Take a look at how they exploited it:
I join everyone else in urging sysadmins to patch, patch, patch.
However, if you're running a packet sniffer or Network Intrusion Detection System, and you see a user name that's 128KB long (remember, this part of the login is unencrypted)... Yeah, that...