I am running windows 2000 with iis 5 and ftp... I noticed in my log files that someone was trying to crack the username and password of an ftp account on our server.  It appears to be happening in rapid succession.   Is there anything from a security standpoint I can do to prevent this?  I.e. pause after so many failed attempts etc.

Please advise.

Commented:
See here:

but I think the Administrator account can't be locked out. For that one, be sure to set a sufficiently long password that can't be cracked or guessed.
Commented:
Unfortunately IIS doesn't have an anti brute-force mechanism (none that I know of anyway). The only thing you can do is to use the IP access list of IIS and block the IP of the attacker. If your server is not public you can also limit access only to the IP's of the legitimate users.
Commented:
If they are trying for the administrator account, one best practice for securing a windows box is to RENAME the administrator account to something else - security by obscurity. I'll ocasionally look through logs and find brute force attempts for an account named administrator, but I can rest assured, because there is no account named administrator... Just pick a clever name and substitute it (rename it)
