The normal thing to do here is to use the credential just once to generate a (revocable) token, and to store that (reversibly encrypted). Especially if you own both sides of the connection, it is in fact a bad idea to store user passwords; they're irrevocable and inevitably shared across services.
As security advice for developers, the writeup you're commenting about isn't especially useful. But that's not the point. It's a standard consulting war story post, about how they managed step-by-step to exploit a weakness in an application. As a war story, it seems plenty competent.