Neither. The web site administrator thoughtfully left the web based administration section of IIS open with no password. Duh!! And they still didn't figure it out until the intruders (if you can call them that) that was how they got in. Now it hardly took any brains to do what they did and they really didn't break into anything when you leave administrator access open to the world.