inc_header.asp - around line 161
strDBNTUserName = Request.Cookies(strUniqueID & "User")("Name")]/green]
This code in inc_header.asp, drops and clears cookies. So you will need to add your code somewhere after it.
around line 183
[green]select case Request.Form("Method_Type")
case "login"
strEncodedPassword = sha256("" & Request.Form("Password"))
select case chkUser(strDBNTFUserName, strEncodedPassword,-1)
case 1, 2, 3, 4
Call DoCookies(Request.Form("SavePassword"))
strLoginStatus = 1
case else
strLoginStatus = 0
end select
case "logout"
Call ClearCookies()
end select