Summary of Windows server security configuration page 1/2

Source: Internet
Author: User

1. system partition

A) All partitions use NTFS, C: System system partition 10g, D: Software Installation 10g E: website directory F: Tools and backup 50g soft, backup, Other

2. Install the operating system:

Windows Server 2003 Enterprise Edition with Service Pack 1, which is upgraded using windowsupdate.

Pack SP2 and all patches

Serv-u6.0(replace servadmin.exeand servudaemon.exe with the corresponding files in the installation directory, and Use ODBC storage)

3. Disable the Guest user

4. install components (jmial, easy to use, upload, aspjepg, etc)

5. creating an iisuser user group and a ServU user does not belong to any group. The settings of The ServU password are more complex: servu_pass_ip address. that is, all IIS users are added to the iisuser group for ServU start and choose to start with the service. then in services. set the starting user of servudaemond in MSC to ServU.

6. Delete the c: \ inetpub directory

7. Disable NetBIOS on TCP/IP
Network neighbors-properties-local connection-properties-Internet Protocol (TCP/IP) properties-advanced-wins panel-NetBIOS settings-Disable NetBIOS on TCP/IP. In this way, cracker cannot use the nbtstat command to read your NetBIOS information and the MAC address of the NIC.

8. Rename Administrator as the ending number of cytz_admin_ip.

9. Modify port 3389

1. Run regedt32 and go to this item:
HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Control \ Terminal Server \ winstations \ RDP-TCP

And: HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Control \ Terminal Server \ WDS \ rdpwd \ TDS \ Tcp
Note: The above registry key is a path; it has a line break for ease of reading.

2. Find the "portnumber" subitem and you will see the value 00000d3d, which is a hexadecimal representation of 3389. Use a hexadecimal value to modify the port number (f79d), that is, 63389 in decimal format, and save the new value.

10. Run gpedit. msc => Computer Management => Windows Settings => Security Settings => Local Policies => Audit policies are set as follows:

Account Management failed

Logon Event successful failed
Object Access failed
Policy Change failed
Failed to use privilege
System Event success/failure
Directory Service Access failed
Account Logon event failed

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.