Just remember, anybody using URLScan in its default configuration is immune to this (and all the other attacks of this nature) attack. If you are new to using a Windows 2000 server, get this installed *FIRST*, then start working your way to adjusting the server to your needs.