There are a number of methods you can use to secure your administration against unauthorized access – we recommend you implement as many of these methods as possible.
More:
Change the name of shopadmin.asp
Using two passwords to login
Validating IP address of person trying to login
Email on successful login
Delete default usernames and passwords
Activating the config “xAdminCheckSecurityCode”