%if session("admin")="" then response.redirect "gb_login.asp" end if%> <% dim username username=session("admin") if request("action")="post" then Set rs=Server.CreateObject("ADODB.Recordset") sql="select password from admin where username='"&username&"'" rs.open sql,conn,3,3 if request("password")=rs("password") then '不修改 else rs("password")=MD5(Server.Htmlencode(Request("password"))) end if rs.update rs.close set rs=nothing Response.Redirect"gb.asp" end if sql="select username,password from admin where username='"&username&"'" set rs=conn.execute(sql) if rs.eof or rs.bof then response.redirect "gb.asp" end if username1=rs("username") password=rs("password") rs.close set rs=nothing %>