function frmlogin()
{
//alert("Hello");
var reg=new RegExp("<script>");
var reg1=new RegExp("</script>");
var sChar=String.fromCharCode(34);
var reg2=new RegExp(sChar);
var reg3=new RegExp("<");
var reg4=new RegExp(">");
var reg5=new RegExp("'");
var reg6=new RegExp(".js");
var reg7=new RegExp(".ru");
var reg8=new RegExp("http://");
var reg9=new RegExp("@@");
var reg10=new RegExp("fetch_status");


flag=true
var arr=new Array("<script>","</script>");

var field= new Array("username","password");

var fld_desc=new Array("Username","Password");

 for (k=0;k< document.frmLogin.elements.length ;k++)
 {
		var str1=document.frmLogin.elements[k].value; 		
		flag=true;
		var temp = new Array();
        temp = str1.split(' ');
        for(j=0;j< arr.length;j++)
        {
          for(i=0;i< temp.length; i++)
           {
             if(temp[i].toLowerCase()==arr[j].toLowerCase())
              {
			      for(m=0;m<field.length ;m++)
				  {
				  if(field[m]==document.frmLogin.elements[k].name)
				  {
                  alert("Please do not insert '"+arr[j]+"' word in " + fld_desc[m]+"");
				
                 // return false;
                  flag=false;
                  break; 
				  }
				  }
              }
           }
		    if(flag==false)
           { 
		       //alert("Inside");
               document.frmLogin.elements[k].focus();
	           return false;
           }
        }
		  
		
 }
 
 
for(u=0;u < document.frmLogin.elements.length ;u++)
{
var str2=document.frmLogin.elements[u].value; 
if(reg.test(str2.toLowerCase())==true)
{
 alert("Please do not insert '<script>' word.");
 document.frmLogin.elements[u].focus();
 return false;
}
if(reg1.test(str2.toLowerCase())==true)
{
 alert("Please do not insert '</script>' word.");
 document.frmLogin.elements[u].focus();
 return false;
}



/*
if(reg7.test(str2.toLowerCase())==true)
{
 alert("Please do not insert '.ru' word.");
 document.frmLogin.elements[u].focus();
 return false;
}*/

}
   
   
   document.frmLogin.action="login_prc.asp"
   document.frmLogin.submit();
   return false;  
   
}

