Get something like Password Nazi and/or other software to monitor attacks on your server. There are ways to slow down/sop brute force attacks. Probably the most effective is to spew out fake positives (don't return a HTTP forbidden response, return a 200 OK to a banner farm or something).
That's just a generalization, but do a search on Google or cgi-resources.com
SpaceAce
|