protected void login_Click(object sender, EventArgs e) { SqlConnection cn = new SqlConnection(); cn.ConnectionString = System.Web.Configuration.WebConfigurationManager.ConnectionStrings["cn"].ToString(); cn.Open(); string str = "select * from reg where Email='" + email.Value + "' and Pass='******'"; SqlCommand cmd = new SqlCommand(str, cn); SqlDataReader dr = cmd.ExecuteReader(); if (dr.Read()) { if (dr[10].ToString() == "0") { if (dr[9].ToString() == "0") { Session["uname"] = email.Value; Response.Redirect("index.aspx"); } else { otp = rand(); abc A = new abc(); A.otpsave(otp, email.Value); returnname r = new returnname(); em.send_maill(r.name(email.Value), email.Value, 3, otp); Response.Redirect("ChkOTP.aspx"); } } else { alert.Visible = true; Label4.Text = "Your Account has been deactivated"; } } else { alert1.Visible = true; Label3.Text = "OOPs! Check your E-mail & Password"; } cn.Close(); }