UserName = HtmlEncode(Uname.Text.Trim().ToString()); UserPass = GetMd5(HtmlEncode(Upass.Text.Trim().ToString())); string StrSql = "select top 1 id from admin where username=@username and userpass=@userpass and is_open=true and is_admin=true"; MyDBlink.GetSqlCommand(StrSql); MyDBlink.comm.Parameters.AddWithValue("@username", SqlDbType.VarChar); MyDBlink.comm.Parameters["@username"].Value = UserName; MyDBlink.comm.Parameters.AddWithValue("@userpass", SqlDbType.VarChar); MyDBlink.comm.Parameters["@userpass"].Value = UserPass;