Help please! I'm "in the merde". Directory protected by .htaccess has been reached

We are hosted on an apache site:
1 -I 3 created months ago a .htaccess file in a directory called "download"
I've written the following text in the .htaccess file:
PerlSetVar AuthFile rights/list/administrator
AuthName "Acces Restreint"
AuthType Basic
<limit GET POST>
require valid-user
</limit>
the file called "admininstrator" in rights/list directory only contained :
robert:141238
For weeks things were OK.
Today I have received a phone call from a VERY ANGRY customer who succeeded in listing "download" directory!!! He has got Windows XP
What's wrong???

I do not understand! I have made immediately several tries with XP, NT, 2000 computers and I have not managed to access download directory without the box and passwords?!!!!!
Please I'm calling for help! (I have just blocked the site with "deny from all" in .htaccess file)


