Re: Easily remembered... most attacks they are guessing the username too.....

Er, why? Company records, directors' names. If there's a director called Roger Bellend, try "rbellend", "roger.bellend" and "" (the last only if they're a bit techy and hate their users enough to make 'em type that shit).

One of those should work and with a bit of luck, being a director, he'll have insisted on having a bit more access than he should have, the "three strikes" on dodgy passwords being disabled and session logging turned off.

