Unknown Log Entries
The apache status is logging these from some remote IP I do not know in Russia.
GET /cgi-bin/ezshopper3/loadpage.cgi HTTP/1.0
GET /cgi-bin/faqmanager.cgi HTTP/1.0
GET /cgi-bin/environ.cgi HTTP/1.0
GET /cgi-bin/ezshopper/search.cgi HTTP/1.0
GET /cgi-bin/ezshopper/loadpage.cgi HTTP/1.0
GET /cgi-bin/ezshopper2/loadpage.cgi HTTP/1.0
GET /cgi-bin/enter.cgi HTTP/1.0
Seems they are probing the system. I just run a basic WordPress site. Can I disable cgi-bin?
Any insights into why they would go at these files?
-
A google search for this: /cgi-bin/ezshopper3/loadpage.cgi Tells me it's an old vulnerability: /http://www.securityfocus.com/bid/2109/exploit Seems they are probing the system. I just run a basic WordPress site. Can I disable cgi-bin?
Yes sure. You can modify the account via WHM to disable CGI Privilege, or disable CGI Access for the Package the account is using here: WHM " Packages " Edit a Package0 -
Thank you for pointing out where to disable cgi-bin 0
Please sign in to leave a comment.
Comments
2 comments