I am responsible for testing the security for my companies web site before it goes live. We are running IIS 5 off of a Windows 2000 server. How can I attempt to hack into IIS. I know that a lot of hackers use the ISAPI extensions to hack IIS but is there anywhere I can go that will tell me specifically how to do this so that I can be sure we’re secure? Thanks.