Gents,
adding to the above text i found out that disable file upload on PHP will stop the tries of attack.
any help.
thanx for the solution i will test it. any way i will not enable the editing on a working site. i made a portable wp installation using XAMPP in which solved my users requirements in editing themes.
i understand all the risks. i just want to know how to do it. i read on another post that it is possible but then they described the dangers of it instead of showing how.
thanks alot for the help it works.