Eli the Bearded sez, "Long, detailed writeup of webserver
getting 0wned by a sophisticated spammer.
Through a PHP product security hole a
webserver was converted to a full time
spam machine following orders from a
remote server. The author of this paper
has found that this is not an isolated
event and apparently has been going on
for months.
Got a server? Keep it patched, including
any silly little add-ons like the photo
gallery bit that got subverted here."
60k PDF Link
(Thanks, Eli!)