what about <img src="get_image.cgi"> instead? makes it pretty obvious that it's dynamically created by a script .. though of course anyone taking this over would also see in the web server config that there's some sort of handler set up for .png files that runs a script ..