if Instr(UserName,">")>0 or Instr(UserName,"<")>0 or Instr(UserName,"=")>0 or Instr(UserName,"%")>0 or
Instr(UserName,chr(32))>0 or Instr(UserName,"?")>0 or Instr(UserName,"&")>0 or Instr(UserName,";")>0 or Instr(UserName,",")>0 or Instr(UserName,"'")>0 or
Instr(UserName,chr(34))>0 or Instr(UserName,chr(9))>0 or Instr(UserName,"")>0 or Instr(UserName,"$")>0 then Response.Write ("")
Response.end else
UserName=Trim(UserName) end if
set rs=server.createobject("adodb.recordset")
sql="select * from [user] where UserName='"&UserName&"'" rs.open sql,conn,1,3 if rs.eof then