03-Jan-2011, 10:31 PM
Perhaps it would be safer to send the passwords during login in an already encrypted form? Currently (as far as I know), the script sends the unencrypted password over an unencrypted network (most of the time).
example: http://pajhome.org.uk/crypt/md5/
more info: http://pajhome.org.uk/crypt/md5/advancedauth.html
example: http://pajhome.org.uk/crypt/md5/
more info: http://pajhome.org.uk/crypt/md5/advancedauth.html
I'm giving you three guesses...