Because of the SANS post today here, I have made a post on my site (codingfriends) on two ways that I make a brute force attack hopefully abit more harder.
Basically by having a password generated, and also changing the admin user login name to something else since that is what the brute force attack was using. I have outlined the sites and also the sql that can do this on my site at codingfriends
Has another one else got any other suggestions, since I am using a dynamic IP address then I cannot just stop access to a static IP.