What measures can be taken to prevent SQL injection attacks in the login script and ensure secure data handling?

To prevent SQL injection attacks in the login script and ensure secure data handling, you should use prepared statements with parameterized queries. This approach helps to sanitize user input and prevent malicious SQL queries from being executed.

// Establish a database connection
$pdo = new PDO('mysql:host=localhost;dbname=your_database', 'username', 'password');

// Prepare a SQL statement using a parameterized query
$stmt = $pdo->prepare('SELECT * FROM users WHERE username = :username AND password = :password');

// Bind parameters and execute the statement
$stmt->bindParam(':username', $_POST['username']);
$stmt->bindParam(':password', $_POST['password']);
$stmt->execute();

// Check if the user exists and handle the login process
if ($row = $stmt->fetch()) {
    // User authenticated, proceed with login
} else {
    // Invalid credentials, display error message
}