Poster is spot on that C99 is not very stealth. I remember getting hit with this guy a few months ago -- very easy to diagnose and clean up.
mod_security can help for people running Apache, and so will using maintained and up to date scripts.
[0] "Pass Non-PHP Requests to PHP." http://wiki.nginx.org/Pitfalls