Hey,
Thanks for the reply. The version of Jetty that they are using has the "//" problem that allowed me to view the files that make up the login page. From there I could download the swf file for the front page.
Using a little product from HP called swfscan (
http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/03/20/exposing-flash-application-vulnerabilities-with-swfscan.aspx) to decomplie the swf and view the source code. Found a few little issues with the code and was able to get into the app.
Also ran WebScarab over the site and it found lots of nice little bits of information.
Thanks again for the advice.
A