I would start by seeing if you can find any uniquely identifiable information about the attacker. Chances are, he reports the same user agent every time he hits -- If the user agent is an unusual (or unique) agent, just set up a mod_rewrite rule that forbids him. He won't even notice (cause he already gets forbid errors when he sends the wrong password), but he will never hit a correct password. You could also send a shorter forbidden document to save bandwidth, and if it persists for more than a few days, contact the proxy owners to let them know their open proxy's are being used for hacking attempts.
__________________
SIG TOO BIG! Maximum 120x60 button and no more than 3 text lines of DEFAULT SIZE and COLOR. Unless your sig is for a GFY top banner sponsor, then you may use a 624x80 instead of a 120x60.
|