Generally speaking, any malicious activity that denies a service. In relation to web sites and PHP, this typically means access to a web server or web application. Usually this is mentioned where brute-force and exhaustive tactics are used to “overload” such a service service.