Maybe it's a little slack, i'm not sure but i don't fully know what happened.
I operate a number of servers remotely doing various tasks - I can't afford the bandwidth, so I "co-locate" - ie. hhouse the servers where there is bandwidth - it was a 7.3box (not sme) running frontpage server extensions - ports 80, 443 and 1729 open and it had been running for around 550 days consequtively. next thing there was a irc chat relay server running there from a directory /var/tmp/bot.x
the group and owner was apache, perhaps too simplistically assumption was drawn entry point was apache - but there wasn't much else open
anyway I have had a few compromises starting with the ill fated redhat 5.1, and the standard policy is shutdown
like i say maybe a bit slack, but I just cursed, rebuilt and throught 550 days was pretty good - it needed upgrading anyway.