A webscarab fuzzer which is often used for brute forcing, by sending huge number of customized HTTP requests cannot be used for:
Finding default files and directories
Finding maximum attempts for account lockout
Finding a password for a given user ID
Finding the information displayed on a validation CAPTCHA