This was a nasty bug that allowed remote users to view the ASP code behind your web application, potentially revealing sensitive business rules and database passwords, by simply appending ::$DATA to the URL.
The only way this could be a concern for you today is if you're still running NT 4.0 with Service Pack 3. <shudder> Come on, people; this has been fixed since 1998 (see
Security Bulletin MS98-003 for more information about the problem, and a hotfix if you really want to stay at NT 4.0 SP3).
Eliminate the problem by installing
Service Pack 6a. More info here:
KB #197464 How to Detect the ::$DATA Attack in IIS Log Files
KB #188806 FIX: "::$DATA" Data Stream name of a file may return the script code for the file