How do you get around 3x login fail?
and captcha
folk that do this sort of thing will scan for proxies and rotate them
the ip is only banned for a few mins,
personally i think its trivial and boring but those that are into this sort of thing
will have tens of thousands of working proxies
also its not only used for websites
many forms of captcha were defeated years ago, with recognition algorithms with 80-90% accuracy
ill admit it tends to be used by folk who do not have the knowledge to use other methods
like (generating valid session cookies)
a friend of mine a few years ago was able to reverse engineer the login dlls of yahoo and windows messenger
from this he was able to crack the algorithm/encryption these programs use to authenticate
when you enter a user name and password it is converted to a session cookie basically using md5 sha1 and various other encryption methods
reversing the dlls and a good knowledge of cryptography allows this to be found
hashed cookies are used for logins so sites do not keep a database of actual usernames and passwords
he was able to generate valid login session cookies and take any account
caused a bit of a storm in a t-cup for a while
cracking can also be used for hardware like routers etc to steal peoples wifi
some routers generate automatic passwords, the algorithm that generates the password
can be cracked, it is also similar to how "keygens" work to crack software