QUOTE (LS Support @ Dec 30 2014, 01:59 AM)

I agree, and this forum's older software may even provide entry points. I've tried to lock it down best I can but you know how that goes.
The attack I had was a "Brute force" attack, sending millions of password guesses. This spiked the server load, and I got an automatic notification from my hosting company. We are on a business/enterprise class commercial server.
Here is what my hosting company did.
They put a Bot Crawl Delay on my server. After so many hits, it puts in a delay of 3 seconds or more. Now, a malicious bot that was hitting the serve maybe hundreds of times a second, was S L O W E D to a crawl, and finally gives up and disconnects- Or even better, sits there wasting its time and not attacking other sites.
You are not a commercial site selling anything. You do not NEED SEO. You do not need Google et al hammering your site either.
Think of it this way. A fast talking pushy salesman is at your door. Suppose you forced him to count to ten in between every word he said.
How long would he stick around?