Hmm, Adron thought only the directory listings were available before the hole was fixed, but I think one or more source files may have been compromised after all...
Are there any IIS or CVS logs from before changing the ACLs?
Well, the CVS access doesn't exactly log much. There's IP and file, not user names.
I haven't received IP info on from everyone I know is accessing the CVS. I've matched up some, but there's a few unknowns remaining. You obviously don't have to post your ip for everyone to see, just message me so I can strike you off the log files.
Hrm doesnt it suck this was to late?
"just message me so I can strike you off the log files. "
ok ill message you
Strike me off.