In a case like this, would this work: create a /cfide/administrator/ directory in every website... and have an index.cfm file there that looks like the real administrator log in, but responds that every password is invalid... and also bans that IP address from the rest of the websites on the server? This way - they waste thier time hitting a page that has no database connection so it shouldn't tax the server too much - and it won't allow them in on the real pages?
>As long ad you do have a real cfide vdir in the site, which u need for >ajax,.cfform etc anyway, then you wont have that problem. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~| Order the Adobe Coldfusion Anthology now! http://www.amazon.com/Adobe-Coldfusion-Anthology/dp/1430272155/?tag=houseoffusion Archive: http://www.houseoffusion.com/groups/cf-talk/message.cfm/messageid:354641 Subscription: http://www.houseoffusion.com/groups/cf-talk/subscribe.cfm Unsubscribe: http://www.houseoffusion.com/groups/cf-talk/unsubscribe.cfm

