Your method is nice and would be ok in situations where only previously known users can access your application.
As a variation, in the webserver/ISP setting one could think of putting the user/encrypted_password table in a flat file readable from the application. It would avoid the problems with double permissions and under some conditions it would be faster than accessing the database.
One problem I see is that if the attacker can change your application files, it can intercept the cleartext password between steps 3 and 4.
In reply to Re: Re: Protecting your DBI user/password in scripts?
by abell
in thread Protecting your DBI user/password in scripts?
by JPaul
| For: | Use: | ||
| & | & | ||
| < | < | ||
| > | > | ||
| [ | [ | ||
| ] | ] |