was this a phishing attack that got the "hacker" in?!?!
I thought that in this day and age, all password authentication on the web has some sort of a lockout mechanism after X tries that keeps you from logging in for a period of time or after an added layer of authentication... although not sure a "captcha" would be sufficient if this was an automated tool attack.
|