The security gurus at sans.org have observed the use of a new web
defacement tool. There is some useful information there, including advice
to check that your php config has
allow_url_fopen = Off .
The link is:
"Probable php shell/web defacement tool usage on the rise" at
http://isc.sans.org/diary.php?storyid=1030