Mr. Romulus Dogaru, A computer from a network block registered with your name recently successfully compromised one of our own computers. 217.156.93.166 gained unauthorized root access to our system on Sept. 16th at approximately 8:32 PM. The attacker downloaded and installed 3 rootkits. The following captured packet offer proof but we'd be glad to let you see the entire session, if more is needed. 09/16-20:32:31.106291 192.168.1.102:23 -> 217.156.93.166:61216 TCP TTL:64 TOS:0x0 ID:1919 IpLen:20 DgmLen:54 DF ***AP*** Seq: 0x657812E6 Ack: 0x2703A29 Win: 0x7D78 TcpLen: 20 5B 72 6F 6F 74 40 6E 73 31 20 2F 5D 23 20 [root@ns1 /]# =+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+ As you can see our system sent yours a root shell. If you'd like to see the entire session, we'd be more than happy to send it to you. Ian Stefanison