2000 system security has always been a headache for network administrators. Although win2003 has been launched, many still use the 2000 system, in fact, as long as you set the system correctly and add security software, the security can be greatly improved, but there is no absolute security setting. Every system has vulnerabilities, and attack and defense are always opposite. The following describes the settings of 2000, and no security software is used. The security reinforcement process for the 2000 system is described as follows:
1. Install a minimal operating system and the latest service package;
2. install and configure the application you want to run on the host;
3. Apply for a new service package and install the latest security patch;
4. delete or disable unnecessary services and components in the operating system;
5. Reinforce other parts of the operating system;
6. set strict access control permissions for files and other objects.
The following describes the procedure:
1. Minimal Operating System Installation Considerations: from a clean system, do not install multi-system startup on the host to prevent damage caused by startup control of other systems. Only NTFS partitions are used as file system partitions because they provide Log check information. In addition, you must use NTFS to use DACL for files to achieve access control security. Only the TCP/IP protocol is installed, and no other protocol is installed, do not install any additional programs or services when selecting an installer. If the server version of win2000 is installed, configure it to standalone (independent server) mode.
2. install and configure applications and service programs: do not install any redundant programs, install and use services and applications carefully, and select the latest installation and service version whenever possible. Install and configure the normally used applications on your system, and install and configure the programs you selected to provide network services on your system. Check whether the program you want to install has security defects. In an application environment with high security requirements, do not install MS-ofiice or any development tools. The fewer executable programs, the better.
3. apply for a new service package and install the latest security patch: Microsoft provides the windows update Program, which can be directly connected to the Microsoft download site to obtain the updated hotfix, that is, the security patch released after the release of the large service package, it is usually used to compensate for recent security vulnerabilities.
4. configure the services provided by the operating system: Disable all unnecessary services provided by the operating system. Enable system services that have other requirements as required, however, in principle, try to avoid using system services provided by Microsoft.
Services that can be set to auto-start:
Event log event logging
Logical disk manager (LDM) disk management needs
Network connections network management needs
Plug and play hardware device plug-and-play
Protected storage needs
Remote procedure call (RPC) system inter-process call needs
Security accounts manger (SAM) account management data requirements
Windows management instrumentation (WMI) management control needs
WMI driver extensions management control needs
Services that can be set to manually started:
DNS clinent is only required when DNS is started
Runas service is only used when the runas command is required
IIS admin service Microsoft web service requirements
Required for disk management of Logical disk manager administrative service
Nt lm security support provider Microsoft web service requirements
Word wide web publishing service Microsoft web service requirements
5. Configure the Account Policy: Right-click my computer, select "manage", open the Local Security Policy in the Administrative Tools, adjust the password policy and account lock policy, and set
6. Account management considerations: (1) log on with as few accounts as possible and use as few accounts as possible. Website accounts are generally used for system maintenance. Do not use any unused accounts. (2) In addition to the administrator, it is necessary to add an account belonging to the administrator group. On the one hand, the administrator can also use another account once the password is forgotten, on the one hand, it is found that an account can be cracked and another account can be used. (3) All account permissions must be strictly controlled, and management permissions are not easily granted. (4) Rename the administrator and change it to something that is not easy to guess. This prevents hackers from speculating on the account and password. (5) disable the guest account, rename a complex name, and add a password to prevent unauthorized access. (6) give all user accounts a complex password, which must contain numbers, letters, and special characters at the same time. The length must be at least 8 characters long. (7) setting the number of locks in the account attribute can prevent some large-scale logon attempts.
7. Configure log audit: Microsoft's default log audit is disabled and must be started manually. Open "Administrative Tools" "Local Security Policy" "Local Policies" "Audit Policy" and "Administrative Tools" Event Viewer "to set the following:
Audit Policy Change-successful or failed
Audit Logon Events-successful or failed
Audit Object Access -- failed
Audit Directory Service Access -- failed
Audit privileged use-Audit System Events-successful or failed
Audit Account Logon Events-successful or failed
Audit Account Management-successful or failed
8. Disable the NETBIOS interface: the NETBIOS interface is used to extract names between two or more computers running the NETBIOS application, establish a connection, and support reliable data transmission. It is designed to be compatible with common CIFS/SMB protocols. This protocol causes computer information to leak so that an empty session can be established. You can disable "microsoft Network files and printer sharing" in Network Connection Properties ".
Select the internet Protocol (TCP/IP) in the figure, select "properties" and "advanced", and then select "Disable NETBIOS on TCP/IP ".
9. protection System Account Database: directly enter the syskey command in the Start Operation, select "Start encryption" in the displayed box, and then select "Update". Then, the selection item appears, you can select "Start password" or "automatically generate password by system ". To prevent the original password from being leaked, you must also delete the SAM file from the WINNT/REPAIR directory.
10. Set privileges and rights: win 2000 provides a security mechanism for user rights, which can be used to set any operation scope of a user in the operating system. You can go to the "control panel", "Administrative Tools", and "Local Security Policy" to list some settings that correspond to user rights assignment. You can see the specific settings at a glance.
11. Use the file encryption function of win2000: Right-click a file or folder and select "advanced" on "general" and select "encrypted content to protect data ". Confirm and exit. If the application is in a folder during final confirmation, the system will prompt whether to include all the files in the folder. We recommend that you include the entire folder. Note: win2000 file encryption does not prevent files from being deleted by users with the corresponding permissions. for data security, we recommend that you back up files frequently.
12. debug information for system failure is not recorded: debugging information for system failure is stored in the memory dump file. When the system crashes, information for debugging can be provided, however, the existence of the dump file may expose other information, such as the application password. Right-click my computer, and the "properties" option is displayed. On the "advanced" Page, select "Start and fault recovery", and select "NONE" in "Write debugging information ".
13. Configure TCP/IP Filtering: win2000 provides a certain network traffic filtering function to ensure the security of TCP/IP, but must be set manually. Click the network connection icon, select "network and dial-out connection", select "internet Protocol (TCP/IP)" in general, and click "properties", "advanced", and "options ". Click "TCP/IP filter IP" and set "properties. Select "Start TCP/IP filtering (all companion servers)", select "only allow", and add port 80 to the TCP port.
14. disable Automatic boot from the CD and floppy disk: mainly to prevent malicious users from executing illegal files and malicious access to the system on Microsoft's CD, you can disable automatic startup of the disc and floppy disk from BIOS settings, and set the BIOS password to prevent malicious modification.
15. Use a screen saver with a password: Start the Screen Saver with a password to prevent unauthorized physical access when the Administrator leaves temporarily. I don't need to say much about how to set it.
16. IE browser security: Disable the Automatic completion function of the browser. On the "content" page of "internet Options" of "control Cotton Board", select "Automatic completion ", cancel the support name and password on the form and form, and clear the following history; Same as above, on the "advanced" page of "internet Options, select "do not save encrypted content to the hard disk" and "Clear the internet folder when the browser is closed", and regularly clear historical records in the corresponding directory.
17. outlook Express security: prevents virus calls. VBS ,. run the following two Commands: "regsvr32/u wshom. ocx and regsvr32/u wshext. dll ". The recovery operation removes/U.
18. delete all network resource sharing: Control Panel-Computer Management-shared folder-stop sharing, and then stop all the default sharing in it. However, the IPC sharing server will be enabled each time it is started, you need to stop it again.
19. set the wait time when the system starts to 0 seconds: Control Panel-system --- start/Close, change the default value displayed in the list to 30 to 0 or in boot. in ini, change the value of TIMEOUT to 0.
20. open only necessary ports: Close other ports except necessary ports, especially ports 139 and 445, which are more dangerous. By default, all ports are open.
21. retain only the TCP/IP protocol: delete NETBEUI and IPX/SPX protocols and only the TCP/IP protocol. Only the TCP/IP protocol is required for the website. Other protocols are useless, websites are used by some hacking tools.
22. Firewall and anti-virus software should always be on. As a network administrator, security personnel should always visit some security sites, pay attention to the latest vulnerabilities, and update the latest patches in a timely manner.