| The "dictionary attack* has several variants, of which one is "try all usernames ever harvested, against all common domains". And to some extent, yahoo et al have developed some defenses against it, though they are far from robust. In an environment where a given spammer may be routing traffic through 20K bots on 20K virus-infested systems on the same number of different IP addresses, so that there's no single point of origin and the flow is intermittent from each, it can be remarkably difficult to keep up with which senders are bots and which aren't. |