Fail: http://loonycgb.x10.mx/video.php?video=4' <-- mysql error = hackable website. Patch it up now using (int) before the GET. Eg; $_GET['video'] becomes (int)$_GET['video']

^ oh and http://loonycgb.x10.mx/members.php?id=3'

row[password]: c2bb0d67b3c1018717e11dcaa5133007b9389e997d561f266d 8ffae53a1508daf

Is that two MD5s put together or own encryption method?


--------------------------

Tip: change view counter to unique ip per 24 hours to stop fake counts eg; DDoS attack would end up showing 100 million hits for one video.