that is a extremely complex and broad question.The answer is YES but it takes more than your average sqript kiddie know how. A fully patched and firewalled xp box that is not a server and is not running any "listning" services is pretty hard to crack but It can be done.If a attacker can get you to visit a malicious link or open a email its GAME OVER. So the answer is no one is ever really secure but if you stay on top of the game you will be fairely safe.I visit bug traq and security focus every day and check my services fo new vunerabilitys



