http://php-security.org/2010/05/19/mops-2010-035-e107-bbcode-remote-php-code-execution-vulnerability/index.html
<= e107 recent vuln
94.249.152.10 - - [05/Jun/2010:14:10:39 +0100] "POST /contact.php
HTTP/1.1" 200 18708 "-" "Mozilla/5.0" <= my apache logs
http://188.24.49.67/ <= his home ip
inetnum
debian:~# uname -a Linux debian 2.6.18-6-686 #1 SMP Thu Aug 20 21:56:59 UTC
2009 i686 GNU/Linux
debian:~# cat /etc/issue
Debian GNU/Linux 4.0 \n \l
debian:~# dpkg -l|grep nginx
ii nginx 0.4.13-2+etch2 small, but very powerful and efficient
debian:~# ps xauwww|grep worker|grep -v grep
www-data 3577