it is not a question of rights of user X, but the ability to spambot X to try any combination of username/password...
why do you think the net evoluted and brought encryption on password and logins ?!... because a spambot can try more than 50 000 combinations of random username/passwords per minute, trying to access your forum OR breaking your server by DDOS or DOSS... (denial of service)...
|