sounds like lazy lazy admin(s). we got them everywhere.
can't be arsed to do the job properly - so they just setup a half-assed job, patch it and forget about it.
those types of admins are a crackers best friend. you just scope them out and their systems and then go "shopping in a candy store" so to speak.
don't say anything.
:-)
