account=ReplaceBadChar(Trim(request.form("ac")))
password=ReplaceBadChar(Trim(request.form("pw")))
sqlStr="select * from WP_admin where admin_account='"&account&"' and admin_password='"&md5(password)&"'"
set rs = server.createobject("ADODB.RecordSet")
rs.open sqlStr,conn,1,1
If rs.eof Then
response.redirect("error.asp?err=1902")
Else
session("admin")=account
response.redirect("main.asp")
End If
rs.close
Set rs=Nothing
Set conn=nothing
%>