One of the more amusing patterns I spotted in the URLs is where an alarming amount of the filesystem appears to be exposed, e.g.:
www.dulceswilly.com/mysql/BHP_sym/root/usr/local/etc/apache22/server.key
If I was on a non-company IP, I'd be tempted to poke around and see what else is visible...