Thanks Thor, I don't find anything in the 3 logs that are generated by ISA, i.e: web, IP, and FW. I only find this in the event log on the ISA server. Event Type: Warning Event Source: ISS Filter Event Category: None Event ID: 6 Date: 4/30/2002 Time: 5:32:00 PM User: N/A Computer: PATHFINDER Description: POP buffer overflow detected from 209.94.202.69:1617 to 206.X.X.X:110 Chris -----Original Message----- From: Deus, Attonbitus [mailto:Thor@xxxxxxxxxxxxxxx] Sent: Thursday, May 02, 2002 10:27 AM To: [ISAserver.org Discussion List] Subject: [isalist] Re: POP Buffer Overflow http://www.ISAserver.org -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 At 06:42 AM 5/2/2002, you wrote: >http://www.ISAserver.org > > >Can someone shed some light on what this is? > >I've received this twice in my events log and just wondering if I should >be alarmed. > >Thanks for any feedback, > Can you post the log entry? AD -----BEGIN PGP SIGNATURE----- Version: PGP 7.1 iQA/AwUBPNFMsYhsmyD15h5gEQKr3gCg4U5IAbeJVKOXTy1LfelOrjxz7b8An0je FOPA6+XWw200O9KKmqHSwWM7 =IImX -----END PGP SIGNATURE----- ------------------------------------------------------ You are currently subscribed to this ISAserver.org Discussion List as: Christian.Villeneuve@xxxxxxxx To unsubscribe send a blank email to $subst('Email.Unsub')