Today I had to secure a directory on a webserver that the previous admin had left unprotected. It wasn't a serious security hole, just one of those things that could have caused some irritations were it to be exploited to any large degree. As it turns out, securing the directory in question I think became a bigger irritation than having to deal with the possible fallout of leaving it open because the system (as I found out later) was based on Plesk which seems to over-rule any of the usual methods of securing a directory in apache. So without knowing this I followed these steps first: