1. Someone mentioned a brute-force FTP attack, with the log showing about 10 attempts per second. Is it not possible to restrict attempts to the same account, to only once per ten seconds or more?
2. I think cPanel has an option to disable FTP access, unless you enable it in the Control Panel for say, 60 minutes, before it automatically closes access. I wouldn't necessary endorse this, as it could enable a keyboard logger to then gain access to your Control Panel. Tublr has a nice option where you can post a message using a secret email address. I wonder whether a secret email could be used to enable FTP access for limited time. eg. ftp-secret-code-2255$$@mydomain.com