I changed locations for my admin and mod areas.
Never had an issue with false logins unless its me screwing up (happens often).
I made a fake admin/mod area that ultimately leads to a trap and .htaccess bans that ip address.
Nice simple easy solution.
I imagine these attacks are automated and looking for /admincp/ sort of thing.
I highly recommend renaming your admin and mod areas.
Not to mention hiding your version number as they often use the 2 as a means of targeting the desired board.
|