CFFTP, CFLDAP and securing passwords


good afternoon. have several applications use tags such cfftp , cfldap. these applications not prompt user input, rather automatically supply application username , password required db lookup. currently, passwords stored in plain text in db (sql 2k)...yes, know...horrible!!! how secure these passwords or @ least secure passing passwords tags, not in plain text? since automatically supplying these passwords, can't use salting , hashing, right? expedient assistance appreciated. thank you.

chris

hi chris,

you should storing passwords one-way hash in database won't sftp problem. if using sftp passwords not sent server in plain text anyway, difference giving on sftp tag query column, in plain text anyway. if understand correctly want retrieve usernam , password database, encrypt password, pass username, password , encryption key function unencrypt password , pass sftp tag? have give unencrypted password tag since imagine password on server not encrypted.

that seems lot of overhead absolutely no increase in security.


More discussions in Advanced Techniques


adobe

Comments

Popular posts from this blog

VIDIOC_S_FMT error 16, Device or resource busy - Raspberry Pi Forums

using a laptop skeleton to build a pi laptop - Raspberry Pi Forums

Forum for Joomla? - Joomla! Forum - community, help and support