A php-based web application (forum, blog, CMS, etc.) that has an exploit, usually php injection, whereby various script/botnet kiddie tools and irc-related items are installed, usually in<nobr> <wbr></nobr>/tmp or<nobr> <wbr></nobr>/var/tmp. Perhaps they'll install a php shell too. Sometimes, they'll try to run a rootkit against the local machine.<br><br>This is nothing new, and doesn't really have anything to do with "Macs". It has more to do with php and people not keeping their php-based web applications up to date than anything