This tutorial keeps the original Classic ASP/MSSQL login flow—collect credentials, find the user, verify the password, then create Session state—but updates the security guidance.
If IsEmpty(Session("userid")) Then %>
<form method="post" action="loginck.asp">
<input type="text" name="userid" autocomplete="username">
<input type="password" name="password" autocomplete="current-password">
<button type="submit">Log in</button>
</form>
<% Else
Response.Write "You are already signed in."
End IfDim userid, password
userid = Trim(Request.Form("userid"))
password = Request.Form("password")Use Request.Form for POSTed credentials rather than the combined Request() collection.
Dim RExp : Set RExp = New RegExp
RExp.Pattern = "^[A-Za-z0-9._-]{3,50}$"
If Not RExp.Test(userid) Then
Response.Write "Invalid user ID format."
Response.End
End IfValidation controls the allowed user-ID format; it is not the SQL-injection defense. Parameter binding handles data values safely in SQL.
Set cmd = Server.CreateObject("ADODB.Command")
Set cmd.ActiveConnection = conn
cmd.CommandText = "SELECT userid, password_hash FROM member WHERE userid = ?"
cmd.CommandType = 1 ' adCmdText
cmd.Parameters.Append cmd.CreateParameter("@userid", 200, 1, 50, userid)
Set rs = cmd.ExecuteADO's Command and CreateParameter() APIs let the provider receive the user ID as data instead of concatenating it into the SQL text.
' After retrieving the user, verify the submitted password with
' a vetted Argon2id/bcrypt/PBKDF2 password-hashing component.
If Not rs.EOF Then
' passwordOk = PasswordVerifier.Verify(password, rs("password_hash"))
If passwordOk Then
Session("userid") = rs("userid")
Response.Redirect "mem/index.asp"
End If
End IfClassic ASP/VBScript does not provide a modern built-in password-hashing API comparable to current frameworks. Use a vetted component/service that supports a password-specific algorithm such as Argon2id, bcrypt or PBKDF2. Do not substitute MD5, SHA-1 or a single fast SHA-256 hash.
Return a generic login failure message so the response does not reveal whether the user ID or password was incorrect. Use HTTPS for all authentication traffic.
Author & Instructor at plus2net
I write and maintain practical tutorials on Python, PHP, SQL, JavaScript, HTML, jQuery, and web development at plus2net. The tutorials focus on clear explanations, working examples, and code that readers can test and adapt while learning.