How to configure Web server security and security in win 2003

Source: Internet
Author: User
Tags port number

Web server security configuration content
1. Default port number of the terminal service: 3389.
Reason for change: you do not want illegal users to connect to the server to log on to the experiment. When this server is hosted, it is not expected to happen. Haha, haven't you forgotten the 2000 input method vulnerability?
Change method:
(1) [hkey_local_machine system currentcontrolset control terminal server wds rdpwd tds tcp] at the first place. Do you see the portnumber on the right? In decimal format, change it to the desired port number, for example, 7126, as long as it does not conflict with others.
(2) [hkey_local_machine system currentcontrolset control terminal server winstations rdp-tcp. The method is the same as above. Remember to change the port number to the same as the above.
2 system Disk windowssystem32cacls.exe00000000.exe0000net.exe0000net1.exe0000telnet.exe0000ftp.exe
The registry deletes wscript. shell, wscript. shell.1, wscript. network, wscript. network.1, and shell. application.
Registry name: adodb. stream, scripting. dictionary, scripting. filesystemobject
3. Enable firewall and TCP/IP filtering, and enable a group of port ing in serv-u.
80 20 21 2121 * and serv-u port groups

The following section describes how to disable the execution of exe, bat, com in the web Directory of win2003.

Run ----- enter gpedit. msc ---- computer configuration --- windows settings ---- security settings software restriction policy (if there is nothing next to it. Right click to create a policy) --- Other rules ---- (right click) create a path rule (p ).

Figure 1:

 

In this way, the d: wwwroot directory cannot execute any exe.bat.com files. No matter what permissions you have. Even the system cannot be executed.

This greatly improves the security of the permissions to be improved by using exp.

Of course, here is an idea. . We all know that c: windowstemp is a temporary folder. Almost all users can write data. It does not require execution permissions.
Of course, we can add a rule for him here. So that c: windowstemp has no execution permission. The method is as follows.

Principle: programs cannot be run from these directories based on software policies to increase security.

 

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.