Problem with changing the FTP user name and PW is that a lot of parts of the site are run by helpers that need access to do their bit to help (i dont have enough time to do it all) so the security can never be 100%, I know this is a security flaw, bit there's not much i can think of that can be dont to trace ftp access into the site?
IP banning doesnt seem to work because most technical people know how to change their ip address with in a couple of minutes if they need to
Its on a shared server, not sure if we have access to any access logs, i will check into that
cheers
|