I'm also stuck at this point. Have the python exploit working on my localhost, now just need to run it live.
That being said, your tmp folder permissions theory is much more interesting though and that would be a brilliant way keep everyone else from catching up. :)