Aim is to prevent (as much as possible) brute force attacks.
One solution php sleep(), but read that it uses much of server resources (for example, here http://bytes.com/topic/php/answers/745681-how-does-sleep-work).
Other solution, record number of logins in mysql, after 2nd or 3rd failed login, echo and validate captcha, after 5-6 failed logins set some timelimit (how to do without sleep())... etc. Question is: does such method will use less system resources?
Please advice on some good method to prevent brute force atacks... may be after certain number of failed login attempts to redirect somewhere, or to display some different content....?