begin Rick Welykochy quotation:
> How could a firewall prevent defacements?

Well, quite.

The fact that this host was associated with Smoothwall is good for
laughter value, but one really has no indication how the intruders 
got in.  Thus the point of my earlier post:  The bad guys get in
whichever way you (_or_ your dumb-ass users) make easy through neglect.
In this case, it's rather more likely to have been social engineering 
or password reuse than any outright configuration error.

