Hi... wow.. this blew up out of no where.. was feeding my new 3 week old son.. and got the phone call from hell...
thank Fris... for pointing this out.. as I mentioned in Montreal.. we were looking for a security person to do work for us.... as the one person I had contacted was backed up for a few months with other clients... then the 2257 crap hit.. .
from what i understand.... our original apache set up on our personal servers allows pl files to be readable..something that our guys should have caught and fixed.. but didn't... this is not a software wide issue ... as much as it is a server security issue... and we are now currently working on correcting it...
as Fris mentioned every system has its weaknesses.. and they will all be found at some point.. unfortunately ours happened to be tonight...
lastly.. as for our ESclients... I do not know how our clients build their webservers. in most cases we do not have access to the client's web servers. If their severs are secured properly... (unlike ours.. as we found out) they should not have similar issues....
I'll post more info as I find out more... thank you to those who are supporting us and who took the time to contact us...
