Those of you who build websites know sometimes the things you attempt simply will not work. Either the technology won’t cooperate or it is designed in a way you don’t expect. Once in awhile you come across an infrastructure item that has a bug or an odd behavior. Even less often do you come across a security problem that is a result of poor engineering.
The thing that makes what I am uncovering tonight so worrisome is that the company who provides the service is bound to know it exists. It is too simple to have been missed. As such, I let the company behind E-zekiel know by email that I am publishing this blog entry exactly 48 hours after emailing them. Hopefully they will fix the problem and this will be an artifact of what can go wrong in web programming and nothing more. Otherwise, I *think* we are all free to link to any URL we want and say what we want. For those who might critique that 48 isn’t long enough, I ask that you research the company to see how long they have been running their operations with such a glaring information security problem.