Hab mal dein Script umgeschrieben, hab es aber nicht getestet.
<?php
if(isset($_POST['submit'])) {
$username = mysql_real_escape_string($_POST['username']);
$password = mysql_real_escape_string($_POST['password']);
$code = mysql_real_escape_string($_POST['code']);
if(empty($username) empty($password) empty($code)) {
$err = 'Füll bitte alle Felder aus.';
} else {
$query = mysql_query('SELECT password, secretcode FROM users WHERE username = \'' . $username . '\' LIMIT 1');
if(mysql_num_rows($query) > 0) {
$r = mysql_fetch_object($query);
if($password !== $r->password) {
$err = 'Ungültiges Passwort.';
} elseif($code !== $r->secretcode) {
$err = 'Ungültiger Sicherheitscode.';
} else {
$_SESSION['hksession'] = $username;
header('Location: http://HOTELLINK/');
}
} else {
$err = 'User wurde nicht gefunden.';
}
}
}
?>
<?php if($err) { echo $err; } ?>
<form action="" method="post">
<input type="text" name="username" placeholder="Username">
<input type="password" name="password" placeholder="Passwort">
<input type="text" name="code" placeholder="Sicherheitscode">
<input type="submit" name="submit" value="Login">
</form>