Spammer exploits PHP app to 0wn computer

Eli the Bearded sez, "Long, detailed writeup of webserver

getting 0wned by a sophisticated spammer.

Through a PHP product security hole a

webserver was converted to a full time

spam machine following orders from a

remote server. The author of this paper

has found that this is not an isolated

event and apparently has been going on

for months.

Got a server? Keep it patched, including

any silly little add-ons like the photo

gallery bit that got subverted here."
60k PDF Link

(Thanks, Eli!)