How is the password sent from browser to server in case of non-ssl transfer?
I want to use bcrypt to hash password+salt before sending.... but it seems there is no javas
Maybe you can try to implement the APOP command http://www.ietf.org/rfc/rfc1939.txt