You might also want to consider the URL scan tool from Microsoft. (http://www.microsoft.com/technet/tre...ls/urlscan.asp)

It looks for common attacks and blocks them. Make sure to check your settings afterwards, because it does tend to change some things. When I installed it, it changed all my custom 404 pages to the default.

Also, you might want to check to make sure you have the latest version of ImageFolio 3.1 because there is a couple of exploits for that version.

http://xforce.iss.net/xforce/xfdb/12197

Does your AUP allow you to run servers?
This is a good question. My ISP (cable company) blocks ports and has a big old long paragraph or two saying how you cannot run a server and if your caught with a server your internet access will be cut off...