Security issue: CGI-BIN
Just wondered if someone could offer any advice;
I found my CGI-BIN had a cgi file in it, which worried me as I never use this folder. Anyway, I removed the file straight away, and also deleted the CGI-BIN folder. 2 days later, the folder is back, but I haven't created it!
Obviously something nasty is going on here, so I have done the following;
- reset all my password
- using .htaccess I have password protected that particular folder
- I have also added a 301 redirect, so if someone does manage to get to it, then it will redirect them to Microsoft.com
Is there anything else I should do? Maybe CHMOD it to 0 ?
|