Nice Work , thus something small
  1. give administrator folder another name . which only you can remember
  2. block joomla 1.7 "index.php/login?view=reset&layout=complete" since one can add a SQL injection to the link

Mambo good though