I have two techniques that I use together.
I pick a host where suExec is in force. That permits me to make best use of unix filesystem permissions for security. Nothing needs to be world-readable. I have to be cautious about the security of my programs, but I'd do that anyway (wouldn't I?).
User passwords don't need to be stored. Standard practice is to store a digest of the password, and compare the digest of the offered password to authenticate.
After Compline,
Zaxo
In reply to Re: Securing your scripts on webhoster's server
by Zaxo
in thread Securing your scripts on webhoster's server
by b10m
| For: | Use: | ||
| & | & | ||
| < | < | ||
| > | > | ||
| [ | [ | ||
| ] | ] |