> Anything I should specifically look for to see if it is > compromised? I do have blackice defender - server version > installed, and it blocks a LOT of attempts..
If you have a host-based firewall installed, why are you allowing inbound NetBIOS traffic? I'd look at OS logs (especially logins if you have auditing enabled - I hope you do!), user accounts and groups, I'd look for any processes running that you don't recognize, and I'd look at inbound and outbound traffic with "netstat -A" at the command line, for starters. To be honest, I'm no expert at server forensics, though. Dave Watts, CTO, Fig Leaf Software http://www.figleaf.com/ voice: (202) 797-5496 fax: (202) 797-5444 ______________________________________________________________________ Structure your ColdFusion code with Fusebox. Get the official book at http://www.fusionauthority.com/bkinfo.cfm ------------------------------------------------------------------------------ To unsubscribe, send a message to [EMAIL PROTECTED] with 'unsubscribe' in the body or visit the list page at www.houseoffusion.com
