Firstly...hello again to all AO'ers..Havent posted for quite some time now.

I would run a security scanner on the box like Nikto to test the security of the webserver, and to check the security of the OS, scan it with a testing tool like Nessus (but dont DOS the box).

The output will tell you that the box is insecure, which you could then pass on to your boss... And you have done it without hacking the machine or causing any downtime (hopefully)...