The worm uses a phpBB forum script that has not been patched to break into the server. Once in the server, it defaces all the .html files it can find. As long there is at least one unpatched phpBB forum script on the server, the whole server is at risk. See http://www.f-secure.com/v-descs/santy_a.shtml
Comment