The word "miscellaneous" to me implies things like quotes, backticks, and similar non-alphanumeric characters. "Fiddling" with them would be attempting to find somewhere that didn't quote an input value correctly: they were attempting to find something like an SQL injection.
It wasn't much of a "brute force" attack, it wasn't SQL injection (though it's possible they were poking at that too), but just the simple question, what happens if we try to login five times with "miscellaneous" passwords? Hey, look, a captcha! I wonder what server the image comes from...
The Captchas, on the other hand, might have been using an existing software. Remember: These captcha images will have to be autogenerated by a script which, as a convenience to the user, might have used some kind of mechanism to determine "fully qualified" URLs. And this had slipped below the radar, as it's a feature used much less often, and hence likely to receive much less scrutiny.
I think it's pretty likely that these kinds of information leaks can happen when you deal with a larger codebase or system. Hence following the advice of some other HN users, who recommend a strictly firewalled system for this kind of use-case, looks like a prudent thing to do.
Deciding which way the decision should go must be causing quite a few hours of concentrated legal consideration - there are downsides in both directions for the government.
People who get caught trying to brute force servers (do people even get caught for this???) are the lowest hanging fruit and are the ones least harmful to society.
My point is precedent doesn't really matter, because realistically, you won't have anyone to actually prosecute except for the 13 year old "hacker" who had no idea what they were doing.