Well, I'm not sure if there are tools avaliable to hackers (probably are) But I'm pretty sure you cannot "guess" your way into all three.
If a member trys to access the vBulletin ACP they will just get a password protected box, they would have to know the address of your cpanel to start with, then they would have to guess your username which is pretty hard to do as it can be anything and they would have to guess your password, which is very unlikely to happen, same with the FTP, they would have to know either the ftp address or the server ip and your FTP username/ pass which, again would be hard to guess.
|