I brought a new nt 4 server online and someone has extracted the usernames and is attempting to access them. I had this happen before on another machine and fixed the problem. I can't remember what the process is called that they are using so I can find the fix though. I have applied all the security updates etc... but I assume there is one more I need. Does anyone know what the process is called. I want to say it had the word anonomous or reverse in it, but my memory is sketchy. The last time I looked at this was two years ago. Thanks.