@Nyamboki, you do not see any issue with what John K has described?

Developers tend to leave .zip and .sql files lying around in the webroot, especially just before or after uploading a new version. It is usually named the same as the folder which one can figure out from the URL. At least I used to do that when I was young and foolish.

On Sun, Feb 8, 2015 at 5:48 PM, David Nyamboki via skunkworks <skunkworks@lists.my.co.ke> wrote:

And Whats the issue mr
John

On 7 Feb 2015 15:30, "John K. via skunkworks" <skunkworks@lists.my.co.ke> wrote:
Anyone know the dev's of the Nairobi County App at JamboPay? Need to notify them of some serious security concerns in their app. Seroius to the point that I won't use the app until they are patched. 

And if anyone on this list uses it, please don't use the same PIN you use for other secure services like Mpesa, atm etc until these issues are patched.



_______________________________________________
skunkworks mailing list
skunkworks@lists.my.co.ke
------------
List info, subscribe/unsubscribe
http://lists.my.co.ke/cgi-bin/mailman/listinfo/skunkworks
------------

Skunkworks Rules
http://my.co.ke/phpbb/viewtopic.php?f=24&t=94
------------
Other services @ http://my.co.ke

_______________________________________________
skunkworks mailing list
skunkworks@lists.my.co.ke
------------
List info, subscribe/unsubscribe
http://lists.my.co.ke/cgi-bin/mailman/listinfo/skunkworks
------------

Skunkworks Rules
http://my.co.ke/phpbb/viewtopic.php?f=24&t=94
------------
Other services @ http://my.co.ke