Login Security ASP.Net

<%@ Page Language="C#"%>

    protected void Button1_Click(object sender, EventArgs e)
    {
        if (FormsAuthentication.Authenticate(TextBox1.Text, TextBox2.Text)) {
            FormsAuthentication.RedirectFromLoginPage(TextBox1.Text, true);
        }
        else {
            Response.Write("Invalid credentials"); 
        }
    }



    Login Page


    
    

        Username
        
        
        Password
                 TextMode="Password">
        
                 Text="Submit" />
    

    


File: web.config