On Friday, August 29, 2003 3:57 PM, Bryce C wrote: > I was just running through my fw logs and I noticed ALOT of hits on > port 901 (SWAT usually) and all from Cox addresses. A Google search turned up these links: http://www.dshield.org/pipermail/list/2003-June/008480.php. http://www.dslreports.com/forum/remark,7041312~root=security,1~mode=flat http://securityresponse.symantec.com/avcenter/venc/data/backdoor.netdevil.ht ml Looks like the kiddiez are playing with something called "NetDevil". ~Jeff