Windows 2003 prohibits exe,bat,com of directories such as Web execution

Source: Internet
Author: User

Use Gpedit.msc (Group Policy) to prevent directories from executing certain files.

First of all:

Run-----Enter gpedit.msc----Computer Configuration---Windows Settings----security settings ↓ Software restriction policy (if there is nothing next to it.) Right-click to create a policy)---other rules----(right-click) a new path rule (p) is created.

As shown in figure:

This way the D:wwwroot directory will not be able to execute any exe.bat.com files. No matter what jurisdiction you are. Even system is unable to execute.

This greatly improves the security of using exp elevation privileges.

Here's a thought, of course. As you all know, C:windowstemp is a temporary folder. Basically all users can write. It is not required to execute permissions.

Of course we can add a rule to him here. Let C:windowstemp have no execute permission. method as above.

Principle: Based on software policy from these directories can not run programs to increase security.

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.