Your server needs proper security.. brute force attacks are all too common (my servers ban dozens of IP's daily for these) If your web host does not run some type of protection from brute force attacks, you need a new host..
ALSO Make sure your mysql db password in the config file is uber complex as well.. good hackers really do not use the GUI in most cases.. they inject code through an insecure script and it may not even be related to your forum...
Good luck... for me? a server gets hacked and it is full system dump and reload of the OS...
|