1. system partition
A) All partitions use NTFS, C: System system partition 10g, D: Software Installation 10g E: website directory F: Tools and backup 50g soft, backup, Other
2. Install the operating system:
Windows Server 2003 Enterprise Edition with Service Pack 1, which is upgraded using windowsupdate.
Pack SP2 and all patches
Serv-u6.0(replace servadmin.exeand servudaemon.exe with the corresponding files in the installation directory, and Use ODBC storage)
3. Disable the Guest user
4. install components (jmial, easy to use, upload, aspjepg, etc)
5. creating an iisuser user group and a ServU user does not belong to any group. The settings of The ServU password are more complex: servu_pass_ip address. that is, all IIS users are added to the iisuser group for ServU start and choose to start with the service. then in services. set the starting user of servudaemond in MSC to ServU.
6. Delete the c: \ inetpub directory
7. Disable NetBIOS on TCP/IP
Network neighbors-properties-local connection-properties-Internet Protocol (TCP/IP) properties-advanced-wins panel-NetBIOS settings-Disable NetBIOS on TCP/IP. In this way, cracker cannot use the nbtstat command to read your NetBIOS information and the MAC address of the NIC.
8. Rename Administrator as the ending number of cytz_admin_ip.
9. Modify port 3389
1. Run regedt32 and go to this item:
HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Control \ Terminal Server \ winstations \ RDP-TCP
And: HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Control \ Terminal Server \ WDS \ rdpwd \ TDS \ Tcp
Note: The above registry key is a path; it has a line break for ease of reading.
2. Find the "portnumber" subitem and you will see the value 00000d3d, which is a hexadecimal representation of 3389. Use a hexadecimal value to modify the port number (f79d), that is, 63389 in decimal format, and save the new value.
10. Run gpedit. msc => Computer Management => Windows Settings => Security Settings => Local Policies => Audit policies are set as follows:
Account Management failed
Logon Event successful failed
Object Access failed
Policy Change failed
Failed to use privilege
System Event success/failure
Directory Service Access failed
Account Logon event failed