Shouldn't need anything else. Have had a chance to set up a couple of IDS/IPS evasion bots, perimeter scanning came up clean. Small SQL injection issue merged with XSS shows that the backend database may be either 768-bit encrypted or a simple 3DES matter, but a little more time should take care of that issue. Once the tables are writable to sa, should be ready to jump in and jump out with no problem. One of their systems caught an early sniff, but was shut down with a smurf.
For the non-technical: trust me, the above makes absolutely no sense whatsoever. Which makes it funny, because good old Todd swallows it hook, line, and sinker.