i guess you got me there H.
i guess some of your assumptions are true... no, PERSONALY i don't give a rat's ass about ppl who i work for, the client or the web hosting inc. i don't have any interest to be friendly w/ a competition and make them aware. if i can prove they've been hacked the client could give us the hosting job and i would get more money. that's my interest and nothing else ... sorry to disappoint. even you won't help me i'm not gonna "back-off" because there's not a slightest proof that this site is secure. we'll see how lock down this is... you don't know anything about me so f-off w/ your "you shouldn't have the job" BS. i guess you would assume that every admin is perfect so this one is too and i should "back off"... but even I w/ my "limited knowledge" can see that the nmap scan speaks for itself
and by the way ... yes i did try to login w/ ftp & telnet "just to see" ... so sue me... and obviously, just as i expected it doesn't lock you out
but that doesn't mean i'm gonna let a BF'er go loose on the daemon
