Using a PHP Script to do this work (as I'm using right now) requires first a WEB Server and second needs more time to process. But gives the opportunity to sanitize the input (remove bad/exploit characters from the strings).
Never use usernames/passwords for a sql server in client applications, it can be captured with software as it is making its way out of your lan card. And make sure you remove any '-"; characters from your input strings before sending them.
Sanitation localy (for dumb players 'wannabe hackers') and then on a remote WEB server (for serious 'penetration testers')...
Are you refering an "I" , "diot" to yourself here? I didnt understand...
If you are going to give meaningless replys , dont reply at all! Say something useful!
PS.: I'm trying to help. You're trying to 'look cool'. Not working...