It was in January of 2002 when we finally recognized the signs of disaster - the IDS told of anomalous activity on port 22 both inbound and out. Where there was little or no traffic before, we now see dozens of SSH connections to (and from) various foreign nations. We didn't know what they were...