On RH, I have been capturing http packets with tethereal and examining them with ethereal. In one obvious buffer overflow attack I found: Frame size = 1506 IP total length = 1492 NTLMSSP data size = 1044 What is the NTLMSSP? The hex dump shows it to be in >addition< to the ethernet frame size, which to me, does not make sense. Thanks for your help, Mike. -- Michael D. Berger m.d.berger@xxxxxxxx --------------------------------------------------------------------- The official User-To-User support forum of the Apache HTTP Server Project. See <URL:http://httpd.apache.org/userslist.html> for more info. To unsubscribe, e-mail: users-unsubscribe@xxxxxxxxxxxxxxxx " from the digest: users-digest-unsubscribe@xxxxxxxxxxxxxxxx For additional commands, e-mail: users-help@xxxxxxxxxxxxxxxx