Protected Sub Page_Load(ByVal sender As Object, ByVal e As
System.EventArgs)
        If User.Identity.IsAuthenticated Then
            Label4.Text = User.Identity.Name
        Else
            Label6.Visible = True
            TextBox1.Enabled = False
            Button1.Enabled = False
        End If
    End Sub
    Protected Sub Button1_Click(ByVal sender As Object, ByVal e As
System.EventArgs)
        Dim conn As New
SqlConnection(ConfigurationManager.ConnectionStrings("WroxUnitedConnectionString").ConnectionString)
        Dim trans As SqlTransaction = Nothing
        Dim cmd As New SqlCommand()
        Dim cmd1 As New sqlcommand()
        Try
            conn.Open()
            trans = conn.BeginTransaction
            cmd.Connection = conn
cmd.Transaction = trans
            ' set the order details
                      cmd.CommandText = "INSERT INTO variz(membername,
variz, varizdate) " & _
                             "VALUES ('" & User.Identity.Name & "'," &
TextBox1.Text & "," & Date.Today & " )"
cmd.ExecuteNonQuery()
Catch ex As Exception
        End Try
        
        
  
    End Sub
)
AS
	INSERT INTO variz(membername, variz, varizdate)
VALUES (@MemberName, @Variz, GETDATE())
----------------------------------------------------------------------------------------------------------------------
 Protected Sub Button1_Click(ByVal sender As Object, ByVal e As
System.EventArgs)
        Dim conn As New
SqlConnection(ConfigurationManager.ConnectionStrings("WroxUnitedConnectionString").ConnectionString)
        Dim trans As SqlTransaction = Nothing
            Dim cmd As New SqlCommand("storedvariz", conn)
        Try
            cmd.CommandType = Data.CommandType.StoredProcedure
            cmd.Parameters.AddWithValue("@MemberName",
User.Identity.Name)
            cmd.Parameters.AddWithValue("@Variz", TextBox1.Text)
            conn.Open()
            cmd.ExecuteNonQuery()
            conn.Close()