i dont think its as much hacking as it is password guessing. people are lazy and use the same passwords for everything, so when you find one, usually you get them all.
i remember a while back i got an email from some guy saying he hand 1000's of affiliate information that he got from a mysql db hack. i tried to call his bluff but he replied with all my personal info, including user name, password, social security, etc.
fucked up tho, hope you get your money back
|