It's definitely a php-based exploit, but not targeting all open source php apps (that I can tell so far), so probably looking for some specific code problem. An analysis of the source and libraries used by the known targets would probably narrow it down.. -- Life is too short to be boring