Thete are definitely password gurssing attacks that occur on a continuous basis all over the web.
You should use OTP (2 factor) for all remote access.
DouglasFoster just so you know this thread (2004 old one) got necro'd by previous poster (the one above douglas to advertise for a commercial solution.