Humm there is a huge flaw that has been in this since v1.
Ok, basicly the bot goes to the page, detects its this style of auth and instead of trying to guess the correct image, it just does them all. What i mean is... it loads this page /register.php?clicked=1 increasing the clicked number each time using the same cookies. Once it guesses the correct number, it can continue to register.
~Cmd
|