Yeah, sorry about that. I typed in "PC compliance." I forgot the "I"
PCI compliance, while should be practiced, is kind of a joke because it is not very standardized. The service my client used (I forget what it was), and obtained a compliance certification, was completely different than the one I used (Comodo Securities)
Both had the problem of the TRACK/TRACE method is lighttpd, but Comodo's responded with a problem with their version of PHP that they are using (5.2.10-ubuntu.) Comodo was very adamant about PHP being updated to v5.3, but my clients' code wouldn't run on 5.3. I am not exactly sure how their code works (I guess they aren't either), but apparently it does something with FFMPEG to automatically convert and stream uploaded videos from various sources. They also have a store running on the same server with a database that shares the responsibilities of both.
Of course, I explained to them that this is not the way to accomplish this. You never want a database on the same physical machine as the server, but you know how people like to take the cheap way out of things. I of course, offered to redesign their system to "industry standards" but they seemed more concerned with meeting a deadline than doing things the right way, not to mention spending the money to get the job done the right way.
Oh well. This is the part of doing freelance consultation work I don't like. Of course, since they didn't follow my suggestions, when everything falls to pieces, guess who they blame? LOL
Thanks for your help, though.