Server security Settings Batch processing _dos/bat

Source: Internet
Author: User
The first one is more complete, it is recommended to use the first
Copy Code code as follows:

@ECHO off
Cls
TITLE SERVER SAFE SETUP PRO
COLOR 0A
echo y|cacls.exe C:\/P administrators:f system:f "Network SERVICE": R
echo y|cacls.exe d:\/P administrators:f system:f servu:f "Network SERVICE": R
echo y|cacls.exe e:\/P administrators:f system:f servu:f "Network SERVICE": R
echo Y|cacls.exe "C:\Program Files"/t/p administrators:f system:f everyone:r
echo y|cacls.exe "C:\Program Files\Common Files"/t/g administrators:f system:f everyone:r
echo Y|cacls.exe c:\windows/p administrators:f system:f
echo Y|cacls.exe c:\windows\system32/p administrators:f system:f
echo y|cacls.exe c:\windows\system32\inetsrv/p administrators:f system:f everyone:r
echo Y|cacls.exe "C:\Documents and Settings"/P administrators:f system:f
echo Y|cacls.exe "C:\Documents and Settings\All Users"/t/p administrator:f system:f everyone:r
echo Y|cacls.exe c:\windows\temp/p everyone:f
echo Y|cacls.exe%systemroot%\system32\shell32.dll/p administrators:f
echo Y|cacls.exe%systemroot%\system32\wshom.ocx/p administrators:f
echo Y|cacls.exe c:\windows\system32\*.exe/p administrators:f system:f
echo Y|cacls.exe "c:\Documents and Settings\All Users"/e/g Everyone:r
echo y|cacls.exe%systemroot%\system32\svchost.exe/e/g "Network SERVICE": R
echo y|cacls.exe%systemroot%\system32\msdtc.exe/e/g "Network SERVICE": R
echo y|cacls.exe%windir%\system32\mtxex.dll/e/g everyone:r
echo Y|cacls.exe c:\windows\system32\cmd.exe/p administrator:f
echo Y|cacls.exe c:\windows\system32\net.exe/p administrator:f
echo Y|cacls.exe c:\windows\system32\net1.exe/p administrator:f
echo Y|cacls.exe c:\windows\system32\sc.exe/p administrator:f
echo Y|cacls.exe c:\windows\system32\at.exe/p administrator:f
echo y|cacls.exe%windir%\system32\dllhost.exe/e/g everyone:r
echo Y|cacls.exe c:\windows\system32\netsh.exe/p administrator:f
echo Y|cacls.exe c:\windows\system32\net.exe/p administrator:f
echo Y|cacls.exe c:\windows\system32\cacls.exe/p administrator:f
echo Y|cacls.exe c:\windows\system32\cmdkey.exe/p administrator:f
echo Y|cacls.exe c:\windows\system32\ftp.exe/p administrator:f
echo Y|cacls.exe c:\windows\system32\tftp.exe/p administrator:f
echo Y|cacls.exe c:\windows\system32\reg.exe/p administrator:f
echo Y|cacls.exe c:\windows\system32\regedt32.exe/p administrator:f
echo Y|cacls.exe c:\windows\system32\regini.exe/p administrator:f
echo y|cacls.exe%windir%\assembly/e/t/g "Network SERVICE": R
echo Y|cacls.exe%windir%\microsoft.net/e/t/g everyone:r
echo y|cacls.exe "%windir%\microsoft.net\framework\v1.1.4322\temporary asp.net Files"/e/t/g everyone:f
echo y|cacls.exe%windir%\system32\mscoree.dll/e/g everyone:r
echo y|cacls.exe%windir%\system32\ws03res.dll/e/g everyone:r
echo y|cacls.exe%windir%\system32\msxml*.dll/e/g everyone:r
echo y|cacls.exe c:\windows\system32\urlmon.dll/e/g everyone:r
echo y|cacls.exe c:\windows\system32\mlang.dll/e/g everyone:r
echo y|cacls.exe c:\windows\system32\tapi32.dll/e/g everyone:r
echo y|cacls.exe c:\windows\system32\wininet.dll/e/g everyone:r
cacls c:\windows\assembly/e/t/p "Network SERVICE": R
cacls c:\windows\microsoft.net/e/t/p "Network SERVICE": R
cacls "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Temporary asp.net Files"/e/t/P "Network Service": F
cacls c:\windows\system32\mscoree.dll/e/g everyone:r
cacls c:\windows\system32\ws03res.dll/e/g everyone:r
cacls c:\windows/e/g "Network SERVICE": R
If exist c:\windows cacls c:\windows/e/g "Network SERVICE": R
cacls c:\windows\microsoft.net/e/t/p "Network SERVICE": R
cacls "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Temporary asp.net Files"/e/t/P "Network Service": F
cacls "C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Temporary asp.net Files"/e/t/P "Network Service": F
cacls c:\windows\system32/e/g "Network SERVICE": R
cacls c:\windows\system32\rasapi32.dll/e/g "Network SERVICE": R
echo Y|cacls.exe c:\windows\system32\inetsrv\adsiis.dll/p administrators:f autosystem:f
echo Y|cacls.exe c:\windows\system32\inetsrv\iisadmpwd/p administrators:f autosystem:f
echo Y|cacls.exe c:\windows\system32\inetsrv\metaback/p administrators:f autosystem:f
cacls C ": \program Files\serv-u"/e/g "Servu": F
cacls d:\wwwroot/e/g servu:f
Echo Set server directory permissions above

net stop Browser
sc config Browser start= disabled
net stop LanManServer
sc config LanManServer start= disabled
NET share C $/delete
NET share d$/delete
NET share e$/delete
NET share f$/delete
NET share admin$/delete
NET share ipc$/delete
echo Delete default share above, set service item
Echo.. Delshare.reg .....
echo Windows Registry Editor Version 5.00> C:\delshare.reg
Echo [hkey_local_machine\system\currentcontrolset\services\lanmanserver\parameters]>> C:\delshare.reg
echo "AutoShareWks" =dword:00000000>> C:\delshare.reg
echo "AutoShareServer" =dword:00000000>> C:\delshare.reg
Echo.. Delshare.reg .....
REGEDIT/S C:\delshare.reg
Echo.. Delshare.reg .....
Del C:\delshare.reg
Echo.
echo .....
Echo.
Echo =========================================================
Echo.
echo ..... ..... dos ...........
Echo.
echo .....
echo Windows Registry Editor Version 5.00> C:\dosforwin.reg
Echo [hkey_local_machine\system\currentcontrolset\services\tcpip\parameters]>> C:\dosforwin.reg
echo "EnableICMPRedirect" =dword:00000000>> C:\dosforwin.reg
echo "Deadgwdetectdefault" =dword:00000001>> C:\dosforwin.reg
echo "Dontadddefaultgatewaydefault" =dword:00000000>> C:\dosforwin.reg
echo "EnableSecurityFilters" =dword:00000000 ">> C:\dosforwin.reg
echo "Allowunqualifiedquery" =dword:00000000>> C:\dosforwin.reg
echo "Prioritizerecorddata" =dword:00000001>> C:\dosforwin.reg
echo "ReservedPorts" =hex (7):31,00,34,00,33,00,33,00,2d,00,31,00,34,00,33,00,34,00,\>> C:\dosforwin.reg
Echo 00,00,00,00>> C:\dosforwin.reg
echo "SynAttackProtect" =dword:00000002>> C:\dosforwin.reg
echo "EnablePMTUDiscovery" =dword:00000000>> C:\dosforwin.reg
echo "NoNameReleaseOnDemand" =dword:00000001>> C:\dosforwin.reg
echo "EnableDeadGWDetect" =dword:00000000>> C:\dosforwin.reg
echo "KeepAliveTime" =dword:00300000>> C:\dosforwin.reg
echo "PerformRouterDiscovery" =dword:00000000>> C:\dosforwin.reg
echo "Enableicmpredirects" =dword:00000000>> C:\dosforwin.reg
Echo.
Echo ==========================================================
Echo.. Dosforwin.reg .....
REGEDIT/S C:\dosforwin.reg
Echo.. Dosforwin.reg .....
Del C:\dosforwin.reg
Echo ==============================================================
Echo.
Echo ===============================================================
Echo.. Remote Registry Service ... .....
echo .....
Echo.
echo Windows Registry Editor Version 5.00> C:\regedit.reg
Echo [hkey_local_machine\system\currentcontrolset\services\remoteregistry]>> C:\regedit.reg
echo "Start" =dword:00000004>> C:\regedit.reg
Echo.
Echo.. Regedit.reg .....
REGEDIT/S C:\regedit.reg
Echo.
Echo ...
Del C:\regedit.reg
Echo ===============================================================
Echo.. Messenger .....
echo .....
echo Windows Registry Editor Version 5.00> C:\message.reg
Echo [hkey_local_machine\system\currentcontrolset\services\messenger]>> C:\message.reg
echo "Start" =dword:00000004>> C:\message.reg
Echo.
Echo.. Message.reg .....
REGEDIT/S C:\message.reg
Echo.
Echo.. Message.reg
Del C:\message.reg
Echo ===============================================================

Echo ===============================================================
Echo.. LanManServer .....
echo .....
echo Windows Registry Editor Version 5.00> C:\lanmanserver.reg
Echo [hkey_local_machine\system\currentcontrolset\services\lanmanserver]>> C:\lanmanserver.reg
echo "Start" =dword:00000004>> C:\lanmanserver.reg
Echo.
Echo.. Lanmanserver.reg .....
REGEDIT/S C:\lanmanserver.reg
Echo.
Echo.. Lanmanserver.reg
Del C:\lanmanserver.reg

Echo ==============================================================
Echo ... TCP/IP NetBIOS Helper Service
echo .....
echo Windows Registry Editor Version 5.00> C:\netbios.reg
Echo [hkey_local_machine\system\currentcontrolset\services\lmhosts]>> C:\netbios.reg
echo "Start" =dword:00000004>> C:\netbios.reg
Echo.
Echo.. Netbios.reg .....
REGEDIT/S C:\netbios.reg
Echo.
Echo.. Netbios.reg
Del C:\netbios.reg
REGEDIT/S Forddos.reg


A second
Copy Code code as follows:

Echo.
Echo------------------------------------------------------
Echo.
echo ......
Echo.
NET share C $/delete
NET share d$/delete
NET share e$/delete
NET share f$/delete
NET share admin$/delete
NET share ipc$/delete
net stop Server
net start Server
Echo.
echo .....
Echo.
Echo------------------------------------------------------
Echo.
echo ...........
Echo.
Echo.. Delshare.reg .....
echo Windows Registry Editor Version 5.00> C:\delshare.reg
Echo [hkey_local_machine\system\currentcontrolset\services\lanmanserver\parameters]>> C:\delshare.reg
echo "AutoShareWks" =dword:00000000>> C:\delshare.reg
echo "AutoShareServer" =dword:00000000>> C:\delshare.reg
Echo.. Delshare.reg .....
REGEDIT/S C:\delshare.reg
Echo.. Delshare.reg .....
Del C:\delshare.reg
Echo.
echo .....
Echo.
Echo =========================================================
Echo.
echo ..... ..... dos ...........
Echo.
echo .....
echo Windows Registry Editor Version 5.00> C:\dosforwin.reg
Echo [hkey_local_machine\system\currentcontrolset\services\tcpip\parameters]>> C:\dosforwin.reg
echo "EnableICMPRedirect" =dword:00000000>> C:\dosforwin.reg
echo "Deadgwdetectdefault" =dword:00000001>> C:\dosforwin.reg
echo "Dontadddefaultgatewaydefault" =dword:00000000>> C:\dosforwin.reg
echo "EnableSecurityFilters" =dword:00000000 ">> C:\dosforwin.reg
echo "Allowunqualifiedquery" =dword:00000000>> C:\dosforwin.reg
echo "Prioritizerecorddata" =dword:00000001>> C:\dosforwin.reg
echo "ReservedPorts" =hex (7):31,00,34,00,33,00,33,00,2d,00,31,00,34,00,33,00,34,00,\>> C:\dosforwin.reg
Echo 00,00,00,00>> C:\dosforwin.reg
echo "SynAttackProtect" =dword:00000002>> C:\dosforwin.reg
echo "EnablePMTUDiscovery" =dword:00000000>> C:\dosforwin.reg
echo "NoNameReleaseOnDemand" =dword:00000001>> C:\dosforwin.reg
echo "EnableDeadGWDetect" =dword:00000000>> C:\dosforwin.reg
echo "KeepAliveTime" =dword:00300000>> C:\dosforwin.reg
echo "PerformRouterDiscovery" =dword:00000000>> C:\dosforwin.reg
echo "Enableicmpredirects" =dword:00000000>> C:\dosforwin.reg
echo .....
Echo ==========================================================
Echo.. Dosforwin.reg .....
REGEDIT/S C:\dosforwin.reg
Echo.. Dosforwin.reg .....
Del C:\dosforwin.reg
Echo ==============================================================
Echo.
echo ..... (......................).
Echo.
Echo.. Telnet,...... telnet.
echo .....
echo Windows Registry Editor Version 5.00> C:\telnet.reg
Echo [hkey_local_machine\system\currentcontrolset\services\tlntsvr]>> C:\telnet.reg
echo "Start" =dword:00000004>> C:\telnet.reg
Echo.
Echo.. Telnet.reg .....
REGEDIT/S C:\telnet.reg
Echo.
Echo.. Telnet.reg .....
Del C:\telnet.reg
Echo.
Echo ===============================================================
Echo.. Remote Registry Service ... .....
echo .....
Echo.
echo Windows Registry Editor Version 5.00> C:\regedit.reg
Echo [hkey_local_machine\system\currentcontrolset\services\remoteregistry]>> C:\regedit.reg
echo "Start" =dword:00000004>> C:\regedit.reg
Echo.
Echo.. Regedit.reg .....
REGEDIT/S C:\regedit.reg
Echo.
Echo ...
Del C:\regedit.reg
Echo ===============================================================
Echo.. Messenger .....
echo .....
echo Windows Registry Editor Version 5.00> C:\message.reg
Echo [hkey_local_machine\system\currentcontrolset\services\messenger]>> C:\message.reg
echo "Start" =dword:00000004>> C:\message.reg
Echo.
Echo.. Message.reg .....
REGEDIT/S C:\message.reg
Echo.
Echo.. Message.reg
Del C:\message.reg
===============================================================
Echo.. Telephony ...
echo .....
echo Windows Registry Editor Version 5.00> C:\Telephony.reg
Echo [hkey_local_machine\system\currentcontrolset\services\tapisrv]>> C:\Telephony.reg
echo "Start" =dword:00000004>> C:\Telephony.reg
Echo.
Echo.. Telephony.reg
REGEDIT/S C:\Telephony.reg
Del C:\Telephony.reg
Echo ==============================================================
Echo ... TCP/IP NetBIOS Helper Service
echo .....
echo Windows Registry Editor Version 5.00> C:\netbios.reg
Echo [hkey_local_machine\system\currentcontrolset\services\lmhosts]>> C:\netbios.reg
echo "Start" =dword:00000004>> C:\netbios.reg
Echo.
Echo.. Netbios.reg .....
REGEDIT/S C:\netbios.reg
Echo.
Echo.. Netbios.reg
Del C:\netbios.reg
Echo ===============================================================
Echo ===============================================================
echo Powered by Winter cordyceps sinensis
Echo sleepboy82@hotmail.com
echo Jooline Services Set
Goto:end

The above file download address

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.