|
dozey: spoilers not entertained, please understand that defending is not equal to attacking. i agree with your claims about free software to break a website's authentication using dictionary/bruteforcing ...
the fact stands plain, we look for all possible ways to get in, while the script-kiddies/nuisance creators look only at weak auth/passwords which are very lame.
we've got policies to update/educate the users of websites, and enable multifactor auth with ssl or something like ssl+tls ... instead of just letting the passwords getting transmitted through HTTP for people to pry/sniff/hijack... use any word.
don't spoil this thread please, it's a request.
|