Ok I have come a little bit further.
Some have been advising me to use a application wide login. I must use just one lgin with the DB and then Use a Session Variable to validate the users login and then to set their security level based on a lookup to the SQL Database.
I have never done something like this and how secure is my security now.
if anybody can help plz do so, any suggestion is welcome
thnx in advance