Skip to Content
ADO.NET Cookbook
book

ADO.NET Cookbook

by Bill Hamilton
September 2003
Intermediate to advanced
624 pages
14h 27m
English
O'Reilly Media, Inc.
Content preview from ADO.NET Cookbook

5.8. Transferring Login Credentials Securely

Problem

You need to protect login credentials during transmission over the network and when they are stored within a database.

Solution

Use password hashing and salting with the .NET FormsAuthentication class to control user authentication and access to the application.

The schema of table TBL0508 used in this solution is shown in Table 5-5.

Table 5-5. TBL0508 schema

Column name

Data type

Length

Allow nulls?

UserName

nvarchar

50

No

PasswordHash

nvarchar

50

No

PasswordSalt

nvarchar

50

No

The sample code contains two event handlers:

Create Button.Click

Creates a GUID-based salt and generates a hash of the password concatenated with the salt for a user-specified password. The username, password hash, and salt are inserted into a database.

Login Button.Click

Retrieves the salt and the hash of the password and salt from the database for the specified username. The user-entered password is concatenated with the retrieved salt and the hash is generated. If the hash matches the hash retrieved from the database, the user is authenticated.

The C# code is shown in Example 5-8.

Example 5-8. File: ADOCookbookCS0508.aspx.cs

// Namespaces, variables, and constants using System; using System.Configuration; using System.Web.Security; using System.Data; using System.Data.SqlClient; private const String TABLENAME = "TBL0508"; // . . . private void createButton_Click(object sender, System.EventArgs e) { // Create and display the password salt. String ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.

Read now

Unlock full access

More than 5,000 organizations count on O’Reilly

AirBnbBlueOriginElectronic ArtsHomeDepotNasdaqRakutenTata Consultancy Services

QuotationMarkO’Reilly covers everything we've got, with content to help us build a world-class technology community, upgrade the capabilities and competencies of our teams, and improve overall team performance as well as their engagement.
Julian F.
Head of Cybersecurity
QuotationMarkI wanted to learn C and C++, but it didn't click for me until I picked up an O'Reilly book. When I went on the O’Reilly platform, I was astonished to find all the books there, plus live events and sandboxes so you could play around with the technology.
Addison B.
Field Engineer
QuotationMarkI’ve been on the O’Reilly platform for more than eight years. I use a couple of learning platforms, but I'm on O'Reilly more than anybody else. When you're there, you start learning. I'm never disappointed.
Amir M.
Data Platform Tech Lead
QuotationMarkI'm always learning. So when I got on to O'Reilly, I was like a kid in a candy store. There are playlists. There are answers. There's on-demand training. It's worth its weight in gold, in terms of what it allows me to do.
Mark W.
Embedded Software Engineer

You might also like

ADO.NET 3.5 Cookbook, 2nd Edition

ADO.NET 3.5 Cookbook, 2nd Edition

Bill Hamilton
Microsoft® Access® 2010 Programmer's Reference

Microsoft® Access® 2010 Programmer's Reference

Teresa Hennig, Rob Cooper, Geoffrey L. Griffith, Jerry Dennison

Publisher Resources

ISBN: 0596004397Catalog PageErrata