This is really a Joomla question but I'll post here as you get better responses than from jooml.org.
I've just noticed in the backend of Joomlawatch a 'Bot' has tried to access the following url on my site
with the page title 'Forgot Your Password' and asking for a Token
Should I be worried?? I've blocked access for this particular IP address sofar. Are there any other precautions other than a secure user name and password which is already in place. I'm running version 1.5.10