Buyur login sayfasini yeniden yazdim :

<?php
ob_start();
session_start();
include("../config.php");
$giris=$_SESSION["giris"];
$yetki=$_SESSION["yetki"];
if(!empty($giris) && $yetki=="1"){
header("Location:home.php");
exit();
}
?> 
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> 
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en"> 
<head> 
    <meta http-equiv="Content-Type" content="text/html; charset=utf-8" /> 
    <meta name="robots" content="noindex,nofollow,nosnippet,noodp,noarchive,noimageindex">     
    <link rel="stylesheet" media="screen,projection" type="text/css" href="css/reset.css" />  
    <link rel="stylesheet" media="screen,projection" type="text/css" href="css/main.css" />  
    <!--[if lte IE 6]><link rel="stylesheet" media="screen,projection" type="text/css" href="css/main-ie6.css" /><![endif]--> 
    <link rel="stylesheet" media="screen,projection" type="text/css" href="css/style.css" />  
    <link rel="stylesheet" media="screen,projection" type="text/css" href="css/mystyle.css" /> 
    <title>Yönetim Paneli</title> 
</head> 

<body> 

<div id="main"> 

<div id="content" class="box" align="center"> 
    <br><br><br><br><br><br> 
    <a href="index.php"><img src="design/logo.png" border="0" /></a> 
    <br><br><br><br><br><br> 
    <?php
	if($_POST){
	$username=trim(strip_tags(mysql_real_escape_string($_POST["username"])));
	$password=trim(strip_tags(mysql_real_escape_string($_POST["password"])));
	if(empty($username) || empty($password)){
	echo '<p class="msg error" style="width:300px;"><b>Alanlari bos geçemezsiniz!</b></p><br>';
	}else{
	$password2=md5($password);
	$count=mysql_num_rows(mysql_query("SELECT * FROM administrator WHERE username='$username' AND password='$password2'"));
	if($count!=0){
	$row=mysql_fetch_assoc(mysql_query("SELECT * FROM administrator WHERE username='$username' AND password='$password2'"));
	$rowusername=$row["username"];
	$rowpassword=$row["password"];
	$rowaccess=$row["yetki"];
	$_SESSION["giris"]=$rowusername;
	$_SESSION["yetki"]=(int)$rowaccess;
	echo '<p class="msg done" style="width:300px;"><b>Giris yapildi.</b></p><br>'; 
    echo '<script language="javascript">location.href="home.php";</script>';  
	}else{
	echo '<p class="msg warning" style="width:300px;"><b>Kullanici Adi yada Sifre Hatali!</b></p><br>';
	}
	}
	}
	?>
  
     <form method="post"> 
                        <dl> 
                            <dt><label for="email">Kullanici Adi</label></dt> 
                            <dd><input type="text" name="username" class="dsaciklama" /></dd> 
                        </dl> 
                        <dl> 
                            <dt><label for="password">Sifre</label></dt> 
                            <dd><input type="password" name="password" class="dsaciklama" /></dd> 
                        </dl> 
                         
                         <dl> 
                        <input type="submit" name="gonder" value="Giris Yap" style="background: #E6E6E6; border: 1px solid #ccc; padding: 3px 7px; border-radius: 3px; color: #000; cursor:pointer" /> 
                         </dl>        
    </form> 
        <br><br><br><br> 
</div>  

</div>  

<hr class="noscreen" /> 

<div id="footer" class="box"> 
    <p class="f-left"><a href="http://www.site.com/" target="_blank">Site.com</a></p> 
</div>  

</body> 
</html>
Kontrol yapmak icin :

ob_start();
session_start();
$giris=$_SESSION["giris"];
$yetki=$_SESSION["yetki"];
if(!empty($giris) && $yetki=="1"){
include("../config.php"); 
}else{
header("Location:404.html");
exit();
}