Edit2: Jesus Christ, just reread what he wrote... Did he really say that you should hash it ON THE CLIENT?! Chaos, if you don't know what you are talking about, don't talk! Especially not when it comes to cryptography. Jesus. Fucking. Christ.

So you tell me to send the unhashed password to the script so it can compare the one from the sql table?
Where would you encrypt the password if not on client? wtf.