something else.
}
 
From my understanding you cannot have mysql_num_rows following with a mysql_query inside the bracket. It must be as follows:
That's because you don't understand PHP.

You had it right the first time.

I'm wondering, does the single-quote/apostrophe (') in the input account for "sometimes"?


Since MySQL isn't executed in PHP, it's as if you're using EVAL to bind user-input to the SQL language. If you didn't already know, eval is evil.

You should never, EVER directly bind input with eval- or any raw coding language.

Since PHP doesn't make evil code look obviously wrong as it is, I'll explain an easy solution for you: Use parameterized queries. Rather than placing user input directly into the query, PHP will send the data and the query separately.

Best way to stop SQL Injection in PHP - Stack Overflow

I'm not 100% sure you have a SQL injection or not- and I'm not sure if SQL injections is the root of your problem. This is something you need to do regardless since that evil practice (placing user input directly inside of any coding language) will cause problems and more coding later on.

Now that you need to relearn the way you do things, your question is irrelevant.

Furthermore, you should use a SQL query to select COUNT(*) rather than using mysql_num_rows.
 
So here's what I did:

PHP:
elseif (mysql_num_rows(mysql_query("SELECT Username FROM members WHERE Username = '$reg_username'"))){
$msg1 = 'Username Not Available!<br />';
$user = 'denied';
$status= 'denied';
$reg_username = $_POST['reg_username'];}

It works actually however I frequently (not usually but most of the time) receive this error:

Code:
Warning: mysql_num_rows(): supplied argument is not a valid MySQL result resource in C:\AppServ\www\Class2c1\register-testing.php on line 51

Can anyone explain what's the meaning this particular issue?

Wait, you're setting $reg_username AFTER checking for it in the database? The error could come about when the query doesn't go through due to a missing variable.

Just inquisition, I'm not entirely sure that's the problem.
 
That's because you don't understand PHP.

You had it right the first time.

I'm wondering, does the single-quote/apostrophe (') in the input account for "sometimes"?


Since MySQL isn't executed in PHP, it's as if you're using EVAL to bind user-input to the SQL language. If you didn't already know, eval is evil.

You should never, EVER directly bind input with eval- or any raw coding language.

Since PHP doesn't make evil code look obviously wrong as it is, I'll explain an easy solution for you: Use parameterized queries. Rather than placing user input directly into the query, PHP will send the data and the query separately.

Best way to stop SQL Injection in PHP - Stack Overflow

I'm not 100% sure you have a SQL injection or not- and I'm not sure if SQL injections is the root of your problem. This is something you need to do regardless since that evil practice (placing user input directly inside of any coding language) will cause problems and more coding later on.

Now that you need to relearn the way you do things, your question is irrelevant.

Furthermore, you should use a SQL query to select COUNT(*) rather than using mysql_num_rows.
I'm not sure what are you trying to explain, its way too complicated bro.
 
PHP:
<?php
$run = mysql_query("SELECT Username FROM members WHERE Username = '$reg_username'");
$check = mysql_num_rows($run);
if($check=="1"){
echo "That username is in use";
}else{
//whatever code
}
?>

Anywho thats the basic script to check it. I am just as new as you are. good luck!
 
Wait, you're setting $reg_username AFTER checking for it in the database? The error could come about when the query doesn't go through due to a missing variable.

Just inquisition, I'm not entirely sure that's the problem.
Hehe, nice catch. This could definitely be a problem. But, I would assume that either PHP would error out or the MySQL query would run successfully, as it should, with an empty string.

As s-p-n said, this code is easily SQL injectable, and you should look into parametrized queries and binding parameters with either MySQLi or PDO. But I wouldn't think that would be the sole cause of this error.

If your query is erroring out, then it should not be able to run mysql_num_rows on it, and thus it would output the PHP error that you are seeing. You may want to check for errors in the MySQL query result before running mysql_num_rows.
 
Hehe, nice catch. This could definitely be a problem. But, I would assume that either PHP would error out or the MySQL query would run successfully, as it should, with an empty string.

As s-p-n said, this code is easily SQL injectable, and you should look into parametrized queries and binding parameters with either MySQLi or PDO. But I wouldn't think that would be the sole cause of this error.

If your query is erroring out, then it should not be able to run mysql_num_rows on it, and thus it would output the PHP error that you are seeing. You may want to check for errors in the MySQL query result before running mysql_num_rows.

All I know, is that mysql_num_rows is really funky and errors out when the input query isn't perfect. I've had unexplainable problems before with it. The mysql query might error out when it has a missing variable, causing the num_rows to mess up.

With that said, you (NubPro) should add "or DIE(mysql_error());"
to the end. If I were to do this particular code, this is how I would have it:

PHP:
<?php
$username = mysql_real_escape_string($_POST['reg_username']);
$query = mysql_query("SELECT `Username` FROM `members` WHERE `Username` = '$username'") or DIE(mysql_error());

if(!mysql_num_rows($query)) {

 //whatever is up here

} else {

 $msg1 = 'Username Not Available!<br />';
 $user = 'denied';
 $status= 'denied';
 $reg_username = $username;

}

Give that a shot and tell me if any errors are posted when you run it, or anything. :thumbup:
 
Last edited:
1. Put an index on the username field (it should already have one), because this will eventually be slow.
2. Use SELECT COUNT(*)..., and this will use that index.

In general, use everything every query returns to you. Check explains if you ever want to see what's going on.
 
Back