Okay, now that I have a weekend project lined up, I now turn to finding a decent log scanning and firewalling daemon for the newer Linuxes that doesn't suck.
Or I move the one I wrote ages ago over to it. At least iptables is still in use so it shouldn't be too hard.
Been using Fail2Ban. Fail2Ban was running on the box that got nailed yesterday and should have caught the brute force attempts to get in but didn't for some odd reason.