Yeah i found an article that said pretty much the same thing.

I also remember reading that there was a vulnerability with MS OS and the way that they handled images. The hack was on a linux box so this wouldnt work.

The article didnt really say how he did it, so he might of used the php method.