Hi grumblenz,
We had one of our devs look at the video real quick and from a security standpoint it proves absolutely nothing because it does not actually show an exploit.
If you take the code in the demonstration video and URLDecode it you’ll get the message “You’re not supposed to read this. this an exploit.. Actually, this is text to hide the real exploit, just in case some tries to replicate this hack after watching this video.”
If they were actually hacking a site in this video, they would be entering a script, not a piece of text. They have formulated the text to make it seem that they are “faking” a hack to protect people. But there definitely is no hack happening in the video. How do you respond to someone who claims they can hack your product but are only willing to show a video of a fake hack as evidence?
I think the best response might simply be: Before you buy a product from any security company, take your time. Browse the companies websites. Get a feel for their public image and their marketing strategies. If it seems like someone is trying to scare you in to buying a product, think twice.
Hope that helps!